Last reviewed: 2026-07-31
Scans in CodeCleared
Understand commit-scoped CodeCleared scans, types, credit consumption, status, and wait behavior.
Purpose
A scan evaluates selected checks for one repository commit.
Who
Members review scans; authorized integrations can create them on eligible plans.
Prerequisites
Use a connected repository and an exact commit hash.
How it works
Create or run a scan for a commit, optionally restrict its types or project unit, then review its status until it completes. API clients can use the wait endpoint.
Business rules
Scans are commit-scoped. Types draw from their applicable credit pools after scan preflight succeeds (access and required inputs). A 402 indicates unavailable credits or entitlement, not malformed input.
Governance “latest scan” preference uses sourceTrigger: cli (BYOT lockfile/SBOM upload) outranks api | push | manual-ui, which outrank scheduled (pr-event excluded). See CLI CI gate (BYOT).
Scenarios & edge cases
Wait expires: keep the scan ID and read status later. Partial scan: verify the requested scan types and unit before comparing results. Failed scan: read its status (error / errorCode on each project unit) instead of creating duplicates. See Scan failures.
Limits
API wait requests are bounded; asynchronous workflows should continue from the scan ID.
Common errors
- Using a branch name as a commit hash.
- Treating 402 as an authentication failure.
- Ignoring
errorCodeon failed units and retrying blindly.