BeeraSafe

How scanning works

The five-stage pipeline every scan walks: sync, dependencies, SAST plus secrets, IaC plus containers, risk and policy.

Last updated · September 2026

On this page

Every scan walks the same pipeline: sync the tree, run each analyzer, score the risk, evaluate policies, then notify. Here is what happens at each stage.

StageWhat happens
SyncThe repository tree is read through the GitHub API on the selected branch. Manifests, source files, Dockerfiles, and IaC files are fetched within size budgets.
Dependenciesnpm, pip, and Go manifests are parsed (including lockfiles for transitive dependencies) and matched against live OSV.dev advisories for CVEs and fix versions.
SAST + secretsPattern rules flag injection, XSS, unsafe deserialization, weak crypto, SSRF, and path traversal; entropy plus allow-listed patterns flag exposed credentials without ever displaying full secret values.
IaC + containersTerraform, Kubernetes, Docker, and CloudFormation files are checked for open storage, excessive permissions, missing encryption, and privileged workloads.
Risk + policyFindings roll up into a 0–100 security score per repository. Organization policies decide whether pull-request checks pass or fail.
Accuracy note
Dependency findings come from published advisories and are high-signal. SAST and secret rules are heuristic. Treat them as a starting point for human review, not a final verdict.