Use it from CI
Onam does not ship a CI plugin, GitHub Action, command-line tool or pull-request check today, and it does not post comments on pull requests. A scan reports; it does not fail anything on its own.
If you want a pipeline step that scans and decides, call the same API the console uses.
The pattern
- Start a scan of the branch you built.
- Poll its status until it is no longer
queuedorrunning. - Read the findings, filtered to the severities you care about.
- Decide in your own script whether to fail the job.
Example
Authenticate as described in the API reference, using an account whose role can start scans. Then:
# 1. Start a scan — the response includes secops_scan_id and status "queued"
POST /api/v1/secops/sast/scan
Content-Type: application/json
{"tenant_id": "<your tenant id>", "repo_url": "https://github.com/org/repo", "branch": "release-2.4"}
# 2. Poll until status is completed or failed
GET /api/v1/secops/sast/scan/{secops_scan_id}/status
# 3. Read high-severity findings — the response has "total" and "findings"
GET /api/v1/secops/sast/scan/{secops_scan_id}/findings?severity=highYour script then fails the job if total is above the threshold you choose — for example, any high or critical security issue. Because hotspots are capped at medium, a gate on high and critical only acts on proven findings.
About the fail switch
The scan service has a fail_on_findings option, and it is off by default. It applies only to the service's older folder-scan endpoint, not to repository scans started as above — so for repository scans, the pass/fail decision belongs in your pipeline script.
Things to plan for
- Whole-branch scans. Each scan analyses the full branch; there is no changed-files-only or new-findings-only mode. A gate on "any high finding" will fail on findings that already existed. Start in report-only mode, work the backlog down, then turn the gate on.
- Scan time. Repository size drives it, and the scan job has a one-hour limit. Give the polling step a generous timeout.
- Public repositories. See the note on private repositories in Connect a repository.