An API key committed two years ago, a dependency with a critical CVE, a CI workflow that runs untrusted code: the risks in a repository rarely show in a code review. Connect GitHub or GitLab with read-only access and Code scans your repositories when you connect them, on every push or on a schedule.
Code lives on code.mlab.sh. Sign in with your mlab.sh account: same organization, same members, same roles. Nothing to install.
What attackers look for first in a repository.
Keys and tokens in your files and in the full Git history, shown masked, so you know what to rotate.
Known CVEs in the packages your lockfiles pull in, with the version that fixes them.
Install hooks, obfuscated code and files that run on their own in an editor or an AI assistant.
GitHub Actions open to injection, unpinned actions and excessive permissions.
Renamed and transferred repositories keep their history, and each repository page also shows what its forge knows: activity, contributors, branch protection, signed commits and code owners.
Code is in beta: scanners, pages and integrations keep improving, and some things may change along the way. Tell us what you would like to see on GitHub Discussions or through our contact page.