ProdgatorDocs
Security

Security findings

See every security finding from GitHub, uploaded reports and connected platforms, grouped into one finding per problem.

Availability

Team plan and above. The Team plan shows uploaded reports and scan results; Business and higher adds GitHub alerts, findings and deduplication. Every member with access to Security can view findings; uploading, dismissing, splitting and rejoining need the or role.

The Security page collects security findings from your connected GitHub organizations, uploaded reports.

What the page shows

The page has two views: the default Findings view and the Scan results view. When your plan includes AI security triage and it is turned on, a third tab, Triage, shows the triage (link to it with ).

The Findings view groups every scan result from every source into one row per unique problem. A summary shows your count: "312 findings, deduplicated from 1,240 scan results across 4 sources" means 1,240 open scan results are displayed as 312 findings. The Sources column shows " scan results" for each finding.

Clicking on a finding shows its full description, "Deduplicated from N scan results across M sources" when it groups more than one, and then every scan result, each with its scanner, state, severity, location, package, the branch and commit it was found on, a link to its source, and the reason it was grouped into this finding.

The Scan results view shows every scan result as its source reported it, in any state (open, fixed, dismissed), loaded 1,000 at a time. Search and filters work on both views.

On the Team plan, the Findings view is not available. You see only uploads and the Scan results view, and the summary shows scan results.

Deduplication does not delete anything

Every scan result from every source is kept until your plan's retention removes it, whether or not it is part of a finding. The Scan results view, the export and the API route always show the full set, each scan result with its finding id and the reason it was grouped. Deduplication changes how findings are shown, not what is stored.

Where findings come from

SourceHow Prodgator reads it
GitHub Dependabot alertsWebhook and sync (every 6 hours)
GitHub code scanning alertsWebhook and sync
GitHub secret scanning alertsWebhook and sync
Uploaded SARIF, CycloneDX and SPDX reportsFrom the Security page or the API
Prodgator report actionScanner files attached to and attestations

Any scanner that writes SARIF 2.1.0, CycloneDX JSON or SPDX JSON works. Set up a scanner shows how to send results from ASH, Grype, Trivy, Semgrep, Checkov and Syft.

GitHub sends alerts only for repositories where the alert feature (Dependabot, code scanning, secret scanning) is enabled. Prodgator also pulls all alerts from each connected installation every 6 hours, so alerts from before you connected and changes made on GitHub show up.

Findings from a pull request scan can also reach the tracked branch when the pull request merges. See Findings from pull requests.

Plan features and limits

Team: uploads and the Scan results view.

Business and Enterprise: GitHub alerts, findings and deduplication, the security findings export (, every scan result).

FreeTeamBusinessEnterprise
Security report uploads per pipeline runNone310Unlimited
Security report file sizeNone10 MB50 MB100 MB
Findings kept per reportNone5,00020,00050,000

Uploads made outside a pipeline run also have an hourly safety limit per organization (Team 60, Business 300, Enterprise 1,000) against runaway scripts.

See Plans and features for other limits.

Exports and compliance evidence

Compliance checks and the export use every scan result behind a finding. See Exports.

Notifications

Prodgator creates one notification per uploaded report that opens critical or high findings. These go to Slack and outbound webhooks under the Security and compliance category. See Notifications.

GitHub alerts follow the existing notification rules.

From the API

API keys with can:

  • Read scan results at (paged with )
  • List findings (Business and Enterprise only) at , each with and

API keys with can upload reports. See Upload a report.

For details, see the Public REST API.

On this page