Using ScanSuite

Scheduling periodic and incremental scans

Recurring scans, monitored branches and incremental re-analysis of only what changed.

Periodic scans keep an up-to-date view of vulnerabilities, which matters because both the codebase and the scanner rules change over time.

Scheduled, monitored and incremental scans are only available for Git repositories. The form disables them while a ZIP archive is the source — an archive has no remote commit identity to compare against, so it can only be scanned once.

The scanning modes

ModeBehaviour
Full scanA single run of the whole repository or archive, now.
Daily / Weekly / MonthlyA scan now, then every day, every week on today's weekday, or every month on today's date, at the time set in Run at. The form says it in a sentence, such as Every Friday at 03:30.
Monitor ChangesAn initial full scan of the target branch, then hourly checks for new commits. When the branch moves, only the changed files are fetched and analysed.
Incremental ScanA one-off scan of what changed since the last successful scan of the same branch. The first run scans everything; nothing is started when there are no new commits.
Custom ScopeScans only the files and folders matching the patterns you supply.
Verify FixesReassesses only the findings you list. See Rescans and fix verification.

Setting up a scheduled scan

  1. 01
    Open the Static Analysis tab

    Enter the repository on the Git Repository tab.

  2. 02
    Choose the scan frequency

    Daily, Weekly or Monthly, and the time in Run at.

  3. 03
    Click Start Analysis

    The first scan runs now; the next ones run at the time you chose.

Weekly schedule on the Static Analysis form
A weekly scan at 03:30, with the sentence saying when it runs

Repository monitoring

The Monitor Changes mode performs an initial full scan of the target branch and then checks hourly for new commits. If the branch has moved, only the modified files are downloaded and an incremental scan runs against them.

Repository monitoring configuration
Configuring repository monitoring

How the comparison point is chosen

Standard Git scans are pinned to an exact commit SHA, and become eligible history checkpoints once they finish successfully. A newly created monitor adopts the newest compatible checkpoint before deciding whether a diff scan is needed — so setting up monitoring on a repository you have already scanned does not re-analyse the whole tree.

An Incremental Scan is a one-time user action rather than a schedule. It finds the newest compatible successful static scan for the same repository and configuration, and uses that run's source SHA as the comparison checkpoint.

This is what makes per-commit AI analysis affordable: the cost of a re-scan tracks the size of the change rather than the size of the codebase.

Managing scheduled scans

Every schedule and monitor is listed on the Schedules page, where you run, pause, rename or delete it — see Schedule the scan. To change what a schedule scans, choose it from the Saved Scans drop-down at the top of the Static Analysis section.

Last reviewed 2026-09-25