Skip to main content
1

Set up a provider

Pick a provider and paste a credential.
2

Run a scan

The validate, score, and dedup phases run by default.
3

Read the status

Read what the scan found.
4

Browse the findings

Browse the findings in a local web UI.
5

Scan only what changed

To scan only the files a pull request changed, see Scan a pull request.

Where the findings go

A scan writes its findings to the output directory.
Read more about this directory on the output and state page.