Repositories
Add repositories to Vulnara, enable or disable them against your plan, read their branches and languages, and delete them.
A repository is the unit Vulnara scans. Repositories arrive through a git workspace import or are added one at a time by URL, and each one shows its security score, languages, branches and the findings from its latest scans.
What it is for
The Repositories screen is where you see which code you are covering and how it is doing. Use it to find the repositories that need attention, open one to see its posture, decide which repositories count towards your plan, and start scans.

How it works
- Repositories are shown as a board ordered by risk, or as a table. Your choice is remembered.
- The board has three segments: All, Needs attention (security score 0.1 to 40) and Healthy (70 to 100). When any repository needs attention, a banner offers to take you to them.
- Opening a repository shows a drawer with Overview, Scans and Schedules tabs. The overview summarises findings by severity, counting only the latest scan from each scanner, and each severity links to the matching findings.
- The score trend needs at least two scans before it draws a line.
- Branch names come from the provider, using a valid git token from the git workspace when there is one, and anonymously otherwise. If the provider cannot be reached, the branch list is empty rather than an error.
- Languages are read from the provider during import. You can filter by language across all your repositories.
What you can set
- Organization: the git workspace a repository you add by hand belongs to.
- Repository URL: the clone URL. The repository name is suggested from it.
- Repository Name: the name shown in Vulnara.
- Ignore paths: glob patterns to exclude from this repository's scans. See Ignore paths.
- Enabled: whether the repository counts towards your plan and can be scanned.
- Show disabled: include disabled repositories in the list.
Do it
Add a repository
- Open Repositories and choose Add Repository.
- Pick the git workspace, paste the repository URL and check the suggested name.
- Save. The repository appears in the list.
To add every repository in a git workspace at once, import the git workspace instead. See Connect GitHub or GitLab.
Enable or disable a repository
- Open the repository, or select it in the table.
- Switch Enabled on or off.
Delete a repository
- Open the repository's actions and choose Delete.
- Confirm.
The same operations exist in the API:
- GraphQL: createRepository, repositories, repository, repositoryBranches, programmingLanguages, setRepositoryEnabled and deleteRepository.
- CLI: create_repository, repositories, get_repository, programming_languages and delete_repository.
- MCP (read only): repositories, repository and repository_branches.
Good to know
- Your plan sets how many repositories can be enabled at once. An import never fails because of this: repositories beyond the allowance are added disabled. Enabling a repository past the allowance is refused, and the web app offers an upgrade.
- Re-importing a git workspace keeps each existing repository's enabled setting.
- Disabled repositories cannot be scanned or scheduled. Enable them first.
- The scan action is also unavailable when your plan's scan minutes for the month are used up.
- Deleting a repository cancels any scan still pending for it.