ZeroFlaw

Documentation

Git import

What is Git import?

With Git import you connect a GitHub repository directly to ZeroFlaw. The code is downloaded and scanned automatically – no need to create a ZIP file.

How to start a Git import

  1. In the dashboard click "New scan".
  2. Select the "Git import" tab.
  3. If this is your first time, click "Connect with GitHub". You'll be redirected to GitHub to grant ZeroFlaw access to your repositories.
  4. Select the repository and branch you want to scan.
  5. Click "Start scan".
Tip You can revoke access at any time in your GitHub settings under "Authorized OAuth Apps".

Supported Git providers

Currently GitHub is supported. Additional providers (GitLab, Bitbucket) are planned.

Private repositories

Yes, ZeroFlaw can scan private repositories. When connecting with GitHub you'll be asked which repositories to grant access to. Access is read-only – ZeroFlaw cannot change your code.

What happens with my code?

The code is downloaded only for the scan and immediately deleted afterwards. It is not permanently stored. Learn more in our Privacy policy.

FAQ

I can't see my repository in the list

Make sure you've granted ZeroFlaw access to the repository. For organization repositories an administrator must approve the access.

Can I scan a specific branch?

Yes, you can select the branch from the dropdown. By default the main branch (main/master) is selected.

Are changes scanned automatically?

Not automatically, but you can set up scheduled scans or integrate the API into your CI/CD pipeline to scan on every push.