Skip to content

Set a repository's risk profile

Documentation Index

Fetch the complete documentation index at: https://docs.sourcery.ai/llms.txt

Use this file to discover all available pages before exploring further.

A finding on a public, customer-facing service is more urgent than the same finding on an internal tool. A repository’s risk profile is how you tell Sourcery which kind of repository it’s looking at, so it weights severities to match.

A risk profile has two dimensions:

DimensionChoices
Network exposurePublic network, internal only
Data sensitivityCritical, high, standard, low, none

The more exposed the network and the more sensitive the data, the more Sourcery raises the severity of findings in that repository. A repository with no profile set is treated as standard data sensitivity, with no network-exposure adjustment.

  1. Open the repositories page

    Go to Repositories and find the repository.

  2. Choose its exposure and sensitivity

    Set the network exposure and data sensitivity that describe how this repository is deployed and what data it handles.

  3. Save

    Save the profile. It applies on the repository’s next scan.

A risk profile feeds severity scoring, which happens at scan time. Setting a profile does not re-score what is already on screen. On the next scan, Sourcery re-scores the repository’s findings using the new profile, so existing findings pick up the change then. If you’d rather not wait for the schedule, queue a scan to pick it up sooner.