Skip to main content

Overview

Fixability helps you understand how safe and easy a remediation is expected to be to apply. Some remediations are small, predictable changes. Others may involve major upgrades, possible breaking changes, or uncertainty about ownership and review. Backline calculates Fixability to answer a practical question:
“Can this remediation be applied safely right now?”
This helps security and engineering teams distinguish between remediations that are likely straightforward and those that may require more caution.

Where to Find It

Open a remediation and navigate to: Remediation Side Panel → Overview tab Fixability is displayed alongside Impact and Priority to help explain how Backline ranks remediations.

What Fixability Shows

The Fixability section provides an estimate of the expected safety and effort of applying the remediation. It includes:
  • Fixability badge: Safe, Low Risk, Moderate Risk, or Risky
  • Explanation: Plain-language summary of the main factors affecting the score

Fixability Badges

Backline assigns one of four Fixability badges:

Safe

This remediation is expected to require minimal changes and has a high likelihood of being applied safely.Used when the remediation appears straightforward and low risk.

Low Risk

This remediation may require limited code or configuration changes, but is still likely to be applied safely.Used when the remediation introduces some change, but the expected rollout risk remains relatively low.

Moderate Risk

This remediation may involve compatibility concerns, broader changes, or uncertainty that should be reviewed before applying.Used when the remediation is not clearly unsafe, but deserves closer review.

Risky

This remediation may involve significant change, breaking behavior, or limited ownership confidence.Used when the remediation should be evaluated carefully before proceeding.

How It Works

Fixability is calculated during remediation analysis, before Backline opens a PR and before CI results exist.
Fixability is a predictive signal, not a guarantee. It is designed to support triage and decision-making before implementation starts.

Why This Matters

Fixability helps teams understand whether a remediation is likely to be easy to apply or whether it should be reviewed more carefully. Risk reduction alone does not tell you how safe the change will be. Fixability adds delivery context by estimating the complexity and risk of the remediation itself. This helps teams:
  • identify remediations that are safest to apply now
  • separate straightforward fixes from higher-risk changes
  • explain why a remediation received a lower safety score
  • balance urgency with engineering safety

Best Practices

Use Fixability together with Impact and Priority. A common workflow is:
  1. Review the Fixability badge
  2. Compare the score with Impact
  3. Use Priority to understand how the remediation should rank overall
Fixability should not be interpreted as a guarantee. It is a predictive signal meant to support triage and decision-making before implementation starts.

FAQ

Is Fixability the same as success rate?

No. Fixability is a predictive score that estimates how safe and easy a remediation is expected to be before a PR is opened.

Does Fixability use CI results?

No. Fixability is calculated before CI exists, during remediation analysis.

Why would a remediation have low Fixability?

Common reasons include major upgrades, likely breaking changes, and unclear ownership.

Can a remediation be high impact but low Fixability?

Yes. A remediation may reduce a lot of risk while still being complex or risky to apply.

Priority

Understand how Fixability combines with Impact to determine overall remediation priority

Impact

Learn how Backline measures the security risk reduction of a remediation

Remediations

Understand how remediations work in Backline

Dashboard

View metrics and trends across your organization