Skip to main content

Documentation Index

Fetch the complete documentation index at: https://help.loopiq.com/llms.txt

Use this file to discover all available pages before exploring further.

Use Code Security Operations

What this does

Code Security Operations gives teams a place to review security findings from tools such as GitHub security scanning, Datadog Code Security, Checkmarx, and related security integrations. Use this page to triage findings, link them to delivery work, create remediation actions, or accept risk when appropriate.

Before you begin

Make sure:
  • the relevant security integration is configured
  • your role can view security or compliance operations
  • your role can create or link remediation work if you plan to take action
  • repositories are connected to the correct application, module, or team where possible

Open Code Security Operations

  1. Open the security or compliance operations area.
  2. Select the tab for the source you want to review, such as GitHub Security, Checkmarx Operations, or Datadog Operations.
  3. Review the summary cards and trend widgets.
  4. Use filters to narrow results by severity, source, repository, status, or workflow state.
Trend cards summarize recent security posture across snapshots or releases. Use them to understand whether the number of open alerts is increasing, decreasing, or unchanged. If trend bars appear duplicated or flat, refresh the source data and confirm the integration is returning distinct snapshots.

Review a finding

  1. Find the security finding in the findings table.
  2. Open the finding details.
  3. Review title, severity, source, repository, status, affected package or rule, and description.
  4. Review remediation guidance if available.
  5. Check linked work, accepted risk, and related events.

Take action on a finding

Depending on your permissions, you can:
  • create an issue or task for remediation
  • link to an existing work item
  • attach evidence
  • mark a finding as reviewed
  • accept risk with a justification
  • connect the finding to a release certification or evidence dossier

Tips

  • Prefer linking findings to work items instead of tracking remediation outside LoopIQ.
  • Use source system details, such as Datadog or GitHub descriptions, to understand impact and fix guidance.
  • Review high and critical findings before release certification.
  • Keep repository-to-application/module mappings current so findings are routed to the right owners.