Security findings
See every security finding from GitHub, uploaded reports and connected platforms, grouped into one finding per problem.
Availability
The Security page collects security findings from your connected GitHub organizations, uploaded reports.
What the page shows
The page has two views: the default Findings view and the Scan results view. When your plan includes AI security triage and it is turned on, a third tab, Triage, shows the triage (link to it with ).
The Findings view groups every scan result from every source into one row per unique problem. A summary shows your count: "312 findings, deduplicated from 1,240 scan results across 4 sources" means 1,240 open scan results are displayed as 312 findings. The Sources column shows " scan results" for each finding.
Clicking on a finding shows its full description, "Deduplicated from N scan results across M sources" when it groups more than one, and then every scan result, each with its scanner, state, severity, location, package, the branch and commit it was found on, a link to its source, and the reason it was grouped into this finding.
The Scan results view shows every scan result as its source reported it, in any state (open, fixed, dismissed), loaded 1,000 at a time. Search and filters work on both views.
On the Team plan, the Findings view is not available. You see only uploads and the Scan results view, and the summary shows scan results.
Deduplication does not delete anything
Every scan result from every source is kept until your plan's retention removes it, whether or not it is part of a finding. The Scan results view, the export and the API route always show the full set, each scan result with its finding id and the reason it was grouped. Deduplication changes how findings are shown, not what is stored.
Where findings come from
| Source | How Prodgator reads it |
|---|---|
| GitHub Dependabot alerts | Webhook and sync (every 6 hours) |
| GitHub code scanning alerts | Webhook and sync |
| GitHub secret scanning alerts | Webhook and sync |
| Uploaded SARIF, CycloneDX and SPDX reports | From the Security page or the API |
| Prodgator report action | Scanner files attached to and attestations |
Any scanner that writes SARIF 2.1.0, CycloneDX JSON or SPDX JSON works. Set up a scanner shows how to send results from ASH, Grype, Trivy, Semgrep, Checkov and Syft.
GitHub sends alerts only for repositories where the alert feature (Dependabot, code scanning, secret scanning) is enabled. Prodgator also pulls all alerts from each connected installation every 6 hours, so alerts from before you connected and changes made on GitHub show up.
Findings from a pull request scan can also reach the tracked branch when the pull request merges. See Findings from pull requests.
Plan features and limits
Team: uploads and the Scan results view.
Business and Enterprise: GitHub alerts, findings and deduplication, the security findings export (, every scan result).
| Free | Team | Business | Enterprise | |
|---|---|---|---|---|
| Security report uploads per pipeline run | None | 3 | 10 | Unlimited |
| Security report file size | None | 10 MB | 50 MB | 100 MB |
| Findings kept per report | None | 5,000 | 20,000 | 50,000 |
Uploads made outside a pipeline run also have an hourly safety limit per organization (Team 60, Business 300, Enterprise 1,000) against runaway scripts.
See Plans and features for other limits.
Exports and compliance evidence
Compliance checks and the export use every scan result behind a finding. See Exports.
Notifications
Prodgator creates one notification per uploaded report that opens critical or high findings. These go to Slack and outbound webhooks under the Security and compliance category. See Notifications.
GitHub alerts follow the existing notification rules.
From the API
API keys with can:
- Read scan results at (paged with )
- List findings (Business and Enterprise only) at , each with and
API keys with can upload reports. See Upload a report.
For details, see the Public REST API.