Skip to content
Published

Last reviewed: 2026-07-31

Scans in CodeCleared

Understand commit-scoped CodeCleared scans, types, credit consumption, status, and wait behavior.

Purpose

A scan evaluates selected checks for one repository commit.

Who

Members review scans; authorized integrations can create them on eligible plans.

Prerequisites

Use a connected repository and an exact commit hash.

How it works

Create or run a scan for a commit, optionally restrict its types or project unit, then review its status until it completes. API clients can use the wait endpoint.

Business rules

Scans are commit-scoped. Types draw from their applicable credit pools after scan preflight succeeds (access and required inputs). A 402 indicates unavailable credits or entitlement, not malformed input.

Governance “latest scan” preference uses sourceTrigger: cli (BYOT lockfile/SBOM upload) outranks api | push | manual-ui, which outrank scheduled (pr-event excluded). See CLI CI gate (BYOT).

Scenarios & edge cases

Wait expires: keep the scan ID and read status later. Partial scan: verify the requested scan types and unit before comparing results. Failed scan: read its status (error / errorCode on each project unit) instead of creating duplicates. See Scan failures.

Limits

API wait requests are bounded; asynchronous workflows should continue from the scan ID.

Common errors

  • Using a branch name as a commit hash.
  • Treating 402 as an authentication failure.
  • Ignoring errorCode on failed units and retrying blindly.

Links