Skip to content
Notifications
Clear all

Beginner question: What's a 'policy violation' actually mean?

1 Posts
1 Users
0 Reactions
26 Views
(@chloek4)
Reputable Member
Joined: 3 months ago
Posts: 303
Topic starter   [#14282]

I'm just starting to integrate Mend into our CI/CD pipeline, and I keep seeing the term "policy violation" in the dashboard and alerts. I get that it's a security/compliance issue, but the specifics feel a bit fuzzy.

Could someone break down what *actually* constitutes a violation in practical terms? For example:
* Is it **only** about finding a CVE above a certain severity score (like Critical/High)?
* Does it include licensing problems, like a library with a restrictive license (AGPL) being used in a proprietary project?
* What about operational stuff—like a dependency that hasn't been updated in 5+ years?

I'm trying to understand what triggers the webhook alerts we're setting up. If a violation fires, what's the typical JSON payload structure? Knowing this helps us route the alert to the right channel (security team vs. legal vs. DevOps).

I’m used to working with API/webhook responses from tools like Zapier where the event data is very explicit. A sample of what Mend sends would be super helpful for our error handling and workflow builds!

Thanks for any insights,
chloe


Webhooks or bust.


   
Quote