Skip to content
Published

Last reviewed: 2026-09-16

Get started with CodeCleared

Set up your organization, connect GitHub or GitLab, define policies, and run a first CodeCleared scan.

Purpose

Create a repeatable first security review for a connected GitHub or GitLab repository.

Who

New organization owners and administrators lead setup; members review results they are allowed to see.

Prerequisites

Have a GitHub or GitLab.com account that can authorize the connection and administer the target repository.

How it works

  1. Create your account and organization.
  2. Connect GitHub or GitLab, select repositories or projects, and import one.
  3. Complete policy onboarding.
  4. Run a first scan; SCA, licenses, secrets, and advisor typically use about four core credits.
  5. Review the project-unit tabs, then confirm or adjust PR / MR checks under repository Scan triggers (all five types are enabled by default on import).

Business rules

An organization owns its policies, entitlements, and billing. A first scan is tied to its selected commit.

Scenarios & edge cases

No project unit: the repository may have no recognized lockfile. PR checks missing (GitHub): confirm the GitHub App has Checks permission, scanOnPr is enabled, and the check type is toggled on (SAST also requires the SAST add-on and project unit). MR checks missing (GitLab): confirm GitLab Premium/Ultimate (External Status Checks), scanOnPr is enabled, and the check type is toggled on.

Limits

Credit use and available scan types depend on the organization plan. Do not treat an initial scan as a certification. GitLab is gitlab.com only.

Common errors

  • Importing a repository before choosing the right organization.
  • Expecting one monorepo tab to represent every lockfile path.
  • Retrying a 402 before changing credits or entitlement.

Links