Remove Tag policy action added to Enterprise Policy Manager

We’ve added a new policy action to Enterprise Policy Manager (EPM): Remove tag. This enables reversible tagging workflows - for example, if a package was previously tagged as risky due to a CVE policy violation but is later cleared because the CVE was withdrawn, downgraded, or assessed as low risk and approved for continued use, you can now remove that tag automatically.

What’s new

  • Configure an EPM policy to remove specific tags through the UI or API.
  • Remove any mutable tag, whether it was added by a policy or manually by a user.

With this addition, you can now create policies that both apply and remove tags as conditions change, enabling policies that keep tags in sync with the current state of risk.

👉 Learn how to build a security tagging workflow in the EPM docs. EPM is currently in Early Access - contact us to get started.

Keep up to date with our monthly product bulletin