Skip to main content

Schedule recurring scans

Scan a repository or a whole git workspace daily or weekly, re-import a git workspace on a cadence, or mail a report on a schedule.

A schedule runs a scan for you on a fixed cadence, daily or weekly at a time you choose. You can schedule a single repository or a whole git workspace, and a git workspace schedule can also re-import its repositories instead of scanning them.

What it is for

Code changes every day, and a scan from last month says little about today. A schedule keeps each repository's findings and security score current without anyone having to remember to start a scan. Scheduled scans run through the same path as a scan you start by hand. Only what started them is different, and every scan records whether it was started manually, by a schedule or from CI.

How it works

  • Vulnara checks for due schedules every minute. When a schedule's time comes, it queues the scan and moves the schedule to its next run.
  • A schedule on a repository scans that repository, on the branch you chose or on its default branch.
  • A schedule on a git workspace scans every enabled repository the git workspace holds at that moment, each on its own default branch. Repositories imported after you created the schedule are included automatically, and disabled ones are skipped.
  • A Sync repositories schedule on a git workspace re-imports its repositories, the same job as Sync now. It uses the git workspace's own valid token at the time it runs, so rotating a token does not break the schedule. A git workspace with no valid token still syncs its public repositories.
  • An Email a report schedule renders a PDF report and mails it. See Reports.
  • When a scheduled scan starts, Vulnara sends a scan-started notification, since nobody is watching the screen when it fires overnight.

What you can set

  • Runs: on a git workspace, choose Scan, Sync repositories or Email a report. A repository schedule always scans.
  • Frequency: Daily or Weekly.
  • Day: the day of the week. Shown only for weekly schedules.
  • Time: the time of day, shown and entered in your own timezone. The zone is named beside the field.
  • Branch: repository schedules only. Leave it blank to scan the default branch.
  • Scanner: one scanner, or leave it on Default scanner. Not offered for a sync.
  • Send to: for a report, one or more email addresses. They do not have to be members of your account.
  • Active: pause a schedule without deleting it, and resume it later.

Do it

  1. Open a repository on the Repositories screen, or a git workspace on the Workspaces screen, and go to the Schedules tab.
  2. Choose Add schedule.
  3. Set the frequency, day and time, and optionally the branch and scanner. On a git workspace, choose what the schedule runs.
  4. Choose Save schedule. The row shows when the next run is due.

Use the switch on a row to pause or resume a schedule, and the delete action to remove it. A paused schedule reads as Paused instead of naming a next run.

With GraphQL, use createScanSchedule, updateScanSchedule, deleteScanSchedule and scanSchedules. The API takes hourUtc and minuteUtc in UTC, dayOfWeek from 0 (Monday) to 6 for weekly schedules, and exactly one of repositoryId or gitEntityId.

graphql
mutation NightlyScan {
  createScanSchedule(
    input: { repositoryId: "<repository-id>", frequency: DAILY, hourUtc: 2, minuteUtc: 30 }
  ) {
    id
    nextRunAt
  }
}

MCP clients can read schedules with scan_schedules and scan_schedule.

Good to know

  • Times are stored in UTC and converted to your timezone for display. A conversion that crosses midnight moves the weekday with it.
  • Creating, changing or deleting a schedule needs the Editor role or above, the same as starting a scan. Viewers can see schedules. See Teams and roles.
  • A schedule cannot be created for a disabled repository.
  • Scheduled scans spend your plan's scan minutes like any other scan. If your plan's limit on parallel scans refuses a repository during a git workspace schedule, the rest of that run is skipped; scans already queued keep running.
  • If one repository in a git workspace schedule cannot be scanned, the others still are.
  • A report that cannot be rendered waits for its next run rather than retrying. Report schedules do not spend scan minutes.
  • There are no cron expressions. Daily or weekly at a set time covers what a schedule can do.

Manage Your Cookie Preferences

We use cookies to enhance your experience. You can accept all cookies, decline non-essential cookies, or manage preferences below. Privacy Policy