What it is
After each scan of a push or pull request, SafeWeave adds a check called SafeWeave Security Scan to the commit on GitHub. On pull requests, Cloud and Cloud Plus also add a comment listing the new findings.
Who gets it
| Free | Cloud and Cloud Plus | |
|---|---|---|
| Check with grade and counts | Yes | Yes |
| Marks on the exact lines | Title only | Full description and fix |
| Findings listed in the check, with fix prompts | No | Yes |
| Pull request comment | No | Yes |
How to use it
There's nothing to switch on. Once a repository is connected:
- Push a commit or open a pull request.
- When the scan finishes, open the pull request's Checks tab, or the check icon next to the commit.
- Click SafeWeave Security Scan to see the details.
What you'll see
- The check result. It fails if there's any open critical or high finding, and passes otherwise. Its title shows the grade, for example "Grade B: no critical or high issues".
- The summary. Your grade and score, counts per severity, and what changed since the last scan: new, still open and resolved.
- Line marks. In Files changed, each finding is marked on its line: critical and high as failures, medium as warnings, low as notices.
- The findings list (Cloud and Cloud Plus). Grouped by severity, each with where it is, what it means, the fix, View in SafeWeave, and for critical and high a Fix prompt for your AI assistant you can copy.
- The pull request comment (Cloud and Cloud Plus). "SafeWeave security scan" lists only the findings this pull request introduces, or says there are none. It's updated on each push, not duplicated.
Limits
- Dismissed false positives don't count toward the check.
- To block merging until the check passes, add SafeWeave Security Scan as a required status check in your repository's branch protection settings on GitHub.
If something goes wrong
- No check appears: make sure the repository is connected on Repositories and GitHub shows Connected on Integrations. Then push again.
- The check fails on something that isn't a problem: open it in SafeWeave and click Mark as false positive. See Fixing issues.
- Want the check in CI as well? See GitHub Action.