Onam Security

Connect a repository

There are two ways to point Onam at code: connect the repository as an account during onboarding, or give its address directly when you start a scan.

Option 1 — connect it as an account

In Onboarding, choose the code repository type and the provider (GitHub or GitLab in the form today; Bitbucket addresses are also accepted by the scanner). The form asks for:

FieldRequiredNotes
Repository URLYesThe HTTPS clone address, for example https://github.com/org/repo
BranchNoLeave blank to use the repository's default branch, detected on connect
Access tokenNoGitHub personal access token or GitLab access token

A connected repository can be scanned by account, so its URL, branch and scan settings come from the connection rather than being typed each time.

Option 2 — give the address when you scan

The New Security Scan dialog in Code Security takes a repository URL and branch directly. See Run a scan.

Address rules

  • HTTPS only. SSH addresses are not accepted.
  • Allowed hosts. github.com, gitlab.com and bitbucket.org by default.
  • No internal addresses. Private-network and cluster-internal hosts are refused.

Private repositories

Public repositories scan without a token. The connection form accepts a token for private repositories, but scanning a private repository is not reliable today: check that the first scan reaches completed rather than failed, and contact support if it fails to clone. We will update this page when private-repository scanning is fully supported.

What happens to your code

Each scan makes a shallow clone of one branch inside an isolated scan job and deletes it when the scan ends. Onam keeps the findings — file path, line, rule, message and a short code snippet — and the dependency list and SBOM. Vendored dependencies, build output, minified files and files over 512 KB are removed before scanning.