Navigation
Code · Source code scanning Beta

Catch what your code gives away before it ships

An API key committed two years ago, a dependency with a critical CVE, a CI workflow that runs untrusted code: the risks in a repository rarely show in a code review. Connect GitHub or GitLab with read-only access and Code scans your repositories when you connect them, on every push or on a schedule.

01

How it works

Code lives on code.mlab.sh. Sign in with your mlab.sh account: same organization, same members, same roles. Nothing to install.

  1. 01 Connect your code Install the mlab GitHub App or connect a GitLab group. Connecting proves the repositories are yours, private ones included. A public repository can also be proven with a .mlab file.
  2. 02 Scan A quick pass on the default branch in minutes, or a full scan of every branch and the whole history. By hand, or automatically.
  3. 03 Fix what matters first Findings ranked by severity, each linked to the exact file and line, with triage that carries over from one scan to the next.
02

What it finds

What attackers look for first in a repository.

Secrets

Keys and tokens in your files and in the full Git history, shown masked, so you know what to rotate.

Dependencies

Known CVEs in the packages your lockfiles pull in, with the version that fixes them.

Supply chain

Install hooks, obfuscated code and files that run on their own in an editor or an AI assistant.

CI workflows

GitHub Actions open to injection, unpinned actions and excessive permissions.

03

Integrations

GitHub
The mlab GitHub App, on the repositories you pick
GitLab.com
A group or your personal namespace
GitLab Self-Managed
Your own instance, through your own OAuth app

Renamed and transferred repositories keep their history, and each repository page also shows what its forge knows: activity, contributors, branch protection, signed commits and code owners.

04

Automation

On connect
A full scan of every repository the moment it arrives.
On push
A quick scan when the default branch changes.
On a schedule
Daily, weekly or monthly, at the hour you choose.
Webhooks and badges
Scan results to your tools, and a README badge for your repository.
05

Your code stays yours

  • Read-only access: nothing is ever written to your repositories.
  • Your code is read, never executed, in a fresh container for every scan.
  • No copy of your repository is kept, only the findings, with secrets masked.
  • Access is temporary and ends when you disconnect.
06

Beta

Code is in beta: scanners, pages and integrations keep improving, and some things may change along the way. Tell us what you would like to see on GitHub Discussions or through our contact page.