Skip to main content

Quick start for security and non-technical users

Sign in, connect GitHub, run your first scan, read the dashboard and security score, triage a finding, download a PDF report and set an alert rule.

This guide takes you from signing in to your first scan results, all in the web app, with no code. By the end you will have a security score for your repositories, a triaged finding, a PDF report and an alert rule that tells you when scans finish.

  1. Sign in

    Open vulnara.rso.dev and choose Sign In. Vulnara is invite-only: if you do not have an account yet, ask your workspace admin to invite you, or choose Request access.

    A new workspace shows Get started with Vulnara, with three steps: connect a workspace, import repositories and run your first scan. The rest of this guide follows them.

  2. Connect GitHub

    Open Workspaces in the sidebar and choose Add Workspace.

    • Workspace: type your GitHub organisation or user name, or paste its URL. Vulnara detects the provider.
    • Automatically add repositories: leave it on, so the repositories are imported straight away.
    • Access token: optional. Without one, only public repositories are imported. To include private ones, paste a GitHub token with the repo scope.
    • Tick the box confirming that you own the workspace or have permission to scan it.

    Choose Add Workspace. The import runs in the background and repositories appear as they arrive. See Connect GitHub or GitLab for tokens and GitLab.

  3. Pick your repositories

    Open Repositories. Each imported repository has an enabled switch. Only enabled repositories can be scanned, and your plan sets how many can be enabled at once. Turn on the ones you care about. See Repositories.

  4. Run a scan

    Choose New Scan in the sidebar. The Scan a repository form opens. Pick the workspace and the repository. Every scanner is selected for you. Leave the branch empty to scan all branches, or pick one. Choose Start scan.

    Vulnara starts one scan per scanner and takes you to Repository Scans. Progress shows in the tasks bar, and you are notified when each scan finishes. See Run a scan.

  5. Read the dashboard

    Open Dashboard. At the top is your workspace's Security score, out of 100. Below it:

    • Security score over time: the trend for the period.
    • Needs attention: the repositories and findings to look at first.
    • Remediation: how many findings have been fixed or decided.
    • How long findings have been open: the age of what is still open.
    • Plan usage this cycle: how much of your plan you have used.

    Switch the period between 7, 30 and 90 days. The score and open findings always show the current state. The period sets what they are compared against and the range of the trend and activity charts. See Dashboard and Security score.

    The Vulnara dashboard with the security score, its trend and the needs-attention list
  6. Triage a finding

    Open Vulnerabilities to see every finding in the workspace. Open a finding and choose Triage. Pick a decision:

    • False positive: the scanner was wrong.
    • Not affected: a real advisory that cannot be exploited here. You pick a justification. Offered for dependency findings only.
    • Already dealt with: it was real and has been handled, for example a leaked key that was rotated.
    • Will not fix: real, and you choose to carry it. You set a review date.
    • Defer: real, but not this cycle. You set a review date.

    Add a reason if you like, then choose Save decision. The first three decisions take the finding out of the security score. Will not fix and Defer hide it from the open list but keep counting it, because the risk is still there. See Triage findings.

  7. Download a PDF report

    On the Dashboard, choose Download report. Vulnara generates a PDF security summary of the workspace and your browser saves it. See Reports.

  8. Set an alert rule

    Open Settings, then Alert Rules, and choose Create Alert Rule.

    • Channel Type: Email, Webhook, Slack, Discord or Telegram.
    • Emails: pick team members by name or type any address, such as a shared inbox.
    • Scopes: the events that trigger the alert, such as Scan Completed and Scan Failed for repositories.

    Choose Create, then Send test to check that the message arrives. Creating alert rules needs the EDITOR role. See Alerts.

Good to know

  • Starting scans, triaging and creating alert rules need the EDITOR role. With the VIEWER role you can read everything, and those buttons show as disabled with the role they need.
  • A triage decision is stored against the finding itself, so it survives rescans and covers every scanner that reports the same thing.
  • If you are near your plan's limits, the dashboard's plan usage card links to billing. See Plans and billing.

Next steps

Manage Your Cookie Preferences

We use cookies to enhance your experience. You can accept all cookies, decline non-essential cookies, or manage preferences below. Privacy Policy