Getting started
Quickstart
Connect a repository, get a scan, and see how findings turn into a pull request.
- 1Sign inSign in with GitHub, GitLab, or Bitbucket. Goosy authenticates through your provider's OAuth flow — it never asks for a password directly, and you can revoke access from your provider's settings at any time.
- 2Connect a repositoryFrom the dashboard, pick a repository from your account. Goosy registers it, records its default branch, and is ready to scan.
- 3Run a scanTrigger a Repo Scan from the repository's page, or just open a pull request — Goosy scans on push automatically once a repository is connected. A scan runs a fast pattern pass first, then an AI pass over what the patterns can't decide on its own.
- 4Review findingsEach finding shows the vulnerable code, an explanation, and — where Goosy is confident in the fix — a suggested patch. You choose whether to apply it, either directly or as a pull request.
- 5Optional: set up Agentic TestingIf you want functional API test coverage in addition to security scanning, add a target environment under the repository's
Testingsection and generate a smoke suite — see Environments, specs & suites.
What happens on every push
Once a repository is connected, Repo Scan runs on new pushes and pull requests without further setup. Deep Scan is opt-in per scan (or scheduled) since it does more work — see Deep Scan for when to reach for it.
Private repositories
Goosy only sees what your OAuth grant allows. For an organization-owned repository, an org admin may need to approve the connection depending on your provider's app-installation settings.