Skip to main content
Regulaxy

Exceptions

What happens today to a vulnerability nobody intends to patch, what is kept, and what the product does not have yet.

A decision not to patch is recorded today as a status on the vulnerability row, not as a standalone exception record. That status, and the free-text note beside it, is the whole mechanism.

Two ways out of the work queue

StatusWhenWhat happens to the row
Not relevantThe decision is that the vulnerability does not apply hereStays in the register, hidden from the view
ArchivedThe decision is not to handle it for nowStays in the register, hidden from the view

Both disappear from the register by default and come back with the Show archive toggle. Nothing in them is deleted: the title, the severity, the patch, the history and the per-server handled marks are kept as they were.

The edit form carries a free-text Notes field. That is where the reasoning is written today.

What this is not

Permanent deletion is a different action, and the register says so in its confirmation: it also removes the per-server handled marks, and it cannot be undone. Archiving is preferable. The audit log is kept either way.

Until then, a decision that is meant to expire needs tracking outside the product. “Archived plus a note with a date” is enforced by nothing: no process brings a vulnerability back out of the archive on the date written in the note.

Updated

This page is the file content/docs/en/v1/risk/exceptions.mdx