# Active Issues

The Active Issues page is your central workspace for monitoring and managing security, compliance, and configuration risks detected across your connected applications and infrastructure. From here, you can prioritize critical findings, assign ownership, and track progress over time.

<figure><img src="/files/56ZmF4BFaJYRDPdgnYYb" alt="" width="563"><figcaption></figcaption></figure>

The main parts of the Active Issues page are the [issues table](#issues-table) and the [filters](#filtering-issues). You can open [each issue to view the details and perform actions](/scan-and-analyze-with-ox/analyzing-scan-results/active-issues-new/issue-details.md).

## Issues Table

The Issues table is the main working area of the Active Issues page. It presents all detected security, compliance, and configuration issues across your connected applications and infrastructure.

Most column headers support sorting. You can select a column header, such as Severity, SLA, or First Seen, to reorder the table and surface the most critical or oldest issues at the top of the list.

The following table explains the purpose and behavior of each column in the issues table.

<table><thead><tr><th width="159.8333740234375">Column</th><th>Description</th></tr></thead><tbody><tr><td>Selection</td><td>Use the checkbox at the beginning of each row to select one or more issues. Selection enables bulk actions from the page toolbar, such as assigning owners or applying workflow actions.</td></tr><tr><td>#</td><td>Displays the row number in the current table view. The numbering reflects the current sort and filter state rather than a permanent issue identifier.</td></tr><tr><td>Severity</td><td>Indicates the risk level assigned to the issue, such as Critical. Severity helps you prioritize remediation based on potential impact and exposure.</td></tr><tr><td>Category</td><td>Shows the security domain or scan type that detected the issue, such as Open Source Security, Container Security, SBOM, or Infrastructure as Code Scan. This column helps you quickly understand the technical context of the finding.</td></tr><tr><td>Name</td><td>Provides a short, descriptive title for the issue. The name usually includes the affected component and a brief explanation of the risk, such as a vulnerable dependency, an exposed resource, or a misconfiguration. Select the issue name to open the issue details page, where you can review technical evidence, remediation guidance, and activity history.</td></tr><tr><td>SLA</td><td>Displays the service level agreement status for the issue. This value shows how much time has passed relative to the defined remediation target. Positive values, such as +8mo or +2y, indicate how long the issue has exceeded its SLA.</td></tr><tr><td>Application</td><td>Identifies the application, repository, or environment where the issue was detected. This value reflects the connection source, such as a GitHub repository, container image, or cloud resource. Select the application name to navigate to the related asset or integration context.</td></tr><tr><td>Issue Owner</td><td>Shows the user currently assigned to the issue. Ownership indicates who is responsible for reviewing and coordinating remediation. If no owner is assigned, this column may be empty or display a placeholder, depending on your organization settings.</td></tr><tr><td>First Seen</td><td>Indicates when OX first detected this issue. This value helps you understand how long the risk has existed in your environment.</td></tr><tr><td>Count</td><td>Displays how many times this issue appears across assets or scans. A higher count can indicate a systemic problem, such as a vulnerable dependency used in multiple projects.</td></tr><tr><td>Actions</td><td>Provides a menu for issue-level actions. Use this column to perform tasks such as assigning an owner, updating status, or triggering workflow steps, depending on your organization configuration.</td></tr></tbody></table>

### Typical workflow

1. Sort by Severity or [SLA](/exclusions-and-sla/scope-policy-and-sla-compliance/enforcing-sla.md) to identify the most urgent issues.
2. Select an issue name to review technical [details and remediation guidance](/scan-and-analyze-with-ox/analyzing-scan-results/active-issues-new/issue-details.md).
3. Assign an[ Issue Owner](/scan-and-analyze-with-ox/analyzing-scan-results/active-issues-new/assigning-issue-owners.md) if one is not already set.
4. Track progress over time using the First Seen and SLA columns to verify that issues are being addressed within your organization’s targets.

## Filtering issues

The Active Issues page provides a filter sidebar for narrowing the issue list to the work that matters to you. Filters are split into a primary set (always visible) and an **Additional filters (45)** section that expands to reveal more granular options.

### Primary filters

<table><thead><tr><th width="274.8333740234375">Filter</th><th>What it filters</th></tr></thead><tbody><tr><td>Application</td><td>Issues belonging to a specific application or repository.</td></tr><tr><td>Severity</td><td>Issues by severity (Appox, Critical, High, Medium, Low, Info).</td></tr><tr><td>Severity Factor</td><td>Issues by the contextual severity factor that influenced their final score (for example, Active Secret in Exposed Cloud Asset).</td></tr><tr><td>Category</td><td>Issues by category, such as secrets, misconfiguration, or vulnerabilities.</td></tr><tr><td>Issue Name</td><td>Issues by their canonical issue name.</td></tr><tr><td>Policy</td><td>Issues triggered by a specific OX policy.</td></tr><tr><td>Actions</td><td>Issues by the action taken on them (for example, remediated, ignored, snoozed).</td></tr><tr><td>App Tag</td><td>Issues on applications that carry a given tag.</td></tr><tr><td>SLA</td><td>Issues by SLA status (within SLA, breached, soon to breach).</td></tr><tr><td>Code-to-Cloud Exposure</td><td>Issues that have a code-to-cloud exposure path.</td></tr><tr><td>Exposure by API</td><td>Issues exposed via an API.</td></tr></tbody></table>

### Additional filters

Click **Additional filters (45)** to expand the full filter list. The filters below cover status history, ownership, integrations, infrastructure, compliance, and artifact details.

<table><thead><tr><th width="299">Filter</th><th>What it filters</th></tr></thead><tbody><tr><td>Severity Change Log</td><td>Issues whose severity has changed, based on the change log.</td></tr><tr><td>Issue Status Over Time</td><td>Issues by status at a given point in time.</td></tr><tr><td>Issue Status vs Last Scan</td><td>Issues by how their status compares to the previous scan.</td></tr><tr><td>Severity Before Prioritization</td><td>Issues by their original (pre-prioritization) severity.</td></tr><tr><td>Severity Reprioritized</td><td>Issues whose severity was changed by OX prioritization.</td></tr><tr><td>Application Source</td><td>Issues by the source of the application (for example, Git provider or registry).</td></tr><tr><td>Issue Owner</td><td>Issues by assigned owner.</td></tr><tr><td>Source Tool</td><td>Issues by the OX source or scanner that produced them.</td></tr><tr><td>OSC&#x26;R Tactic</td><td>Issues by OSC&#x26;R attack tactic (for example, Initial Access).</td></tr><tr><td>OSC&#x26;R Technique</td><td>Issues by OSC&#x26;R technique (for example, T0112: Compromised token).</td></tr><tr><td>Compliance Standard</td><td>Issues by compliance framework (for example, SOC2, PCI_DSS, ISO27001).</td></tr><tr><td>Compliance Control</td><td>Issues by specific compliance control.</td></tr><tr><td>CVE</td><td>Issues associated with a specific CVE.</td></tr><tr><td>DAST URL</td><td>Issues found at a specific DAST-scanned URL.</td></tr><tr><td>CVSS Base Score</td><td>Issues by CVSS base score (or score range).</td></tr><tr><td>CWE</td><td>Issues by CWE classification.</td></tr><tr><td>Languages</td><td>Issues by the programming language of the affected code.</td></tr><tr><td>Vulnerable Library</td><td>Issues tied to a specific vulnerable library.</td></tr><tr><td>Files With Issues</td><td>Issues by the file they live in.</td></tr><tr><td>Analyzed Branch</td><td>Issues found on a specific scanned branch.</td></tr><tr><td>Business Priority</td><td>Issues by the business priority of the affected app.</td></tr><tr><td>Registry Name</td><td>Issues found in a specific container or artifact registry.</td></tr><tr><td>Registry Type</td><td>Issues by registry type (for example, ECR, GCR, Docker Hub).</td></tr><tr><td>Artifact Image</td><td>Issues by the specific artifact image.</td></tr><tr><td>Registry Region</td><td>Issues by registry region.</td></tr><tr><td>Registry Account Id</td><td>Issues by the registry's account ID.</td></tr><tr><td>Kubernetes Cluster</td><td>Issues affecting a specific Kubernetes cluster.</td></tr><tr><td>Kubernetes Namespace</td><td>Issues in a specific Kubernetes namespace.</td></tr><tr><td>Cloud Region</td><td>Issues by cloud region.</td></tr><tr><td>Cloud Account</td><td>Issues by cloud account.</td></tr><tr><td>Cloud Service</td><td>Issues by cloud service (for example, S3, EC2, Lambda).</td></tr><tr><td>Cloud Resource</td><td>Issues by specific cloud resource.</td></tr><tr><td>Artifact OS Image</td><td>Issues by the artifact's underlying OS image.</td></tr><tr><td>Artifact Base Image</td><td>Issues by the artifact's base image.</td></tr><tr><td>Artifact SHA</td><td>Issues by artifact SHA digest.</td></tr><tr><td>Artifact Path</td><td>Issues by path within the artifact.</td></tr><tr><td>First Seen</td><td>Issues by when they were first detected.</td></tr><tr><td>Connection Name</td><td>Issues by the OX connection (integration) that detected them.</td></tr><tr><td>Ticket Status</td><td>Issues by external ticket status (for example, in Jira).</td></tr><tr><td>Commit Date</td><td>Issues by the commit date of the affected code.</td></tr><tr><td>Business Unit</td><td>Issues by business unit.</td></tr><tr><td>Rule ID</td><td>Issues by the specific rule ID that triggered them.</td></tr><tr><td>CSPM Enhanced Issues</td><td>CSPM issues that have been enriched with additional context.</td></tr><tr><td>Triage Status</td><td>Issues by triage status.</td></tr><tr><td>Issues Without …</td><td>Issues that are missing a specified attribute (for example, without an owner or without a ticket).</td></tr></tbody></table>

Use the **Search filters** box at the top of the sidebar to jump directly to any filter by name.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.ox.security/scan-and-analyze-with-ox/analyzing-scan-results/active-issues-new.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
