Last reviewed: 2026-07-25
Project units in CodeCleared
Learn how lockfile paths define project units and how monorepos produce separate CodeCleared results.
Purpose
A project unit scopes dependency results to a lockfile and path inside a repository.
Who
Engineers and policy owners reviewing dependency, SBOM, and license results.
Prerequisites
Connect a repository containing a supported lockfile.
How it works
SCA, SBOM, and license views use lockfile/path-scoped units. Secrets and SAST use their own analysis units. A monorepo can therefore have several project units.
Business rules
No lockfile means no SCA project unit. Scans can target a unit by projectUnitId where supported.
Scenarios & edge cases
Empty unit: inspect the selected path and lockfile. Monorepo: select the relevant unit rather than assuming repository-wide dependency results.
Limits
Project units do not make a repository’s source-code findings disappear or merge dependency paths.
Common errors
- Expecting SCA data from a repository with no lockfile.
- Comparing findings across different project-unit paths.