Last reviewed: 2026-09-16
Trigger scans
Choose manual, automated, API, GitHub Actions, or VCS webhook scan triggers for CodeCleared.
Purpose
Run scans at the point in delivery where their results are useful.
Who
Engineers and administrators configuring scan workflows.
Prerequisites
Connect the repository (GitHub or GitLab.com) and ensure the organization has the required credits and entitlement.
How it works
Use the UI for a manual scan. Enable PR/MR or push automation for repository events. Configure PR check types (vulnerabilities, secrets, licenses, dependency advisor, SAST), severity thresholds, and scheduled scan frequency under organization Scan defaults or per-repository Scan triggers: daily, weekly, monthly, or never (default weekly). On Team and above, use the API, GitHub Actions, or the CLI CI gate (BYOT lockfile/SBOM upload). API creation requires commitHash.
GitLab project webhooks for push and merge-request events are registered automatically on import. GitHub continues to use the GitHub App webhook path.
Severity thresholds (not Quality Gates):
prCheckSeverityThreshold— org default + optional repo override; defaulthigh; fails GitHub PR checks / GitLab External Status Checks for vulns / secrets / SAST when severity ≥ threshold. Set in Settings → Scan defaults → PR checks (?tab=pr-checks), repo Scan triggers, Onboarding, and Import (PR only).apiGateSeverityThreshold— org only; defaultcritical; applies to Public API wait / CLI--wait/ MCP wait (same PR checks tab).
Other Scan defaults tabs: Branches, Scheduled, Triggers (/settings/scan-defaults?tab=…).
Governance snapshot preference for branch état des lieux: cli > api | push | manual-ui > scheduled (pr-event excluded).
Business rules
Automated behavior must be enabled before provider events create scans. API scan requests use the exact commit hash, not only a branch. Never disables automatic scheduled scans even if scheduled scan-type toggles stay on; push, PR/MR, manual, and API triggers are unchanged.
Scenarios & edge cases
No automated scan: verify repository automation settings and provider access. API validation fails: provide commitHash and the connected repository identifier. No scheduled scans: set frequency to Never, or turn off all scheduled scan types.
Limits
API and Actions access are plan-gated; do not retry a 402 without correcting its cause. GitLab is gitlab.com only.
Common errors
- Assuming API access on Free or Starter.
- Supplying
commitShainstead ofcommitHash.