Security scanning
Deep Scan
Cross-file, data-flow-aware analysis for the vulnerability classes a single-file pattern pass can't see.
Repo Scan looks at files individually. Some real vulnerabilities only show up when you trace a value across function and file boundaries — user input that reaches a database call three files later, for example. Deep Scan builds a code property graph of the repository and queries it for exactly that kind of cross-file path.
When to use it
- Before a release, on a repository large or old enough that pattern matching alone likely misses things.
- After a Repo Scan finding you suspect is part of a longer, cross-file chain.
- On a schedule, for a periodic deeper pass independent of day-to-day PR scanning.
What it costs you
Building the graph takes real time and compute — Deep Scan is opt-in per run rather than firing on every push the way Repo Scan does. Expect it to take meaningfully longer than a Repo Scan on the same repository, scaling with codebase size.
Not a replacement for Repo Scan
Deep Scan is a deeper, slower complement, not a faster alternative — keep Repo Scan running on every push for fast feedback, and reach for Deep Scan when you specifically want cross-file coverage.