Exceptions

Last updated: Oct 7, 2026


An exception permits the merge of a pull request with a vulnerability that your team accepts. You do not change the code, and the policy stays the same for all the other pull requests.

Grant an exception

  1. Open the review of the pull request in the platform. The quickest way is the View details in Fluid Attacks → link in the summary comment.
  2. In the Vulnerabilities tab, select the unmanaged vulnerabilities that you accept.
  3. Click Grant exception.
  4. Examine the list below Vulnerabilities to except.
  5. Write a justification: why this pull request can merge with this vulnerability.
  6. Confirm.

The check changes immediately. You do not push a commit, and the assistant does not scan again. The platform publishes a new check run on the same commit, and it writes the summary comment again.

What an exception covers, and for how long

SituationWhat occurs
You push a new commit to the pull requestThe exception continues to apply, also when the code moves to a different line
You open the pull request againThe exception applies again
You merge or close the pull requestThe exception ends
The same vulnerable code occurs in a different pull requestThe exception does not cover it. You decide each pull request separately
The same block of code occurs two times in one pull requestThese are two different vulnerabilities. An exception on one does not cover the other

You cannot select a vulnerability below the severity threshold. This vulnerability does not make the check fail, thus there is nothing to accept.

Examine the exceptions

The Exceptions tab of the pull request shows one card for each exception. The platform gives each card a number: EXC-1, EXC-2, and so on.

FieldWhat it shows
CoversThe quantity of vulnerabilities, with the file and the line of each one
JustificationThe reason that the person wrote
Granted byThe person who granted the exception
Granted onThe date of the exception
AgeThe time from that date

On this page