Troubleshooting
"Shallow clone detected"
The checkout has only recent commits, so older secrets can't be found. Set fetch-depth: 0 on actions/checkout, or GIT_DEPTH: "0" on GitLab.
"api-key is empty"
The DAGSEC_API_KEY secret isn't set, or the workflow runs for a pull request from a fork, which GitHub doesn't give secrets to. Add the secret, or use the GitHub App for repositories with outside contributors.
"the Free plan needs a CI identity token…"
On the Free plan dagsec must confirm the repository is public. On GitHub add id-token: write to the workflow's permissions. On gitlab.com use the dagsec template, which requests the token. Self-managed GitLab and the CLI need a paid plan.
"scanning private repositories needs the Pro plan" (402)
The repository is private and the account is on the Free plan.
"…are used up; they reset on the 1st" (429)
The plan's monthly limit is reached. See Plans and limits.
"too many requests; try again in N seconds" (429)
A per-minute rate limit. Wait and retry.
"dagsec runs on Linux x64 runners"
The scanner is built for x86-64 Linux. Use runs-on: ubuntu-latest, or an x86-64 GitLab runner.
"Could not post the dagsec comment"
The workflow lacks pull-requests: write. On GitLab, check that DAGSEC_GITLAB_TOKEN has the api scope and at least the Reporter role.
"this repository is N MB; dashboard scans are limited to 1000 MB"
Scan it with the GitHub Action on your own runner instead.
"the scan took longer than 10 minutes and was stopped"
The repository's history is very large. Use the Action, where there's no time limit beyond your runner's.
"vulnerability check unavailable"
OSV.dev couldn't be reached during the scan. Vulnerabilities don't fail that scan; run it again.
A finding is a false positive
Add its fingerprint to .dagsecignore on the default branch.
A dependency is missing from the report
Check that its file is supported, that it pins an exact version, and that it isn't under a skipped directory such as vendor or build.
The AI agent installed something dagsec should have stopped
Check that the command is one the integration sees (Claude Code, Cursor), that the API key is valid, and that the month's agent checks aren't used up. When dagsec can't be reached, installs proceed by design.