Skip to content
Published

Last reviewed: 2026-07-25

Project units in CodeCleared

Learn how lockfile paths define project units and how monorepos produce separate CodeCleared results.

Purpose

A project unit scopes dependency results to a lockfile and path inside a repository.

Who

Engineers and policy owners reviewing dependency, SBOM, and license results.

Prerequisites

Connect a repository containing a supported lockfile.

How it works

SCA, SBOM, and license views use lockfile/path-scoped units. Secrets and SAST use their own analysis units. A monorepo can therefore have several project units.

Business rules

No lockfile means no SCA project unit. Scans can target a unit by projectUnitId where supported.

Scenarios & edge cases

Empty unit: inspect the selected path and lockfile. Monorepo: select the relevant unit rather than assuming repository-wide dependency results.

Limits

Project units do not make a repository’s source-code findings disappear or merge dependency paths.

Common errors

  • Expecting SCA data from a repository with no lockfile.
  • Comparing findings across different project-unit paths.

Links