For the complete documentation index, see llms.txt. This page is also available as Markdown.

Reference F: Pull request scan configuration settings

The repository scan configuration controls whether pull request scanning runs and how it behaves. Configure these settings under SettingsData Sources & Integrations.

Setting
Default
Description

Scan PR

Enabled

Triggers a security scan automatically when a pull request opens or receives a new commit. When disabled, the repository produces no pull request scans and no status checks.

Fail PR on scan error

Disabled

Fails the pull request when a scanner fails, rather than permitting the merge on an incomplete scan.

IaC scanner

Enabled

Determines whether the pull request diff is evaluated for IaC misconfigurations.

SCA scanner

Enabled

Determines whether the pull request diff is evaluated for CVE vulnerabilities, license miscompliance, and package operational risk.

Secrets scanner

Enabled

Determines whether the pull request diff is evaluated for hardcoded credentials.

Exclude Path

Empty

Specifies the files and directories omitted from scanning, entered as a comma-separated list of directory names and wildcard patterns without leading slashes. An excluded path is not evaluated in a pull request scan and cannot block a merge.

Note: Git History Scan and Secrets Validation apply to repository scanning. Tagging Bot supports code-to-cloud tracing, not merge gating.

Last updated

Was this helpful?