Run a scan
From the console
- Open Code Security and choose New Scan Pipeline (or New Security Scan on the Projects page).
- Enter the Repository URL and, optionally, a Branch (default
main). - Optionally enter a DAST Target URL — a running app or API you are authorised to test.
- Choose Start Pipeline.
Static analysis and dependency analysis start together. Dynamic testing starts as well if you gave a target URL. Each runs as its own job, so one can finish before the others.
How the branch is chosen
If you name a branch other than main, that branch is scanned. Otherwise Onam uses the default branch recorded on the connected account, then asks the repository for its default branch, and falls back to main.
What a scan costs in time
Scan time depends mostly on repository size. Each scan job has a one-hour limit; a scan that runs past it is marked failed. Watch progress on the Scan History tab.
From the API
The console calls the same API you can call yourself. See Use it from CI for a worked example, and the API reference for authentication.
| Call | Purpose |
|---|---|
POST /api/v1/secops/sast/scan | Start a repository scan (static analysis; dependency analysis starts alongside) |
GET /api/v1/secops/sast/scan/{scan_id}/status | Poll status |
GET /api/v1/secops/sast/scan/{scan_id}/findings | Read findings, optionally filtered by severity or language |
POST /api/v1/secops/dast/scan | Start a dynamic test of a target URL |
Who can start a scan
Viewing results needs read access to code security (secops:read). Starting scans needs a role that can create scans; read-only roles cannot.