Scans
The dashboard at app.dagsec.net scans any GitHub repository by URL.
Start a scan
Paste a repository URL into the box at the top and click Scan. Accepted forms:
https://github.com/owner/repohttps://github.com/owner/repo.git, with or without a trailing slash
Only https://github.com URLs are accepted. For GitLab and other hosts, use the GitLab template or the CLI.
A scan goes through queued, running, then succeeded or failed. It usually takes seconds; large repositories take longer.
What a dashboard scan does
The repository is cloned with its full history into a temporary directory on the dagsec server, scanned, and deleted. The report is stored with your account.
- Private repositories can be scanned on paid plans when the GitHub App is installed on them.
- Leaked credentials are not checked against their providers in dashboard scans, because anyone can scan any public repository. They are in your own CI and the GitHub App.
- A license policy in the repository's
.dagsec.tomlapplies.
Limits
| Limit | Value |
|---|---|
| Scans per month | 5 Free, 300 Pro, 2,000 Team |
| Repository size | 1 GB, as GitHub reports it. Larger repositories are refused with a suggestion to use the GitHub Action. |
| Scan time | 10 minutes, including the clone |
| Scans started per minute from one IP address | 5 |
The result page
- A headline with the number of serious vulnerabilities, or a pass.
- Leaked secrets: each with its type, file and line, commit, author, masked value, location tag (test, docs, example) and fingerprint, with a Copy ignore line button for
.dagsecignore. - Known vulnerabilities: severity, package and version, advisory, summary and the fixed version.
- Dependencies: each direct dependency's health score.
- Download SBOM: a CycloneDX file. See SBOM export.
The scan list on the left shows your latest 50 scans. Successful scans also feed vulnerability alerts.