Last reviewed: 2026-07-28
Source code security
Run source code security checks on SAST project units with separate credits and understand add-ons, included plans, and 402 responses.
Source code security is separately metered
Source code security scans the sast project unit and uses a dedicated SAST credit pool. It is not funded by core dependency credits. Regulated agreements may include SAST; Starter and Team can add it to their plan.
Before you run a scan
Confirm that the repository has a SAST project unit and that your organization has SAST entitlement and credits. Request only the scan types your workflow needs, then review the source location, data flow, and commit before triaging a finding.
Organization SAST rules live under Settings → SAST rules with URL tabs Stock (?tab=stock) and Custom (?tab=custom). Repository overrides use the same tabs on the repo SAST config page.
Finding triage (ignore)
Prefer the narrowest ignore:
- Occurrence — one finding (or a selected set of N findings).
- Entire rule — every match of that rule in the project unit. Broader; use only when justified.
Organization triage, admins, and owners can ignore. Members cannot.
A 402 has a specific meaning
A 402 for source code security means the organization has no eligible SAST credits or entitlement for that operation. It does not mean a malformed payload, and retrying without changing the credit pool will not help. Review Billing or ask an organization owner to add the appropriate SAST entitlement.
Limits
Findings help prioritize review; they are not proof of exploitability or a certification. Keep source snippets and customer data out of external notes and exports. Re-scan after a fix to confirm the intended project unit and commit are clean.