---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Marking and approving a false positive container vulnerability item

# Marking and approving a false positive container vulnerability item {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Container Vulnerable items (CVITs) and remediation tasks (VULs) can be marked as false positives. Approvers with write access can approve such requests from other users.

* [Mark as a false positive in Container Vulnerability Response](https://servicenow-prod.fluidtopics.net/a2D9Kf9WcAdLSs8k9GIWBA "Mark a container vulnerable item (CVIT) or remediation task as a false positive if the warning given by the scanner is not actually an issue. For example, if a CVIT has been decommissioned but the scanner is still raising an issue related to it, mark it as a false positive.")
* [Approve a false positive](https://servicenow-prod.fluidtopics.net/ysDomubzSbqRk6EBKObKeQ "As a false positive approver, you can approve false positive requests from other users.")

{#request-approve-fp-cvr__ul_zq3_3yw_llb}  
Note:  
Email notifications are sent at every stage of the false positive workflow, providing the status and other details of a request. For example, when a CVIT or remediation task is marked as a false positive, the requester receives a
confirmation email. Simultaneously, the approver receives an email stating that a CVIT or remediation task has been marked as a false positive. Starting from v2.5 of Container Vulnerability Response, you can configure the time frames for approving false positives and exceptions, along with email notifications for both the approver and requester after a set number of days. When a request is raised, the container vulnerable item changes to In-Review status and a state change record is created. If the approver doesn't respond within the configured time frame, the container vulnerable item or remediation task reverts to Open status. The previous state is stored in the backup_state field. For more information, see [Configure approval rules for Exception Management](https://servicenow-prod.fluidtopics.net/qvv6l_fxbZqG1_9uq7zGqw "Starting with Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Vulnerability Response (VR) for the first time, the flow designer is enabled by default.").  
Important:  
As a Vulnerability analyst and remediation owner, you can request and approve false positives from the [Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/bWo4zdNcYMgNqM8grmyNNw "From the Vulnerability Manager Workspace, vulnerability managers and analysts can request exceptions and false positives for a remediation task (VUL, AVUL, CVUL or CRG) and record (VIT, CVIT, AVIT or CTR). You can also split a remediation task and create change requests.") and [IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/p4KWSnJ679hjoYagUtsFLw "Indicate a false positive request for host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT), or remediation task (VUL, AVUL, CVUL or CRG) in the IT Remediation Workspace. A false positive is a condition where a scanner incorrectly reports that a vulnerability exists in the system due to situations such as an incorrect classification, improper logic, or an algorithm in the scanner.") respectively.
* **[Mark as a false positive in Container Vulnerability Response](https://servicenow-prod.fluidtopics.net/a2D9Kf9WcAdLSs8k9GIWBA)**   
  Mark a container vulnerable item (CVIT) or remediation task as a false positive if the warning given by the scanner is not actually an issue. For example, if a CVIT has been decommissioned but the scanner is still raising an issue related to it, mark it as a false positive.
* **[Approve a false positive](https://servicenow-prod.fluidtopics.net/ysDomubzSbqRk6EBKObKeQ)**   
  As a false positive approver, you can approve false positive requests from other users.

