Summary
Between April 14 and April 28, 2026, a processing issue occurred within our scanning workflow that prevented a subset of code update events from being fully processed. As a result, some security findings may not have been updated or resolved as expected in the platform. The issue was caused by an update to the processing system that introduced a conflict in how data was written to the database. The issue has been fully resolved, and all affected data has been reprocessed to ensure accuracy.
Key Timeline (IDT)
April 14, 2026, 09:00 IDT: A new update was deployed to the processing system which introduced the underlying issue.
April 28, 2026, 15:30 IDT: A subsequent system update was rolled out that inadvertently corrected the processing error.
May 4, 2026, 11:00 IDT: Internal teams identified reports of inconsistent status updates and began a technical investigation.
May 6, 2026, 10:00 IDT: A formal incident was initiated to analyze the full scope of the impact and coordinate remediation.
May 7, 2026, 14:00 IDT: Data collection was completed to identify all repositories and branches that required reprocessing.
May 8, 2026, 08:00 IDT: Reprocessing of affected data began for several scanning modules.
May 9, 2026, 18:00 IDT: Initial reprocessing for the majority of modules was successfully completed.
June 11, 2026, 12:00 IDT: Final reprocessing for all remaining modules was completed, and the incident was officially closed.
Root Cause
The issue was triggered by a change in the update process that attempted to perform multiple database operations simultaneously within the same request. This led to connectivity conflicts and prevented certain background tasks from completing successfully. Consequently, a small portion of events were not recorded, leading to delays in updating the status of findings for customers.
Actions Taken
Deployed a corrective update to the processing system to ensure stable database interactions.
Conducted a comprehensive data analysis to identify all events that were missed during the affected period.
Triggered system-wide rescans for all affected branches to restore the expected state of all findings.
Verified that all processed updates are now reflecting correctly across the platform.
Action Items
Enhance system logging to provide better visibility into background processing failures.
Implement automated alerts for specific error patterns to decrease detection time.
Improve the scalability of the underlying processing services to handle high volumes more efficiently.
Develop improved internal tools for bulk data correction and status verification.
Resolved
Summary
Between April 14 and April 28, 2026, a processing issue occurred within our scanning workflow that prevented a subset of code update events from being fully processed. As a result, some security findings may not have been updated or resolved as expected in the platform. The issue was caused by an update to the processing system that introduced a conflict in how data was written to the database. The issue has been fully resolved, and all affected data has been reprocessed to ensure accuracy.
Key Timeline (IDT)
April 14, 2026, 09:00 IDT: A new update was deployed to the processing system which introduced the underlying issue.
April 28, 2026, 15:30 IDT: A subsequent system update was rolled out that inadvertently corrected the processing error.
May 4, 2026, 11:00 IDT: Internal teams identified reports of inconsistent status updates and began a technical investigation.
May 6, 2026, 10:00 IDT: A formal incident was initiated to analyze the full scope of the impact and coordinate remediation.
May 7, 2026, 14:00 IDT: Data collection was completed to identify all repositories and branches that required reprocessing.
May 8, 2026, 08:00 IDT: Reprocessing of affected data began for several scanning modules.
May 9, 2026, 18:00 IDT: Initial reprocessing for the majority of modules was successfully completed.
June 11, 2026, 12:00 IDT: Final reprocessing for all remaining modules was completed, and the incident was officially closed.
Root Cause
The issue was triggered by a change in the update process that attempted to perform multiple database operations simultaneously within the same request. This led to connectivity conflicts and prevented certain background tasks from completing successfully. Consequently, a small portion of events were not recorded, leading to delays in updating the status of findings for customers.
Actions Taken
Deployed a corrective update to the processing system to ensure stable database interactions.
Conducted a comprehensive data analysis to identify all events that were missed during the affected period.
Triggered system-wide rescans for all affected branches to restore the expected state of all findings.
Verified that all processed updates are now reflecting correctly across the platform.
Action Items
Enhance system logging to provide better visibility into background processing failures.
Implement automated alerts for specific error patterns to decrease detection time.
Improve the scalability of the underlying processing services to handle high volumes more efficiently.
Develop improved internal tools for bulk data correction and status verification.
Resolved
Between 14.04.2026 and 28.04.2026, a small portion of push events were not processed correctly. As a result, some violations were not resolved as expected.
The underlying issue has been identified and resolved. We are currently performing a retroactive data correction process to ensure all affected violations are updated accordingly.
Monitoring
Between 14.04.2026 and 28.04.2026, a small portion of push events were not processed correctly. As a result, some violations were not resolved as expected.