Ways to triage components in Polaris

All components found are automatically listed in your software bill of materials (SBOM) and issues derived from a component included in your issues. Triaging components gives you a way to exclude components from your SBOM and automatically dismiss issues derived from a component from your issues. If needed, you can change an excluded component back to included.

Note the following when triaging components:

  • This feature is project specific, meaning that when you triage a component, it will be triaged for the whole project but not for other projects.
  • Once you exclude a component, if it is detected in a later test, it will still appear as excluded.
  • If the same component is detected in multiple branches of a project, you only need to triage it once. Triage actions are automatically applied across branches in a project.
  • You can view the triage history of an individual component during triage.
    Note: Issue triage (see Ways to triage issues in Polaris) is affected by component triage.
    • When you exclude a component, any non-dismissed issues derived from the component are automatically dismissed.
    • When you include a component, any issues related to the component that has been previously dismissed automatically, are now set to the default state (not triaged).
  • Dismissed issues and excluded components (via issue and component triage) are not included in reports and dashboards. It can take up to 60 minutes triage actions to affect reports and dashboards.

How to Exclude a Component

  1. Select components by:
    • Manually selecting via checkboxes for individual, multiple, or all.
    • Using filters.
    • Clicking Triage All.
  2. Click Triage (Selected or All).
    The Triage Selected Component panel opens.

    Screenshot of Individual Issue Triage
    1. Under SBOM, select Excluded.
    2. (Optional) Enter a comment in the text box that explains the reason for the status you chose.
  3. Click Save.

How to Include a Component (that has been excluded)

Components are included by default. If component(s) have been excluded, you can change it back to included.
  1. Select components by:
    • Manually selecting via checkboxes for individual, multiple, or all.
    • Using filters (SBOM > Excluded).
    • Clicking Triage All (after using filter if you want to triage all excluded components).
  2. Click Triage (Selected or All).
    The Triage Selected Component panel opens.

    Screenshot of Individual Issue Triage
    1. Under SBOM, select Included.
    2. (Optional) Enter a comment in the text box that explains the reason for the status you chose.
  3. Click Save.