Skip to main content
Select New scan to open the scan panel. It offers three sources. Each tab takes the same options and the same limits.

Scan a public repository

1

Start a new scan

Select New scan.
2

Pick Public URL

Select the Public URL tab.
3

Paste the address

Enter the repository address, for example https://github.com/owner/repository.
4

Run the scan

Pick your agents and options, then select start scan.
This tab works with public repositories only, and needs no setup. To scan a private repository, connect it first. See Connect GitHub.

Upload an archive

1

Start a new scan

Select New scan.
2

Pick Upload archive

Select the Upload archive tab.
3

Select your file

Select or drop your .zip file. The upload area reads click or drop a .zip.
4

Pick your agents

Pick one or more agents, or leave the field empty to run the base library, the default set.
5

Set options

Select advanced to add exclude patterns or a scope file. See Scan options.
6

Run the scan

Select start scan.

Scan options

Every tab takes the same options.

Agents

The picker groups agents by category and shows how many each one holds. You can work at either level.
  • A whole category. Select + all on a category header to add every agent in it.
  • One agent at a time. Expand a category, then select the agents you want.
Leave the field empty to run the base library, the default set.

Advanced

Select advanced on the scan panel to open these. A scope file can define:
  • Targets. What to scan.
  • Reportable. What counts as a finding.
  • Not reportable. What does not count.
  • Trust model. Who is trusted, and what an attacker controls.

Save a preset

1

Set your options

Pick agents, exclude patterns, or a scope file.
2

Save

Select save current, enter a name, then select save.
Select a saved preset to apply it to a new scan. Select the X next to a preset, then confirm with Delete. Once deleted, a preset does not come back.

Limits

A saved preset stores its scope file at a lower limit than one scan. A file under 1 MB can pass for a single scan and still fail to save as a preset.

A very large repository

One scan runs a bounded amount of work. On a very large repository the platform stops at that bound and finishes with the agents it completed. The rest are held rather than lost, and the scan page offers Continue N capped to run them and add their findings to the same scan. See Manage a scan.

What happens to your code

We do not keep your source code. The platform deletes your uploaded source and every scan artifact 7 days after the scan starts. Your findings stay in the dashboard.