Diese Seite ist nur auf Englisch verfügbar.
Scanners
The scanners Vulnara runs on your code, what each one finds, and how their results become findings with a severity.
Vulnara runs a set of scanners over your repositories. Each one looks for a different kind of problem, and their results are brought into one set of findings with one severity scale, so you can compare and triage them together.
What it is for
Choosing scanners decides what a scan looks for. By default a scan from the web app runs every scanner, which gives you the fullest picture. Pick fewer when you only care about one kind of issue or want a faster scan.
The scanners
- Ash: finds secrets committed to the repository, such as keys and tokens.
- Bishop: finds personal data in the repository, such as email addresses, credit card numbers, social security numbers and IP addresses.
- Ripley: finds dependencies with known vulnerabilities, by reading the package manifests and lock files in the repository, and also reports secrets it recognises.
Scanners are shown under these names everywhere in the product: in the scan form, in scan results and on each finding. The API returns the scanner catalogue through dockerScanTools, which gives each scanner's id and name. You pass the id when you start a scan.
How it works
- Each commit is checked out and the scanner runs over the files in it. The
.gitdirectory is kept out of the scan, so the scanner never sees your git history or credentials. Files matching your ignore paths are removed before the scanner runs. - Vulnara locates each result in the file it came from, recording the line, column and line content.
- File paths are made consistent across scanners, so the same file reported by two scanners is recognised as the same file.
- Every scanner's own vocabulary is mapped onto one scale:
- Severity: Critical, High, Medium, Low, Info or Unknown.
- Confidence: High, Medium or Low.
- Rules from different scanners that check the same thing are recognised as the same finding, so a secret that two scanners both report shows once. See Deduplication.
- Secret and personal-data findings are recorded for every commit scanned. Dependency findings are recorded for the last commit only, the head of the default branch.
How personal data is graded
- Credit card and social security numbers: Critical, lowered to High when the scanner's confidence is low.
- Email addresses and IP addresses: Medium.
A severity the scale does not recognise is passed through as the scanner reported it, rather than guessed.
What a dependency finding carries
Each dependency finding names the package, its ecosystem, the installed version, the version that fixes it where one exists, and the vulnerability identifier with its aliases.
What you can set
- Scanners: in the scan form, keep or remove scanners. Vulnara starts one scan per scanner.
- Scanner on a schedule: choose one scanner, or leave it on Default scanner. See Schedule recurring scans.
- Ignore paths: keep vendored code, generated files and test fixtures out of every scanner. See Ignore paths.
Do it
- Choose New Scan in the sidebar and pick a repository.
- Under Scanners, keep the ones you want. All are selected by default.
- Choose Start scan.
From the CLI or GraphQL, each scan names one scanner id: start_repository_scan or startRepositoryScan. See Run a scan.
Good to know
- A repository with no package manifest or lock file gives Ripley nothing to check, so it reports no dependency findings.
- If a scanner fails on a commit, that commit is counted as failed and the rest of the scan carries on. A scan fails only when no commit could be scanned.
- Invalid ignore patterns are skipped and the scan runs without removing anything.
- Secret values are masked in the product. See Triage findings.