> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanoss.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Remediation

> How Earnie assesses what to do about a component, and where that assessment shows up: the Review Workspace, pull-request comments, Self-checks, and MCP.

**Remediation** is Earnie's assessment of what to do about a component: whether to replace it, upgrade it, or leave it, and how urgent that is. Where it's configured, the same assessment appears everywhere a finding does, so a developer, a reviewer, and a coding agent all see the same advice.

## What an Assessment Contains

Each assessed component version carries:

* **A band** — how urgent the situation is, shown as a badge, never as a raw numeric score or weight.
* **An action** — for example, replace or upgrade, with a plain-language summary.
* **Signals** — the individual facts behind the action, ordered blocking, then concern, then info, each with a link to its evidence.
* **Confidence**, with the reasons behind it.
* **An assessment date and source.**

A component Earnie hasn't assessed is marked **Not assessed**, never left blank. An unassessed component never reads as healthy just because nothing is shown.

## Where It Appears

### The Review Workspace

A **Remediation** group appears on the component evidence card, after Lifecycle, on both the finding rail and the component rail. The component list also shows the band on each row, so you can see which components are most urgent before opening any of them. See [Triaging Findings](/en/latest/earnie/using-earnie/triaging-findings).

### Pull-Request Comments and Self-Checks

Earnie decides remediation advice with **one chain**, shared by inline pull-request comments, the summary comment, [Self-checks](/en/latest/earnie/using-earnie/self-checks), and an agent's `earnie_review_code` call. Where a remediation assessment exists, it comes first in that chain, ahead of a bare `fixed_versions` value or a generic suggestion, so the same finding gets the same advice wherever a developer or agent looks. When there's no assessment, Earnie falls back to the next best evidence it has, such as an explicit fixed version or a policy parameter.

For dotted numeric releases, fixed-version advice picks the lowest reported fix above the installed version. If every reported numeric fix is equal to or below it, Earnie uses the next available advice instead of recommending a downgrade. Versions with suffixes or other formats keep the upstream version strings, because Earnie doesn't infer their package-specific ordering.

### MCP

`earnie_get_finding` includes the full assessment, and `earnie_search_findings` rows carry a remediation priority and band, so an agent can triage by urgency without opening every finding. See [Using Earnie Through MCP](/en/latest/earnie/mcp/tools).

## Crypto Severity Escalation

For a reachable, assessed cryptographic finding whose severity was raised one level above its curated base severity, the [Review Workspace](/en/latest/earnie/using-earnie/triaging-findings#reachability) explains the escalation next to the reachability pill, and links to [Settings → Crypto Assessment](/en/latest/earnie/using-earnie/triaging-findings#where-the-severity-comes-from) for the underlying table.

## What's Next

An assessment informs a decision, but doesn't make it for you. See [Triaging Findings](/en/latest/earnie/using-earnie/triaging-findings) for how to record one, and [Setting Policies](/en/latest/earnie/using-earnie/setting-policies) for turning a repeated judgement into a rule.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.