Do reviewed hotspots disappear when they are no longer found in code?

So, we’ve noticed something and I suspect I know what is happening but wanted some confirmation.

In our scans sometimes a hotspot is found and we determined it was safe, so we marked it so.

Then later I noticed that the issue is gone. So I no longer see a record of the hotspot.

I’m guessing this is normal behavior? It is a little alarming because I no longer see any trace of it, what the history was or anything. Just want to make sure this is what I should expect…


Yes. This is normal.

That’s a fair point. We segregated Security Hotspots from Issues so you no longer have access to search for the ones that have been closed.

I’m going to refer this internally in case we want to make any UX changes.


