DevSecOps and SAST
Integrate security into your development cycle: Exposia analyzes your repositories with a range of open source tools and reports the findings in the same interface as your network scans.
Benefits
- SAST battery Gitleaks, Semgrep, Trivy, Grype, Bandit, Checkov, Hadolint, TruffleHog, Poutine, OSV-Scanner and more.
- SBOM Syft generates the software inventory of your repositories for dependency traceability.
- Webhook pull request Trigger a scan on GitHub PR/MR to block vulnerabilities before merging.
- AI option In-depth agentic analysis (AI Analysis) opt-in on eligible repositories.
How it works
- 1. Connect Git OAuth or token from Settings → Connectors.
- 2. Track a repository Choose the branches to analyze.
- 3. Launch or automate Manual scan, scheduled or on each pull request.
Frequently asked questions
Does the code stay on Exposia?
Temporary clone for analysis then deletion — no source retention.
Which plan for repositories?
Pro includes 3 repositories; Free 0 — see Pricing.
What does Poutine analyze?
CI/CD files (GitHub Actions, GitLab CI, Azure DevOps, Tekton) for the supply chain.