Skip to content

Scans ​

The dashboard at app.dagsec.net scans any GitHub repository by URL.

Start a scan ​

Paste a repository URL into the box at the top and click Scan. Accepted forms:

  • https://github.com/owner/repo
  • https://github.com/owner/repo.git, with or without a trailing slash

Only https://github.com URLs are accepted. For GitLab and other hosts, use the GitLab template or the CLI.

A scan goes through queued, running, then succeeded or failed. It usually takes seconds; large repositories take longer.

What a dashboard scan does ​

The repository is cloned with its full history into a temporary directory on the dagsec server, scanned, and deleted. The report is stored with your account.

  • Private repositories can be scanned on paid plans when the GitHub App is installed on them.
  • Leaked credentials are not checked against their providers in dashboard scans, because anyone can scan any public repository. They are in your own CI and the GitHub App.
  • A license policy in the repository's .dagsec.toml applies.

Limits ​

LimitValue
Scans per month5 Free, 300 Pro, 2,000 Team
Repository size1 GB, as GitHub reports it. Larger repositories are refused with a suggestion to use the GitHub Action.
Scan time10 minutes, including the clone
Scans started per minute from one IP address5

The result page ​

  • A headline with the number of serious vulnerabilities, or a pass.
  • Leaked secrets: each with its type, file and line, commit, author, masked value, location tag (test, docs, example) and fingerprint, with a Copy ignore line button for .dagsecignore.
  • Known vulnerabilities: severity, package and version, advisory, summary and the fixed version.
  • Dependencies: each direct dependency's health score.
  • Download SBOM: a CycloneDX file. See SBOM export.

The scan list on the left shows your latest 50 scans. Successful scans also feed vulnerability alerts.