Skip to content

Source Code Scanner

Type: source-code
Category: Source Code
Access Mode: AGENT
Produces: algorithm

The source code scanner analyzes codebases to find cryptographic API calls, hardcoded secrets, and crypto library imports. It supports local directories and remote Git repositories.


  • Crypto API calls — function/method invocations that use cryptographic primitives (e.g., Cipher.getInstance("AES/CBC/PKCS5Padding"), hashlib.sha256())
  • Hardcoded keys — secrets, keys, and tokens embedded in source files
  • Crypto library imports — import statements for cryptographic packages
LanguageDetection Coverage
JavaJCA/JCE, BouncyCastle, Spring Security
Pythonhashlib, cryptography, PyCryptodome, ssl
Gocrypto/*, x509, tls
JavaScriptcrypto, node-forge, jose, webcrypto
TypeScriptSame as JavaScript
C#System.Security.Cryptography, BouncyCastle

paths:
- /home/dev/projects/payment-service
- /opt/apps/auth-service/src
excludePaths:
- node_modules
- target
- .git
- vendor
cryptoApiCalls: true
hardcodedKeys: true
importStatements: true
depth: standard
repos:
- url: https://github.com/yourorg/payment-service.git
branch: main
token: ghp_xxxxxxxxxxxx
- url: https://gitlab.internal/team/auth-service.git
branch: develop
username: scanner
token: glpat-xxxxxxxxxxxx
excludePaths:
- node_modules
- vendor
gitBlame: true
depth: deep
paths:
- /opt/apps/legacy-service
repos:
- url: https://github.com/yourorg/new-service.git
branch: main
excludePaths:
- node_modules
- target
- build
- dist

FieldTypeRequiredDefaultDescription
pathsstring listNo*—Local directories to scan
reposobject listNo*—Git repositories to clone and scan
repos[].urlstringYes—HTTPS clone URL
repos[].branchstringNomainBranch to clone
repos[].usernamestringNo—Auth username
repos[].tokenstringNo—Auth token (PAT, app password)
excludePathsstring listNonode_modules, target, .git, vendor, build, distDirectory names to skip
cryptoApiCallsbooleanNotrueDetect crypto API function calls
hardcodedKeysbooleanNotrueDetect hardcoded keys and secrets
importStatementsbooleanNotrueDetect crypto library imports
gitBlamebooleanNofalseEnrich findings with git blame (who introduced it, when)
depthstringNostandardScan depth: shallow, standard, or deep

*At least one of paths or repos is required.


DepthBehavior
shallowFast scan — only import statements and obvious API calls
standardBalanced — API calls, imports, common hardcoded patterns
deepThorough — includes data flow analysis, cross-file resolution, more patterns

Discovered source code findings are viewable in the Source Inspector page, which provides:

  • Per-project breakdown of crypto usage
  • File-level drill-down showing exact line numbers
  • Language distribution across projects
  • Algorithm usage patterns per repository

  • Private repos — Use personal access tokens or deploy keys for authentication
  • Monorepos — Point to the root; excludePaths handles build output
  • CI/CD integration — Run source-code scans as part of your pipeline and import results via the CI/CD import endpoint
  • Git blame — Enable for audit trails showing who introduced crypto usage and when