Skip to content

Access & security

Security scans

Check an app's dependencies for known vulnerabilities and its code for committed secrets.

A security scan reads your app's repository on GitHub and reports two things:

  • Vulnerable dependencies: packages with known vulnerabilities, from the OSV.dev database.
  • Leaked secrets: API keys, tokens, private keys and passwords committed to the code.

Scans need the app to be connected through the Elula GitHub App. They read the app's configured branch and, in a monorepo, only its root directory.

Run a scan

From the app's linked directory:

elula scan --run      # start a new scan
elula scan            # show the latest result
elula scan --json     # latest result as JSON

A scan runs in the background. Run elula scan again after about a minute to see the result. Only one scan per app can run at a time.

Results appear in the CLI and on the app's Security tab in the dashboard.

What gets checked for vulnerabilities

Elula looks for these dependency files at the app's root:

FileEcosystem
package.json, package-lock.json, yarn.locknpm
requirements.txt, Pipfile.lockPyPI
go.mod, go.sumGo
Gemfile.lockRubyGems
Cargo.lockcrates.io
composer.lockPackagist
pom.xmlMaven

Each finding shows the package and version, a short summary, a severity, and the version that fixes it when one is known.

Severity comes from the CVSS score where OSV provides one:

SeverityCVSS score
Critical9.0 and above
High7.0 to 8.9
Medium4.0 to 6.9
Lowbelow 4.0

What gets checked for secrets

Elula looks for common credential formats, including AWS keys, GitHub tokens, Slack tokens, Google API keys, Stripe keys, SendGrid and Twilio keys, private key blocks, database URLs with passwords, and values assigned to names like password, secret, api_key or token.

It checks:

  • Known config files anywhere in the repo, such as .env files, docker-compose.yml, Dockerfile, settings.py, config.*, .npmrc, appsettings.json and credentials.json.
  • Source files (.js, .ts, .py, .rb, .go, .java, .php) up to three folders deep, skipping node_modules and vendor.

It skips lock files, files over 200 KB and lines that start with # or //, and checks at most 50 files per scan. Matches are masked in the results; you see the file, line and type.

If a scan finds a real secret, rotate it with the provider. Removing it from the code isn't enough, because it stays in your Git history. Then store it as an environment variable. See Environment variables and secrets.

Limits

The scan only finds what matches its patterns and the files listed above. It doesn't replace a full code review or a dedicated scanning tool.