Run project scans

Select projects in Projects to run scans and view progress and results. Supported languages, file formats, and coverage vary by scan type.

Prerequisites

  • You must be signed in to XEIZE.
  • You must have access to the target project.
  • The scan feature you want to use must be enabled.
  • Insider threat scans may also require an AI model (LLM) connection, depending on the environment configured by your administrator.

A scan without the required feature permissions or AI model connection displays a lock icon and the reason.

Available scans

Category UI label Required feature Main results locations
Secrets SECRET SAST Projects > Issues, Issues > SECRET
Source code SAST SAST Projects > Issues, Issues > SAST
Open source SCA SCA Projects > Issues, Issues > SCA, Supply Chain > SCA
Infrastructure configuration IAC SAST Projects > Issues, Issues > IaC
Licenses LICENSE SCA Licenses
Route analysis ROUTE Any of SAST, API, or DAST Project row: Extensions > View > Route
Insider threats MCP SAST and AI, plus an AI model connection if needed Insider Threat > MCP
Insider threats Skill SAST and AI, plus an AI model connection if needed Insider Threat > Skill
Insider threats Repository SAST and AI, plus an AI model connection if needed Insider Threat > Repo

Running ROUTE requires access to at least one of source code security (SAST), API security, or dynamic web application security testing (DAST).

The log analysis feature LOGALYZER cannot run from this dialog. Use the separate traffic-log import feature.

Scan one project

Menu path: Projects > Overview

  1. Open the more menu on the right of the project row.
  2. Select Run Scan.
  3. Select one or more scan types in Choose Scanner.
  4. Hover over a locked item's icon to see the required feature or AI model connection.
  5. Select Scan.
  6. Check for the Scan queued message.

Scan queued means the request was received, not that the scan is complete. If a job for the same project and scan type is already Pending or Running, a new job may not be added. Check Jobs to confirm job creation and the final status.

Scan multiple projects

  1. Select the checkboxes for the projects in Projects > Overview.
  2. Select Run Scan (N) above the table.
  3. Select one or more scan types.
  4. Select Scan.

A job is created for each selected scan type for each project. Selecting two projects and three scan types creates up to six jobs.

Scan immediately after registration

Registering projects through GitHub, GitLab, Bitbucket, or Manual Upload automatically opens Choose Scanner.

  • Scan: Creates scan jobs for the selected new projects.
  • Skip Scan: Registers the projects without creating jobs.

A scan-started message may appear even when you select Skip Scan, but no new job is created. Check existing scan status in Projects or Jobs.

Run a Route scan directly

You can select Route in the normal Run Scan dialog. The project row menu also provides these shortcuts:

  • Run: Projects > project row > more menu > Extensions > Run > Route
  • View results: Projects > project row > more menu > Extensions > View > Route

If there is no completed Route scan, a no-data message appears.

The Route row shortcut does not display a lock state in advance. If you lack the required feature permissions, no job is created.

Check status in Projects

The Scan column in Projects > Overview summarizes the latest scan results for each project.

Status Meaning
No History No scan history has been created.
Pending At least one job is waiting.
Running At least one job is running.
Success The latest jobs for all displayed scan types have completed.
Failed The latest jobs have all failed or been canceled.
Partial Some jobs succeeded; others failed or were canceled.

When jobs have different statuses, the summary uses this precedence: Running, Pending, then completed results.

Hover over the Scan status to view the following for each scan type:

  • Individual status
  • Completion time and duration
  • Start time
  • Reason for failure or cancellation

The Projects list refreshes status about every five seconds. Canceled jobs count as failures in the Projects summary but appear separately as Cancelled in Jobs.

Select a project name to open its open issues. Select a severity badge to filter by both project and severity.

View details in Jobs

Menu path: Jobs

Jobs opens in Live mode by default and refreshes automatically about every five seconds.

  • The default time range is the last 10 days.
  • You can filter by job ID, project, Domain, and status.
  • You can view the project and branch, scan type, creation time, status, and duration.
  • Hover over a failed or canceled status to see a summarized reason.
  • The Reason and Updated At columns are hidden by default. Enable them in the column settings.

Signed-in users can cancel accessible Pending or Running jobs from the row menu. Only Admins and Super Admins can delete jobs.

View results

  1. First, confirm that the job is Finished in Jobs.
  2. View vulnerability scan results in Projects > Issues or the scan-specific Issues menu in the sidebar.
  3. SCA packages and vulnerability groups are also available in Supply Chain > SCA.
  4. View license results in Licenses.
  5. View insider threat results under MCP, Skill, or Repo in Insider Threat.
  6. Open Route results through Extensions > View > Route in the project row.

For a list of the software components in a project, see Generate and download an SBOM.

Troubleshooting

Displayed reason What to check
Integration token invalid or expired Have a Super Admin update the Git service connection and check token expiration and repository access.
Scanner authentication failed Check the API token used to connect to the XEIZE server and the authentication settings in your on-premises installation.
License expired Renew the product license and permission to use the scan feature.
Timeout Have an Admin check the maximum runtime in the project details and increase it if needed.
Resource limit Reduce the scan scope or check the scan server's CPU and memory capacity.
SCA found no supported packages Check that files containing package information are included in the project.
Scanner configuration or rules failed Check the installed scan rules and configuration.
Route input failed Check supported frameworks and the Route input.
AI configuration failed Check the token, model, and connection status used for the AI model.

Admins and Super Admins can select a project row and set the maximum runtime for each scan in the General tab of the details dialog. A manually configured limit must be at least 60 seconds.