Skip to content
Published

Last reviewed: 2026-07-25

Scan monorepos

Scan monorepos with CodeCleared project units, lockfile paths, selective scan types, and partial results.

Purpose

Use project units to make dependency results meaningful in repositories with multiple lockfile paths.

Who

Engineers and policy owners working in monorepos.

Prerequisites

Connect a repository with one or more supported lockfiles.

How it works

Review each discovered project unit. For an API scan, use projectUnitId and scanTypes to target the intended scope when needed.

Business rules

Each lockfile path can produce a separate SCA, SBOM, and license project unit. Partial scans only report their selected unit and types.

Scenarios & edge cases

Empty units: verify the path and lockfile. No SCA unit: the repository may contain no supported lockfile. Different result counts: compare the same unit and scan types.

Limits

Secrets and SAST do not use lockfile-scoped project units in the same way.

Common errors

  • Treating a partial scan as a repository-wide scan.
  • Ignoring empty project units without checking their path.

Links