Repository scopes
Scheduled scan
A full scan of the repository, daily, weekly or monthly.
Scan on push
Scans the pushed commit range. Overlapping pushes merge into one run.
Re-scan on new CVE
Free hourly monitoring. A dependency check runs when a match is disclosed. See CVE disclosures.
PR reviews
A security review with inline comments on every pull request. See Pull request review.
Enable at least one of Scan on push or PR reviews for every active repository. One catches a problem before it merges, the other catches what reaches your default branch. Without either, new code waits for the next scheduled scan.
Cloud scopes
Accounts, subscriptions and projects support a scheduled full scan, daily, weekly or monthly, and a manual scan at any time.PR reviews are independent of scan automation. Enabling one never enables the other. Penetration test schedules live on the Set up a pentest page, because they also carry the engagement and package to run.