← Help center

Run a SAST analysis (source code)

Code analysis

  1. Connect Git and follow a repository (see "Connect Git").
  2. Add it as a Git Repository target in Targets if not already done.
  3. Open the repository target detail page.
  4. Run Analyze code (SAST scan): choose the branch and tools (Semgrep, secret detection, SCA, etc. depending on your plan).

Code findings appear in Vulnerabilities and on the target detail page. You can rerun manually or enable pull request monitoring ("PR Watch" article).