Reference F: Pull request scan configuration settings
The repository scan configuration controls whether pull request scanning runs and how it behaves. Configure these settings under Settings → Data Sources & Integrations.
Scan PR
Enabled
Triggers a security scan automatically when a pull request opens or receives a new commit. When disabled, the repository produces no pull request scans and no status checks.
Fail PR on scan error
Disabled
Fails the pull request when a scanner fails, rather than permitting the merge on an incomplete scan.
IaC scanner
Enabled
Determines whether the pull request diff is evaluated for IaC misconfigurations.
SCA scanner
Enabled
Determines whether the pull request diff is evaluated for CVE vulnerabilities, license miscompliance, and package operational risk.
Secrets scanner
Enabled
Determines whether the pull request diff is evaluated for hardcoded credentials.
Exclude Path
Empty
Specifies the files and directories omitted from scanning, entered as a comma-separated list of directory names and wildcard patterns without leading slashes. An excluded path is not evaluated in a pull request scan and cannot block a merge.
Note: Git History Scan and Secrets Validation apply to repository scanning. Tagging Bot supports code-to-cloud tracing, not merge gating.
Last updated
Was this helpful?
