Accepted Risk Register is one of Understand's built-in reports — run it on your own code from the GUI, or headlessly with und report.
Accepted Risk Register
Languages: AnyTargets: CodeCheck
Every suppressed finding that carries a security disposition, worst first.
Security audits ask for a risk-acceptance log: which findings were silenced on purpose, how severe each one is, what weakness class it falls under, and whether the disposition was Accepted, a False Positive, or something still open. This report lists every suppression whose record carries a Severity, Status or CWE field, ordered by severity, worst first. Suppressions with no security disposition at all are counted so the log cannot silently understate what was silenced.
The records are the ones suppressions already carry (see the Deviation Register).