Access & security
Security scans
Check an app's dependencies for known vulnerabilities and its code for committed secrets.
A security scan reads your app's repository on GitHub and reports two things:
- Vulnerable dependencies: packages with known vulnerabilities, from the OSV.dev database.
- Leaked secrets: API keys, tokens, private keys and passwords committed to the code.
Scans need the app to be connected through the Elula GitHub App. They read the app's configured branch and, in a monorepo, only its root directory.
Run a scan
From the app's linked directory:
elula scan --run # start a new scan elula scan # show the latest result elula scan --json # latest result as JSON
A scan runs in the background. Run elula scan again after about a minute to see the result. Only one scan per app can run at a time.
Results appear in the CLI and on the app's Security tab in the dashboard.
What gets checked for vulnerabilities
Elula looks for these dependency files at the app's root:
| File | Ecosystem |
|---|---|
package.json, package-lock.json, yarn.lock | npm |
requirements.txt, Pipfile.lock | PyPI |
go.mod, go.sum | Go |
Gemfile.lock | RubyGems |
Cargo.lock | crates.io |
composer.lock | Packagist |
pom.xml | Maven |
Each finding shows the package and version, a short summary, a severity, and the version that fixes it when one is known.
Severity comes from the CVSS score where OSV provides one:
| Severity | CVSS score |
|---|---|
| Critical | 9.0 and above |
| High | 7.0 to 8.9 |
| Medium | 4.0 to 6.9 |
| Low | below 4.0 |
What gets checked for secrets
Elula looks for common credential formats, including AWS keys, GitHub tokens, Slack tokens, Google API keys, Stripe keys, SendGrid and Twilio keys, private key blocks, database URLs with passwords, and values assigned to names like password, secret, api_key or token.
It checks:
- Known config files anywhere in the repo, such as
.envfiles,docker-compose.yml,Dockerfile,settings.py,config.*,.npmrc,appsettings.jsonandcredentials.json. - Source files (
.js,.ts,.py,.rb,.go,.java,.php) up to three folders deep, skippingnode_modulesandvendor.
It skips lock files, files over 200 KB and lines that start with # or //, and checks at most 50 files per scan. Matches are masked in the results; you see the file, line and type.
Limits
The scan only finds what matches its patterns and the files listed above. It doesn't replace a full code review or a dedicated scanning tool.