Scan types
MODE
The default is sast.
| MODE | Description |
|---|---|
| sast | Code scanning |
| secret | Secret scanning |
| iac | Infrastructure as code (IaC) scanning |
| all | Run SAST → Secret → IaC in order |
TIMEOUT
The total execution limit, in seconds. The default is 600 seconds (10 minutes) for MODE=all and 360 seconds (6 minutes) for a single scan. Setting TIMEOUT overrides the default. Set the CI job timeout higher than this value.
LANG
Use the LANG environment variable to choose the language of SAST, Secret, and IaC findings and comments on pull requests or merge requests.
If unset or unsupported, the default is KO. Values are case-insensitive; surrounding whitespace is ignored.
| LANG | Comment language |
|---|---|
KO |
Korean |
EN |
English |
JP |
Japanese |
LEVEL
The default is none.
The security job fails when findings at or above LEVEL occur within the scan scope. For PRs/MRs, required-check settings determine whether this blocks merging. In branch push pipelines, it can block subsequent builds and deployments. Use lowercase values, such as LEVEL=medium. If unset or none, findings alone do not fail the job.
This applies to SAST, Secret, IaC, and MODE=all. With MODE=all, a blocking result prevents later scanners from running. warning is equivalent to high; error is equivalent to critical.
| LEVEL |
|---|
| none |
| any |
| info |
| low |
| medium |
| high |
| critical |
AUDIT LEVEL
For IaC, AUDIT_LEVEL excludes results below the specified severity.
For example, AUDIT_LEVEL=medium excludes low and info findings.
| AUDIT_LEVEL |
|---|
| info |
| low |
| medium |
| high |
Push pipelines without a PR/MR
You can enforce LEVEL without creating a PR/MR when a system pushes source code and then builds and deploys it. This supports GitHub branch push events and GitLab branch pipelines with CI_PIPELINE_SOURCE=push. It does not apply to tag pushes, scheduled runs, or manual runs.
SAST and IaC use findings on lines added or modified by the push to decide whether to block. Existing findings on unchanged lines in the same file are excluded from that decision. Secret also checks commits introduced by the push, so a secret added in an intermediate commit can block the job even if removed in the final commit. Secrets reintroduced by a force push are also checked.
Regular and force pushes compare the commits before and after the push. A new branch is compared with its common ancestor with the default branch; the first push to the default branch is compared with an empty repository.
Push scans require XEIZE_TOKEN; a PR/MR comment token is unnecessary. Results appear in the job log. See the GitLab Workflow and GitHub Actions examples.
LOG_FINDINGS
LOG_FINDINGS=pretty (or 1, true) prints a table with severity colors; json prints JSON Lines. Leaving it unset or using 0 or false disables this output.
The table includes LEVEL, finding counts, descriptions, locations, and documentation links. SAST includes matched code, source/sink information, and call flows. IaC includes supplied actual/expected values and remediation suggestions from MR/PR comments.
Secret groups identical values and links their hardcoded locations and commit history. Values are masked as abc***xyz; short or unavailable values appear as ***. Choose the table language with LANG=KO, EN, or JP, and disable colors with NO_COLOR=1.
This setting does not change the LEVEL failure decision. Output can include results before filtering by changed lines, so not every printed finding blocks the job.