How scanning works
The five-stage pipeline every scan walks: sync, dependencies, SAST plus secrets, IaC plus containers, risk and policy.
Last updated · September 2026
On this page
Every scan walks the same pipeline: sync the tree, run each analyzer, score the risk, evaluate policies, then notify. Here is what happens at each stage.
| Stage | What happens |
|---|---|
| Sync | The repository tree is read through the GitHub API on the selected branch. Manifests, source files, Dockerfiles, and IaC files are fetched within size budgets. |
| Dependencies | npm, pip, and Go manifests are parsed (including lockfiles for transitive dependencies) and matched against live OSV.dev advisories for CVEs and fix versions. |
| SAST + secrets | Pattern rules flag injection, XSS, unsafe deserialization, weak crypto, SSRF, and path traversal; entropy plus allow-listed patterns flag exposed credentials without ever displaying full secret values. |
| IaC + containers | Terraform, Kubernetes, Docker, and CloudFormation files are checked for open storage, excessive permissions, missing encryption, and privileged workloads. |
| Risk + policy | Findings roll up into a 0–100 security score per repository. Organization policies decide whether pull-request checks pass or fail. |
Accuracy note
Dependency findings come from published advisories and are high-signal. SAST and secret rules are heuristic. Treat them as a starting point for human review, not a final verdict.
Was this page helpful?

