Exceptions
What happens today to a vulnerability nobody intends to patch, what is kept, and what the product does not have yet.
A decision not to patch is recorded today as a status on the vulnerability row, not as a standalone exception record. That status, and the free-text note beside it, is the whole mechanism.
Two ways out of the work queue
| Status | When | What happens to the row |
|---|---|---|
| Not relevant | The decision is that the vulnerability does not apply here | Stays in the register, hidden from the view |
| Archived | The decision is not to handle it for now | Stays in the register, hidden from the view |
Both disappear from the register by default and come back with the Show archive toggle. Nothing in them is deleted: the title, the severity, the patch, the history and the per-server handled marks are kept as they were.
The edit form carries a free-text Notes field. That is where the reasoning is written today.
What this is not
Permanent deletion is a different action, and the register says so in its confirmation: it also removes the per-server handled marks, and it cannot be undone. Archiving is preferable. The audit log is kept either way.
Until then, a decision that is meant to expire needs tracking outside the product. “Archived plus a note with a date” is enforced by nothing: no process brings a vulnerability back out of the archive on the date written in the note.
Updated
This page is the file content/docs/en/v1/risk/exceptions.mdx