Description
Sonatype natively recognizes Seal's sealed packages as remediated. A sealed package is the exact version your teams already run, with only the security fix backported, and Sonatype identifies it as fixed instead of matching it back to the vulnerable upstream version.
Because the support is built into Sonatype, there is nothing to install or configure. Whether a scan is run by your own security team, by external auditors, or by your customers, the results reflect the patched state of your software without manual overrides, waivers or version upgrades.
Once a sealed patch is deployed, the vulnerabilities it resolves are cleared from Sonatype's findings. Remediated components no longer trigger policy violations or show up as open findings in your reports, so your compliance posture reflects the work your team has actually done.


