Onam Security

Code Security — overview

Onam Code Security scans the things that build your applications: source code, dependencies, infrastructure-as-code templates and — if you give it a URL — the running application itself. It lives in the same console as Onam's cloud posture, identity and data engines, under the same login and roles.

How a code scan flows, from repository to reviewed fix
How a code scan flows, from repository to reviewed fix

What a scan does

ScannerWhat it readsWhat it produces
Static analysis (SAST)Source files in Python, JavaScript, TypeScript, Java, C#, Go, C, C++ and RubySecurity issues (proven by taint or AST rules) and hotspots to review (pattern matches)
Secret detectionEvery file in the cloneHard-coded credentials, keys and tokens
IaC checksTerraform, YAML (Kubernetes, CloudFormation), JSON and DockerfilesMisconfigurations in templates and images
Dependencies and SBOM (SCA)Manifests and lockfiles, or an uploaded SBOMVulnerable packages with a 0–10 risk score, and a CycloneDX 1.5 SBOM
Dynamic testing (DAST)A running web app or API, from its URLFindings per endpoint, exportable as JSON, HTML or SARIF

Static analysis, secret detection, IaC checks and dependency analysis run on every repository scan. Dynamic testing runs only when the scan includes a target URL.

How it fits with the rest of Onam

  • Same platform, same roles. Code findings are read and scans started with the same role-based access as every other engine.
  • Posture score. SAST and DAST results feed the AppSec pillar of the CNAPP posture score.
  • Shared advisories. Dependency findings are matched against the same OSV and NVD advisory store the Vulnerability engine uses.
  • Findings store. Static-analysis findings are also written to the platform-wide findings store, tagged as code, with the file path as the resource.

What it does not do yet: link a code finding to the container image or cloud workload built from that repository, tell you whether a vulnerable dependency function is actually called, or trace a runtime misconfiguration back to its template line. Plan around those gaps rather than assume them away.

Fixing what it finds

Every finding carries the rule's guidance and an AI fix prompt you can copy into your own assistant. For static-analysis findings, AI Code Fix can rewrite the affected files and push them to a separate branch for your review.

Where to go next

  1. Connect a repository
  2. Run a scan
  3. Read the results
  4. Use it from CI