Skip to main content
Every scope has its own automation settings, all on one page. Nothing is on by default, so agents only run where you have asked them to.

Repository scopes

Scheduled scan

A full scan of the repository, daily, weekly or monthly.

Scan on push

Scans the pushed commit range. Overlapping pushes merge into one run.

Re-scan on new CVE

Free hourly monitoring. A dependency check runs when a match is disclosed. See CVE disclosures.

PR reviews

A security review with inline comments on every pull request. See Pull request review.
Enable at least one of Scan on push or PR reviews for every active repository. One catches a problem before it merges, the other catches what reaches your default branch. Without either, new code waits for the next scheduled scan.
You can also refresh a repository’s dependency inventory from here.

Cloud scopes

Accounts, subscriptions and projects support a scheduled full scan, daily, weekly or monthly, and a manual scan at any time.
PR reviews are independent of scan automation. Enabling one never enables the other. Penetration test schedules live on the Set up a pentest page, because they also carry the engagement and package to run.