mirror of
https://github.com/usestrix/strix.git
synced 2026-10-05 02:41:38 +00:00
docs: keep triage telemetry documentation to one line
This commit is contained in:
parent
ccf107b171
commit
23fb424239
2 changed files with 4 additions and 22 deletions
|
|
@ -11,7 +11,7 @@ strix view my-run-name # a specific run under ./strix_run
|
|||
strix view --host 0.0.0.0 --port 8080 --no-open
|
||||
```
|
||||
|
||||
The UI ships prebuilt with Strix, so there is no extra install and no JavaScript build step. The dashboard reads the run files straight off disk. You do not need a cloud account to review or triage the launched run. Anonymous usage telemetry follows your [telemetry setting](/advanced/configuration); emailing a report and sending feedback use the remote services described by those actions.
|
||||
The UI ships prebuilt with Strix, so there is no extra install and no JavaScript build step. The dashboard reads the run files straight off disk. You do not need a cloud account to review or triage the launched run.
|
||||
|
||||
## Options
|
||||
|
||||
|
|
@ -48,12 +48,10 @@ The **Open / Closed / All** filters keep closed findings available with their or
|
|||
|
||||
In the terminal UI, press **F2** to open findings, including on narrow terminals where the sidebar is hidden. In a finding, click **False positive (f)** or press **f** to open the native false-positive form; **r** reopens a closed issue, and **u** undoes a recent change. Use **Tab / Shift+Tab** to move through the optional reason, note and buttons, **Enter** to activate a button, and **Esc** to return. Press **v** in the finding detail or focused findings panel to cycle **Open / Closed / All**. If the selected filter is empty, **F2** opens **All** so closed issues remain accessible. No browser is required.
|
||||
|
||||
Decisions apply to that finding in that run. They are saved locally in `triage.json`, survive restarts and scan resume, and are shared by the viewer and terminal UI. Closing and reopening work offline and with telemetry disabled. They do not require an email address for the launched run. A separate scan starts with its own review state; material changes to a closed finding show **Needs review** and return it to the Open filter while preserving the previous decision.
|
||||
Decisions apply to that finding in that run. They are saved locally in `triage.json`, survive restarts and scan resume, and are shared by the viewer and terminal UI. Closing and reopening work offline. They do not require an email address for the launched run. A separate scan starts with its own review state; material changes to a closed finding show **Needs review** and return it to the Open filter while preserving the previous decision.
|
||||
|
||||
The original scan report, emailed PDF, raw finding files, and SARIF retain the scanner's findings. The PDF cover and filename identify it as the **Original scan report**; its counts describe detected findings, including those you later closed. Local decisions do not change the original scan's exit code or coverage assessment.
|
||||
|
||||
When telemetry is enabled, a saved classification change sends anonymous metadata: the interface used, previous and new status and resolution, optional reason category, severity, CWE, CVE presence, scan mode, and common system/version information. Notes, finding content, targets, run and finding IDs, and local digests are excluded. Delivery is asynchronous and best effort; actions taken with telemetry off are not queued for later delivery. Set `STRIX_TELEMETRY=0` to opt out.
|
||||
|
||||
## Sharing The Link
|
||||
|
||||
<Warning>
|
||||
|
|
|
|||
|
|
@ -18,29 +18,13 @@ We collect only very **basic** usage data including:
|
|||
**Model Usage:** Which LLM model is being used and whether it runs via an API key or a model subscription (not prompts or responses)\
|
||||
**Feature Usage:** Which built-in skills were used during a scan (reported once, at scan end)\
|
||||
**Aggregate Metrics:** Vulnerability counts by severity and weakness category (CWE)\
|
||||
**Finding Triage:** Saved classification changes from the local web viewer and terminal UI, as described below
|
||||
|
||||
### False-Positive Triage
|
||||
|
||||
Closing a finding as a false positive and reopening it work locally whether telemetry is enabled or disabled. Classification changes include closing, reopening, a changed reason category, or a fresh review after evidence changes. When enabled, a successfully saved classification change can emit `finding_triage_changed` with:
|
||||
|
||||
- Source interface: `viewer` or `tui`
|
||||
- Previous and new status and resolution, plus an optional predefined reason category (`reason_code`)
|
||||
- Finding severity, weakness category (CWE), and whether a CVE is present
|
||||
- Scan mode and the common Strix/Python version, OS, and architecture properties
|
||||
|
||||
The event uses the existing random process-only session identifier. It excludes notes, titles, descriptions, evidence, proof-of-concept scripts, code, targets, URLs, paths, email addresses, run names, finding IDs, and local finding digests. Freeform text is never included; categories are validated against a fixed vocabulary.
|
||||
|
||||
Events are emitted after the local decision is saved and sent asynchronously on a best-effort basis. Delivery may be dropped when the process exits or the in-memory queue is full. Delivery failure does not affect the saved decision. Failed changes, repeated no-op submissions, reading a run, and notes-only edits do not emit classification events. There is no persisted analytics backlog, and enabling telemetry later does not replay actions taken while it was disabled.
|
||||
|
||||
These events describe user-reported classification trends, not an independently verified scanner false-positive rate. They do not provide persistent user or finding tracking across processes.
|
||||
**Finding Triage:** Anonymous metadata about false-positive decisions and reopenings when telemetry is enabled; excludes notes and finding content.
|
||||
|
||||
### What We **Never** Collect
|
||||
|
||||
- Usernames, or any identifying information
|
||||
- Scan targets, file paths, target URLs, or domains
|
||||
- Vulnerability details, descriptions, code, or written triage notes
|
||||
- Finding IDs, run names, or local finding digests
|
||||
- Vulnerability details, descriptions, or code
|
||||
- LLM requests and responses
|
||||
|
||||
### How to Opt Out
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue