Supported scan options
- Available options
- Scan without building, using dependency files
- Scan even when gradle.lock is absent
Scanning with a build
1. Scan an exported SBOM
If the project can be built, generate an SBOM during the build and use its package information for the scan.
2. Scan build artifacts
You can also scan built JAR files or installed node_modules directories.
Scanning without a build
| Language | Dependency files |
|---|---|
| C/C++ |
|
| Dart |
|
| Elixir |
|
| Go |
|
| Haskell |
|
| Java |
|
| JavaScript |
|
| .NET |
|
| PHP |
|
| Python |
|
| R |
|
| Ruby |
|
| Rust |
|
Rust source reachability
Rust SCA uses crates.io packages identified in Cargo.lock together with source-code reachability signals.
- When assessing vulnerabilities, check both use of the relevant APIs and the package version.
- For malicious packages, check whether the project uses the package.
Image and container scanning
You can also scan Docker container images.