Skip to content

Vulnerability report empty states

Problem to solve

We have two different empty states on the Vulnerability Report:

Project level Group level
image Screenshot 2025-11-05 at 5.42.49 PM.png

Proposal

Each of the above designs are appropriate for different use cases, but should be consistent between project and group levels:

  • No scanners enabled, and therefore no vulnerabilities
    • Proposal: Use "No vulnerabilities to report" design (what is currently shown under the group-level empty state)
    • Goal is to encourage scanner adoption/ enablement
  • At least 1 scanner enabled, but no vulnerabilities match the applied filters (the default ones, or ones manually added by the user)
    • Proposal: Use "Sorry, your filter produced no results" design
      • As part of this empty state, could we also include which scanners are enabled and which are not?
Edited by Becka Lippert