DevSecOps and SAST

Integrate security into your development cycle: Exposia analyzes your repositories with a range of open source tools and reports the findings in the same interface as your network scans.

Benefits

  • SAST battery Gitleaks, Semgrep, Trivy, Grype, Bandit, Checkov, Hadolint, TruffleHog, Poutine, OSV-Scanner and more.
  • SBOM Syft generates the software inventory of your repositories for dependency traceability.
  • Webhook pull request Trigger a scan on GitHub PR/MR to block vulnerabilities before merging.
  • AI option In-depth agentic analysis (AI Analysis) opt-in on eligible repositories.

How it works

  1. 1. Connect Git OAuth or token from Settings → Connectors.
  2. 2. Track a repository Choose the branches to analyze.
  3. 3. Launch or automate Manual scan, scheduled or on each pull request.

Frequently asked questions

Does the code stay on Exposia?

Temporary clone for analysis then deletion — no source retention.

Which plan for repositories?

Pro includes 3 repositories; Free 0 — see Pricing.

What does Poutine analyze?

CI/CD files (GitHub Actions, GitLab CI, Azure DevOps, Tekton) for the supply chain.