Skip to main content
Security Findings is the central vulnerability table in the Root platform. It lists every CVE affecting your subscribed images and discovered packages, with filtering, status tracking, and drill-down to individual CVE details.

The Security Findings table — filterable by status, severity, ecosystem, and OS distro, with Agentic Factory access per row.

This page may still appear as “Vulnerabilities” in some parts of the sidebar while the rename is being rolled out.

Accessing Security Findings

Navigate to Security Findings (or Vulnerabilities) in the app sidebar. The table shows all CVEs across your organization’s subscribed images and discovered packages.

Table columns

Filtering

By status tab

The table is organized into tabs:

By severity

Filter by Critical, High, Medium, or Low. By default, only Critical and High are shown.

By ecosystem

Narrow results to a specific ecosystem (e.g., only Debian packages, only npm).

Clicking a CVE

Click any CVE ID in the table to open the CVE Details page with full metadata, affected assets, patch artifacts, and the agentic patching visualization.

Where Security Findings appear

The Security Findings table is the organization-wide view. The same data also appears in scoped contexts: All of these share the same data source. Clicking a CVE from any table takes you to the same CVE Details page.

Agentic Patching access

For CVEs where Root has generated patch artifacts, the Security Findings table includes an Agentic Factory button on the row. Click it to open the Agentic Patching flow for that specific CVE.