Your first scan
Goal: add a repository to your organization, complete a scan, and find the corresponding versions and findings.
Verified on September 13, 2026 against ecbd364. Buttons are quoted using their
actual UI labels. Guide home.
1. Prepare your access
Section titled “1. Prepare your access”Sign in to your instance and select the organization you want to work in. If you do not have access to an organization, follow the available onboarding flow or ask its administrator for an invitation. Accessing private data requires an authenticated session.
Adding a repository or performing a write action requires an authorized role
in that organization, usually member or admin. A read-only role lets you
view results but does not provide the same actions. Your plan may also limit
repository additions or automation.
Choose a repository you know, with dependency files checked into version
control. For example, an npm application with its package.json and
package-lock.json. Importing inventory requires read access on the code
hosting platform. When PR creation is available, it also requires write access
on that platform. Contact support if the action is unavailable.
2. Choose what to track
Section titled “2. Choose what to track”If your repository contains a Dockerfile and your instance includes the
base-image support update, resolved external FROM images are inventoried.
After scanning, open Base images in the repository detail to inspect
end-of-life and pinning checks with file/line, source links, version cycles,
and security-support end dates (or an explicit unknown date). Unresolved
build arguments keep their scan warning; CI may override resolved ARG defaults.
These checks cover base-image support calendars, not image CVEs or OS packages.
For severity, grouping and unavailable-service behavior, see
Docker base images.
The support-date display is covered by automated rendered-output tests for
issue #591 on October 4, 2026;
it does not imply deployment on your instance.
In Repositories → Add repository, distinguish between two uses:
| Choice | Use | Consequence |
|---|---|---|
| A provider under Your repos | Analyze a repository your organization can access | Fixes may change that repository if the integration and format support it |
| Track public repo, under Watch OSS | Monitor a public GitHub product at a given tag or branch | Tracking does not grant permission to modify the upstream project |
The menu offers GitHub, Forgejo / Gitea, GitLab, and Bitbucket. Configuration depends on the provider and instance. This walkthrough covers GitHub and public repository monitoring; a provider appearing in the menu does not guarantee that its integration is already configured.
Import your GitHub repository
Section titled “Import your GitHub repository”Open GitHub. If the connection is available, select the repository from the list, then click Import selected. A repository that is already connected or inaccessible may not appear among the choices. A plan limit may prevent some or all of the import: read the result message before trying again.
If the screen requests authorization, follow the GitHub App installation flow. If the instance administrator has not configured the App, installation is unavailable. Import and scan require real repository access.
Your organization’s verified GitHub App installation provides access to its private repositories once your instance includes this integration update. The App must be installed with read access to the selected repositories and linked to your organization. Signing in with GitHub alone uses identity scopes by default and does not grant private repository access. Background scans use the linked installation without your browser session. If the connection is revoked or GitHub refuses access, ask your organization’s administrator to repair that installation or its repository permissions. An installation with read access is enough to scan. If PR creation is available, it additionally requires write permissions accepted on GitHub.
Find a repository on another connected provider
Section titled “Find a repository on another connected provider”For Forgejo / Gitea, GitLab, or Bitbucket, open the provider and choose Import repos on the relevant connection. Once your instance includes the repository-search update, Search repositories filters the loaded import list immediately by owner or repository name, without regard to letter case. Leading and trailing spaces are ignored. Clear the field to see all importable repositories again; already connected repositories remain excluded.
No repositories match your search. means the filter has no matches, not that the connection has no repositories. The search only covers repositories returned by that connection; it does not request additional results from the provider or change your access permissions.
Selected repositories remain selected even when the filter hides them. The count on Import selected includes all selections, visible or hidden; clear the search to review them before importing. Opening an import list, switching connections, or reopening the dialog clears the search.
Monitor a public product
Section titled “Monitor a public product”Open Track public repo, enter the public GitHub repository, then choose an available reference to track. A tag identifies a named version; a branch may change between scans. Check the reference type and value before confirming.
In the fictional example example/server, tracking v1.2.0 means analyzing
that product reference. It changes neither your installation of the server nor
the upstream repository. The tracked repository shows a Public watch badge.
Public watches use anonymous GitHub access, including metadata, tags, branches
and dependency files. Signing in does not increase their API limit; a GitHub
rate-limit response requires retrying later.
3. Wait for the scan result
Section titled “3. Wait for the scan result”Adding a repository may trigger an initial background scan. Open the repository from Repositories and check its status and Recent scans section. Scan queued means the job is waiting to run; it is not a completed result.
If needed, use Scan from the list or Rescan from the details page. Wait for the job to finish before interpreting the inventory. If it fails, read the error and check repository access and whether the tag or branch still exists. An older inventory still being displayed does not prove the new scan succeeded.
Check the repository, tracked reference, date, and available details of the latest scan. An inventory only result means inventory was obtained without usable vulnerability results in that flow; check coverage and source information before drawing conclusions.
4. Read the three levels of results
Section titled “4. Read the three levels of results”| Where to look | What to check | What this does not prove |
|---|---|---|
| Inventory or inventory on the repository details page | Observed dependency names, versions, and files | That every file and ecosystem in the repository is covered |
| Findings | Matches with vulnerability advisories | That every vulnerability is exploitable in your deployment |
| Queue | Candidate changes and the next action | That every finding has an automatic fix |
Find a dependency whose version you know in Inventory. Then open a finding for that repository, if there is one, and inspect its observed version, indicators, and any Recommended updates. One update can address several findings, so the numbers of findings and updates are not necessarily equal.
Overview aggregates organization data. For this first check, focus on the repository and version you just analyzed: an overall total may include other repositories or older results.
If the result looks empty or inconsistent
Section titled “If the result looks empty or inconsistent”| Situation | Next check |
|---|---|
| Add repository is missing or an action is denied | Active organization, role, and plan limits |
| Repository missing from import | Connection to the correct account, read permissions, repository already added |
| Scan remains queued | Job status; ask an administrator to check scan processing if the wait persists |
| Scan failed | Error message, access to the code hosting platform, reference still exists |
| Empty inventory | Files present at the scanned reference and support for their format |
| Inventory present, no findings | Vulnerability sources, scan coverage, and active filters |
| Finding present, no update | Unknown fixed version, no applicable target, or a limitation in fix generation |
You have completed this walkthrough when the scan is finished and you can identify what it actually inventoried, even if it found no vulnerabilities. Continue with Understand the results, then Remediate a vulnerability.