How Vulnara works
The few ideas behind Vulnara - workspaces, git workspaces, repositories, scans, findings and the security score - and the ways you can reach them.
Vulnara scans your code for leaked secrets, personal data and vulnerable dependencies, and turns what it finds into a list you can work through and a score you can track. This page explains the handful of things Vulnara is built from, so the rest of the documentation makes sense.
What it is for
Everything in Vulnara sits in a simple hierarchy. Once you know it, you know where any screen, command or API call fits:
- Workspace: your team's space in Vulnara. It holds everything below.
- Git workspace: a GitHub or GitLab organisation, group or user that you connect.
- Repository: a repository imported from a git workspace.
- Scan: one scanner run on one repository, on a branch.
- Finding: one problem a scan reported.
- Security score: a number out of 100 that summarises the open findings.
How it works
Workspace
A workspace is the top level. Every repository, scan, finding, token and setting belongs to exactly one workspace, and nobody outside it can see them. You can belong to several workspaces and switch between them from the account menu. The account menu calls a workspace a team, for example Create New Team.
Each member holds a role in the workspace: VIEWER, EDITOR or ADMIN. A higher role includes everything the lower ones can do. See Teams and roles.
Git workspace
A git workspace is where your code lives: a GitHub organisation or user, or a GitLab group or user. You connect it once, on the Workspaces screen in the sidebar. To reach private repositories, you add a git token to it. See Connect GitHub or GitLab.
Repository
When you connect a git workspace, Vulnara imports its repositories with their branches and languages. A repository must be enabled to be scanned, and your plan sets how many can be enabled at once. See Repositories.
Scan
A scan runs one scanner on one repository. Vulnara clones the branch and runs the scanner on it. If you pick several scanners, you start several scans. You can start scans by hand, on a schedule, or from CI. See Run a scan and Scanners.
Finding
A finding is one thing a scan reported: a secret in a file, a piece of personal data, or a dependency with a known advisory. Rules from different scanners that check the same thing are recognised as the same finding, so you work through each problem once. You record a decision on a finding, such as false positive or defer, and that decision survives rescans. See Triage findings.
Security score
Each repository has a security score out of 100, and the workspace has one too. It reflects the open findings from the latest scan of each repository. The dashboard shows it with its trend over the period you choose. See Security score.
Networks
Besides code, Vulnara can scan networks for exposed services. A network is a target you add to your workspace, and a network scan probes it. Network scanning is available through the CLI and the API. See Network scanning.
Ways in
You reach the same workspace, with the same permissions, in five ways:
- Web app: vulnara.rso.dev. Everything a person does day to day.
- CLI: the
vulnaracommand for your terminal and scripts. See CLI. - GitHub Action:
theorigamicorporation/vulnara-action@v1scans a branch in CI and can fail the build. See GitHub Action. - GraphQL API:
https://vulnara-gw.rso.dev/graphql, the API that the web app, the CLI and the action all use. See GraphQL API. - MCP for AI clients:
https://vulnara-mcp.rso.dev/mcplets Claude or ChatGPT read your workspace. It is read-only. See MCP.
Whichever way you use, Vulnara checks your role in the workspace on every request. An AI client or a script can never do more than the person or service account behind it.
Finding your way in the web app
- Sidebar: Dashboard and Vulnerabilities at the top, then Repositories and Workspaces under Assets, Repository Scans under Scan History, Git Tokens and Service Accounts under Access & Security, and Settings at the bottom. New Scan opens the scan form from anywhere. On a narrow screen the sidebar collapses to icons.
- Command palette: press Ctrl + P to search your repositories and other resources, or Ctrl + O to jump to a screen or an action.
- Shareable lists: the page, sort, search and filters of a list are kept in the address bar. Send the link and a colleague in the same workspace sees the same view.
- Theme and date format: choose Light, Dark or System, and a date and time format, in Settings. The choice follows you to other devices.
Good to know
- A button you are not allowed to use is shown disabled, with the role it needs, rather than hidden. That way you know the feature exists and who to ask.
- If the connection to Vulnara drops, an indicator tells you. Live updates, such as scan progress, come back when the connection returns.
- If a screen fails to load, you get an error panel with a way back to the dashboard and a reload button.
- Scanners are always shown by their product names.