Onam Security

Use it from CI

Onam does not ship a CI plugin, GitHub Action, command-line tool or pull-request check today, and it does not post comments on pull requests. A scan reports; it does not fail anything on its own.

If you want a pipeline step that scans and decides, call the same API the console uses.

The pattern

  1. Start a scan of the branch you built.
  2. Poll its status until it is no longer queued or running.
  3. Read the findings, filtered to the severities you care about.
  4. Decide in your own script whether to fail the job.

Example

Authenticate as described in the API reference, using an account whose role can start scans. Then:

# 1. Start a scan — the response includes secops_scan_id and status "queued"
POST /api/v1/secops/sast/scan
Content-Type: application/json

{"tenant_id": "<your tenant id>", "repo_url": "https://github.com/org/repo", "branch": "release-2.4"}

# 2. Poll until status is completed or failed
GET /api/v1/secops/sast/scan/{secops_scan_id}/status

# 3. Read high-severity findings — the response has "total" and "findings"
GET /api/v1/secops/sast/scan/{secops_scan_id}/findings?severity=high

Your script then fails the job if total is above the threshold you choose — for example, any high or critical security issue. Because hotspots are capped at medium, a gate on high and critical only acts on proven findings.

About the fail switch

The scan service has a fail_on_findings option, and it is off by default. It applies only to the service's older folder-scan endpoint, not to repository scans started as above — so for repository scans, the pass/fail decision belongs in your pipeline script.

Things to plan for

  • Whole-branch scans. Each scan analyses the full branch; there is no changed-files-only or new-findings-only mode. A gate on "any high finding" will fail on findings that already existed. Start in report-only mode, work the backlog down, then turn the gate on.
  • Scan time. Repository size drives it, and the scan job has a one-hour limit. Give the polling step a generous timeout.
  • Public repositories. See the note on private repositories in Connect a repository.