Skip to content

Issue Lifecycle ​

Every vulnerability finding in Hashiro follows a structured lifecycle from discovery through resolution. Understanding these stages helps teams track remediation progress and maintain clear communication.

Issue lifecycle flow

Screenshots use fictional demonstration data.

Statuses ​

StatusDescription
DraftFinding is being documented, not yet visible to clients
OpenConfirmed vulnerability, visible and awaiting remediation
ClosedSuccessfully remediated and verified
AcceptedRisk accepted by the client, no remediation planned
Pending RetestClient reports a fix, awaiting verification by the tester
RetestingTester is actively verifying the reported fix
Retest FailedFix was insufficient, vulnerability still present
Not ApplicableFinding does not apply to the target environment
DuplicateFinding duplicates another existing issue
InformativeObservation with no direct security impact

Typical Flow ​

Draft → Open → Pending Retest → Retesting → Closed
                                           → Retest Failed → Open (cycle repeats)

Alternative paths:

Open → Accepted (risk accepted)
Open → Not Applicable
Open → Duplicate
Draft → Informative

Verification Workflow ​

For AI-generated findings, an additional verification layer applies:

Verification StateMeaning
CandidateAI-generated finding awaiting human review
AcceptedReviewer confirmed the finding is valid
RejectedReviewer determined the finding is invalid
Needs EvidenceAdditional evidence requested before acceptance
MergedFinding combined with another existing issue

TIP

Candidate findings from AI assessments can be made publicly visible to clients before full verification, so clients can see what automated testing discovered while the provider reviews for accuracy.

Retest Tracking ​

When a client submits a fix for verification:

  1. The issue moves to Pending Retest
  2. The pentester picks it up and moves to Retesting
  3. After verification, it becomes either Closed (fix effective) or Retest Failed (vulnerability persists)

Retest comments capture what was tested and the outcome, providing a clear record of remediation attempts.

Bulk Operations ​

For managing large finding sets efficiently:

  • Bulk status change: select multiple issues and transition them simultaneously
  • Bulk delete: remove multiple findings at once

WARNING

Bulk operations affect all selected findings immediately. Review your selection carefully before applying.

Audit Trail ​

Every status change, severity modification, and retest event is recorded in the issue's history timeline. This immutable log includes what changed, who made the change, and when it occurred.

Hashiro. Continuous Threat Exposure Management.