OpenSSF Finding and Fixing Vulnerabilities Using AI

5.3 Deduplicate

“Deduplication” is the process of eliminating duplicate reports. External reports and internal analysis may repeatedly identify the same problem. Apply deduplication to prevent duplication of effort.

In practice, you need to deduplicate repeatedly as you learn new information. Projects may deduplicate before validation (to eliminate obvious duplicates that don’t need duplicate validation), and deduplicate again after validation has gained more information.

Some writers consider deduplication part of triage (e.g., [Yan2026]), and others treat them separately. No matter how you define the terms, all are needed.

[Yan2026] recommends the following for deduplication:

If it’s not clear that a finding is a duplicate, pass it along to be validated separately. Once more information is acquired, it may be easier to determine if it’s a duplicate.

Quiz

Q1. According to the guidance in this section, which of the following should most likely be treated as distinct findings rather than duplicates?

  1. The same vulnerability reported at multiple call sites that all trace back to one root cause.
  2. A missing global protection, such as an authentication check, reported separately for each affected endpoint.
  3. A root-cause defect and one of its direct consequences flagged together along the same code path.
  4. The same missing check reported on two different endpoints, where each endpoint requires its own separate fix.
Show answer Answer: D