Skip to main content
Remediation is Earnie’s assessment of what to do about a component: whether to replace it, upgrade it, or leave it, and how urgent that is. Where it’s configured, the same assessment appears everywhere a finding does, so a developer, a reviewer, and a coding agent all see the same advice.

What an Assessment Contains

Each assessed component version carries:
  • A band — how urgent the situation is, shown as a badge, never as a raw numeric score or weight.
  • An action — for example, replace or upgrade, with a plain-language summary.
  • Signals — the individual facts behind the action, ordered blocking, then concern, then info, each with a link to its evidence.
  • Confidence, with the reasons behind it.
  • An assessment date and source.
A component Earnie hasn’t assessed is marked Not assessed, never left blank. An unassessed component never reads as healthy just because nothing is shown.

Where It Appears

The Review Workspace

A Remediation group appears on the component evidence card, after Lifecycle, on both the finding rail and the component rail. The component list also shows the band on each row, so you can see which components are most urgent before opening any of them. See Triaging Findings.

Pull-Request Comments and Self-Checks

Earnie decides remediation advice with one chain, shared by inline pull-request comments, the summary comment, Self-checks, and an agent’s earnie_review_code call. Where a remediation assessment exists, it comes first in that chain, ahead of a bare fixed_versions value or a generic suggestion, so the same finding gets the same advice wherever a developer or agent looks. When there’s no assessment, Earnie falls back to the next best evidence it has, such as an explicit fixed version or a policy parameter. For dotted numeric releases, fixed-version advice picks the lowest reported fix above the installed version. If every reported numeric fix is equal to or below it, Earnie uses the next available advice instead of recommending a downgrade. Versions with suffixes or other formats keep the upstream version strings, because Earnie doesn’t infer their package-specific ordering.

MCP

earnie_get_finding includes the full assessment, and earnie_search_findings rows carry a remediation priority and band, so an agent can triage by urgency without opening every finding. See Using Earnie Through MCP.

Crypto Severity Escalation

For a reachable, assessed cryptographic finding whose severity was raised one level above its curated base severity, the Review Workspace explains the escalation next to the reachability pill, and links to Settings → Crypto Assessment for the underlying table.

What’s Next

An assessment informs a decision, but doesn’t make it for you. See Triaging Findings for how to record one, and Setting Policies for turning a repeated judgement into a rule.