Change Intelligence
The Change Intelligence page helps you understand how issues evolve between scans by showing what changed, when it changed, and how those changes affect your security posture. It highlights new issues, resolved issues, removed issues, and severity changes so you can track risk trends over time instead of reviewing individual findings in isolation.
By combining trend analysis with detailed scan comparisons, Change Intelligence allows you to identify regressions, validate remediation efforts, and understand the impact of coverage or detection changes across applications and time periods.
Change Intelligence data is also available through the API for automation, reporting, and integration with external systems.

Filters
Filters define the scope of data shown across the entire Change Intelligence view.
The selected filters are applied together and affect the trend graph, Latest Scan Changes, and Historical Changes.
Updating any filter immediately refreshes the data to reflect the selected scan range, application scope, and severity levels.
Time range
Controls two aspects of the data:
The range of past scans that can be compared against the latest scan
Extends or limits the time period of historical scans displayed in the trend graph and the Historical Changes view.
Application
Filters the data to include only issues related to the selected applications. This filter affects the trend graph as well as both the Latest Scan Changes and Historical Changes sections.
Severity
Filters the data to include only issues with the selected severity levels. This filter affects the trend graph as well as both the Latest Scan Changes and Historical Changes sections.
Issues Status Trend Over Time
This section provides a graph that shows the number of issues over time by type of change. You can use the date selector to view data for different periods, such as the last week or month.
New
Issues discovered for the first time in the selected period.
Changed Severity
Issues whose severity level was updated since the last scan.
Resolved
Issues that were fixed and are no longer active.
Removed
Issues that were removed because their source or component was removed.
Latest Scan Changes
This section lists all changes detected between the latest scan and the selected previous scan. It allows you to compare results and identify what has changed since the last run.

Counters at the top of the list summarize totals for each category.
Each record in the list includes key information about the issue and its change type. You can expand an item to see detailed context.
The following examples illustrate common types of issue changes displayed in this view:
114 New with severity counters
A total of 114 new issues were detected between the latest scan and the selected past scan. The colored counters show how these new issues are distributed by severity.
Repository CTO / ChainProtect – development was created on Sat Feb 07 2026 and first seen in OX on Mon Feb 09 2026
A repository that was scanned by OX for the first time. All issues listed under this entry are considered new relative to the selected comparison scan.
Detected by policy – CSPM issue
Issues that were identified as a result of policy evaluation rather than code, dependency, or image scanning.
Dependency [email protected] was assigned a new vulnerability (CVE-2025-65438)
A dependency that was associated with a newly published vulnerability. The discovery date indicates when the vulnerability information became available to OX.
Clickable issue count or severity badge
Selecting a link navigates you to a filtered issues view. For New entries, the link opens the Active Issues page showing the newly detected issues. For Resolved or Removed entries, the link opens the corresponding Resolved or Removed issues view, allowing you to review issues that were closed or removed in the selected scan.
Export
You can export change data directly from the Change Intelligence page. Export options include exporting all detected groupings or exporting only the groupings that match the currently applied filters.
AI Summary
AI Summary provides an automated overview of the issues currently displayed on the page. It summarizes the findings based on the current view, helping you understand what stands out without reviewing every record manually.

This is useful when you have a large number of issues or frequent scan updates, and you need a quick way to understand the main changes and risks.
AI Summary is optional and disabled by default. This allows organizations to control whether issue data is sent to an AI service, based on internal security and compliance requirements.
When AI Summary is enabled, no issue details, image names, application names, or user data are sent to the AI model. Only library names may be shared for processing in order to generate the summary. Some organizations keep this disabled due to legal or privacy requirements.
Organizations can configure AI Summary to work with their own OpenAI token. In this case, data is sent using the customer-managed token.
To Enable AI Summary:
Go to Settings > AI Settings.
Enable AI Summary.
Historical Changes
The Historical Changes view shows issue updates from previous scans within the selected date range. It helps identify when issues were introduced, when their severity changed, and how risks evolved over time. Each entry reflects the state of the issue at that scan point, including severity changes, resolution, or removal.
Historical results reflect the state of issues at the time of each scan. As coverage, scope, or detection logic changes, issues may later appear as resolved or excluded. For this reason, issue links are available only for the latest scan.

The following examples illustrate how to interpret common entries in the Historical Changes view.
34 New with severity counters
Thirty-four new issues were detected in this scan. The counters show how these issues are distributed by severity.
Development dependencies are now deprecated
Issues that were detected because certain dependencies were marked as deprecated during this scan.
Private image ppa:latest created was scanned for the first time because it was detected in runtime
A container image that was scanned for the first time after being detected as running in the environment.
45 Removed
Issues that were removed in this scan, typically due to scope reduction, coverage changes, or components no longer being relevant.
Last updated
