Security analysis
Scan types
Choose static, deep, ML-assisted or combined security analysis.
| Type | Use it for |
|---|---|
| Static | Fast rule-based source analysis and focused feedback |
| Deep | Broader data-flow and query-based analysis where supported |
| ML | Model-assisted prioritization and vulnerability detection |
| SCA with SBOM | Dependency inventory, component vulnerabilities and SBOM evidence |
| Package | Security analysis for supported operating-system or source-host package formats |
| DAST | Runtime host-scan and incident-response data where enabled |
| All | The eligible combination for the project and plan |
Coverage varies by language and repository. A deeper scan usually needs more time and build context; an ML result still requires evidence-based triage.
For CI, use the scan mode approved for the branch and fail policy. For release gates, record the exact engines, versions, exclusions and source revision.

