Onam Security

Run a scan

From the console

  1. Open Code Security and choose New Scan Pipeline (or New Security Scan on the Projects page).
  2. Enter the Repository URL and, optionally, a Branch (default main).
  3. Optionally enter a DAST Target URL — a running app or API you are authorised to test.
  4. Choose Start Pipeline.

Static analysis and dependency analysis start together. Dynamic testing starts as well if you gave a target URL. Each runs as its own job, so one can finish before the others.

How the branch is chosen

If you name a branch other than main, that branch is scanned. Otherwise Onam uses the default branch recorded on the connected account, then asks the repository for its default branch, and falls back to main.

What a scan costs in time

Scan time depends mostly on repository size. Each scan job has a one-hour limit; a scan that runs past it is marked failed. Watch progress on the Scan History tab.

From the API

The console calls the same API you can call yourself. See Use it from CI for a worked example, and the API reference for authentication.

CallPurpose
POST /api/v1/secops/sast/scanStart a repository scan (static analysis; dependency analysis starts alongside)
GET /api/v1/secops/sast/scan/{scan_id}/statusPoll status
GET /api/v1/secops/sast/scan/{scan_id}/findingsRead findings, optionally filtered by severity or language
POST /api/v1/secops/dast/scanStart a dynamic test of a target URL

Who can start a scan

Viewing results needs read access to code security (secops:read). Starting scans needs a role that can create scans; read-only roles cannot.