Prerequisites
- You must be signed in to XEIZE.
- You must have access to the target project.
- The scan feature you want to use must be enabled.
- Insider threat scans may also require an AI model (LLM) connection, depending on the environment configured by your administrator.
A scan without the required feature permissions or AI model connection displays a lock icon and the reason.
Available scans
| Category | UI label | Required feature | Main results locations |
|---|---|---|---|
| Secrets | SECRET |
SAST | Projects > Issues, Issues > SECRET |
| Source code | SAST |
SAST | Projects > Issues, Issues > SAST |
| Open source | SCA |
SCA | Projects > Issues, Issues > SCA, Supply Chain > SCA |
| Infrastructure configuration | IAC |
SAST | Projects > Issues, Issues > IaC |
| Licenses | LICENSE |
SCA | Licenses |
| Route analysis | ROUTE |
Any of SAST, API, or DAST | Project row: Extensions > View > Route |
| Insider threats | MCP |
SAST and AI, plus an AI model connection if needed | Insider Threat > MCP |
| Insider threats | Skill |
SAST and AI, plus an AI model connection if needed | Insider Threat > Skill |
| Insider threats | Repository |
SAST and AI, plus an AI model connection if needed | Insider Threat > Repo |
Running ROUTE requires access to at least one of source code security (SAST), API security, or dynamic web application security testing (DAST).
The log analysis feature LOGALYZER cannot run from this dialog. Use the separate traffic-log import feature.
Scan one project
Menu path: Projects > Overview
- Open the more menu on the right of the project row.
- Select
Run Scan. - Select one or more scan types in
Choose Scanner. - Hover over a locked item's icon to see the required feature or AI model connection.
- Select
Scan. - Check for the
Scan queuedmessage.
Scan queued means the request was received, not that the scan is complete. If a job for the same project and scan type is already Pending or Running, a new job may not be added. Check Jobs to confirm job creation and the final status.
Scan multiple projects
- Select the checkboxes for the projects in
Projects > Overview. - Select
Run Scan (N)above the table. - Select one or more scan types.
- Select
Scan.
A job is created for each selected scan type for each project. Selecting two projects and three scan types creates up to six jobs.
Scan immediately after registration
Registering projects through GitHub, GitLab, Bitbucket, or Manual Upload automatically opens Choose Scanner.
Scan: Creates scan jobs for the selected new projects.Skip Scan: Registers the projects without creating jobs.
A scan-started message may appear even when you select Skip Scan, but no new job is created. Check existing scan status in Projects or Jobs.
Run a Route scan directly
You can select Route in the normal Run Scan dialog. The project row menu also provides these shortcuts:
- Run:
Projects > project row > more menu > Extensions > Run > Route - View results:
Projects > project row > more menu > Extensions > View > Route
If there is no completed Route scan, a no-data message appears.
The Route row shortcut does not display a lock state in advance. If you lack the required feature permissions, no job is created.
Check status in Projects
The Scan column in Projects > Overview summarizes the latest scan results for each project.
| Status | Meaning |
|---|---|
No History |
No scan history has been created. |
Pending |
At least one job is waiting. |
Running |
At least one job is running. |
Success |
The latest jobs for all displayed scan types have completed. |
Failed |
The latest jobs have all failed or been canceled. |
Partial |
Some jobs succeeded; others failed or were canceled. |
When jobs have different statuses, the summary uses this precedence: Running, Pending, then completed results.
Hover over the Scan status to view the following for each scan type:
- Individual status
- Completion time and duration
- Start time
- Reason for failure or cancellation
The Projects list refreshes status about every five seconds. Canceled jobs count as failures in the Projects summary but appear separately as Cancelled in Jobs.
Select a project name to open its open issues. Select a severity badge to filter by both project and severity.
View details in Jobs
Menu path: Jobs
Jobs opens in Live mode by default and refreshes automatically about every five seconds.
- The default time range is the last 10 days.
- You can filter by job ID, project,
Domain, and status. - You can view the project and branch, scan type, creation time, status, and duration.
- Hover over a failed or canceled status to see a summarized reason.
- The
ReasonandUpdated Atcolumns are hidden by default. Enable them in the column settings.
Signed-in users can cancel accessible Pending or Running jobs from the row menu. Only Admins and Super Admins can delete jobs.
View results
- First, confirm that the job is
FinishedinJobs. - View vulnerability scan results in
Projects > Issuesor the scan-specific Issues menu in the sidebar. - SCA packages and vulnerability groups are also available in
Supply Chain > SCA. - View license results in
Licenses. - View insider threat results under MCP, Skill, or Repo in
Insider Threat. - Open Route results through
Extensions > View > Routein the project row.
For a list of the software components in a project, see Generate and download an SBOM.
Troubleshooting
| Displayed reason | What to check |
|---|---|
| Integration token invalid or expired | Have a Super Admin update the Git service connection and check token expiration and repository access. |
| Scanner authentication failed | Check the API token used to connect to the XEIZE server and the authentication settings in your on-premises installation. |
| License expired | Renew the product license and permission to use the scan feature. |
| Timeout | Have an Admin check the maximum runtime in the project details and increase it if needed. |
| Resource limit | Reduce the scan scope or check the scan server's CPU and memory capacity. |
| SCA found no supported packages | Check that files containing package information are included in the project. |
| Scanner configuration or rules failed | Check the installed scan rules and configuration. |
| Route input failed | Check supported frameworks and the Route input. |
| AI configuration failed | Check the token, model, and connection status used for the AI model. |
Admins and Super Admins can select a project row and set the maximum runtime for each scan in the General tab of the details dialog. A manually configured limit must be at least 60 seconds.