Skip to content

Security analysis

Scan types

Choose static, deep, ML-assisted or combined security analysis.

Type Use it for
Static Fast rule-based source analysis and focused feedback
Deep Broader data-flow and query-based analysis where supported
ML Model-assisted prioritization and vulnerability detection
SCA with SBOM Dependency inventory, component vulnerabilities and SBOM evidence
Package Security analysis for supported operating-system or source-host package formats
DAST Runtime host-scan and incident-response data where enabled
All The eligible combination for the project and plan

Coverage varies by language and repository. A deeper scan usually needs more time and build context; an ML result still requires evidence-based triage.

For CI, use the scan mode approved for the branch and fail policy. For release gates, record the exact engines, versions, exclusions and source revision.