▼ Regressed
3
Passed before, failing now
✚ New
2
Failing now, not before
● Still open
13
Failing in both runs
✓ Resolved
2
Failing before, passing now
○ No longer reported
1
Failing before, not in this run
? No longer assessed
1
Failing before, N/A now

Counts are for Bedrock, SageMaker, AgentCore, and AWS Agent Registry. Agentic AI Security and OWASP rows are mostly derived from those findings, so one change can appear in several areas. The table below includes all assessment areas.

Changes by Assessment Area

Assessment AreaRegressedNewStill openResolvedNo longer reportedNo longer assessed
By Service
Bedrock016010
SageMaker102001
AgentCore005200
AWS Agent Registry210000
By Service total3213211
By Lens
Agentic AI Security006100
By Governance Framework
Responsible AI GRC0019000
By Compliance Standard
OWASP Top 10 LLM0022112
Changes
Methodology

Change States

ChangeMeaning
▼ RegressedPassed in the previous run, Failed now.
✚ NewFailed now; N/A or not present in the previous run.
● Still openFailed in both runs.
✓ ResolvedFailed in the previous run, Passed now.
○ No longer reportedFailed in the previous run, not present now.
? No longer assessedFailed in the previous run, N/A now. Not counted as resolved: N/A also covers access-denied and unavailable-region results.
– Not failingNo Failed result in either run. Hidden by default.

How Findings Are Matched

  1. Rows are grouped by assessment area, Region, and Check ID. The Finding title isn't part of the group, because many checks use one title when they fail and another when they pass.
  2. Within a group, rows with the same title and identical details are paired, then rows whose details match once day counts and dates are blanked out, then rows with matching details under a different title.
  3. Two remaining rows are paired if each is its run's only row, in the group or with its title. If both are Failed and their details differ, the row is marked "details changed": one resource may have been fixed and another started failing.
  4. If one run has several Failed rows and the other a single row that isn't Failed, such as a Passed summary, each Failed row is paired with that row.
  5. Anything left is unpaired and shows as New or No longer reported.

The previous run is the most recent usable run saved before this one: its results are complete and, in single-account mode, its run record doesn't say it failed. Only services selected, optional modules enabled, and regions scanned in both runs are compared. The changes CSV records which rule paired each row. See docs/ASSESSMENT_HISTORY.md in the repository.