You can request an exception for container vulnerable items (CVITs) that can't be remediated or deferred immediately. By automating the VI deferral process, you can defer the matching CVITs based on the rule when the system identifies them.

You can perform the following tasks for an exception rule:

Note: Starting from v2.5 of Container Vulnerability Response, you can configure the time frames for approving false positives and exceptions, along with email notifications for both the approver and requester after a set number of days. When a request is raised, the container vulnerable item changes to In-Review status and a state change record is created. If the approver doesn't respond within the configured time frame, the container vulnerable item or remediation task reverts to Open status. The previous state is stored in the backup_state field. For more information, see Configure approval rules for Exception Management.