ع

Security scans and fixes

Last reviewed:

“Security” brings together code-scan and dependency findings. Stored results describe the last scan and can become stale after project changes. Check their date and scan again after fixes.

Reading project findings

  1. 1

    Open “Security”

    Choose the project’s “Security” tab, using “+” if needed. Check the last scan time and status. Opening the tab loads stored results and does not start a paid deep scan.

  2. 2

    Review the findings

    Findings show severity, title, description, and a suggested fix. A file, line, and category may also appear. Deployment reports list critical findings before warnings and informational items.

  3. 3

    Distinguish findings from missing checks

    “Not scanned yet” means no result is stored. A clean result means that scan reported no issue; it is not a comprehensive guarantee for every app behavior.

Deep scans and cost confirmation

  1. 1

    Open the confirmation card

    In “Security”, click “Run AI scan”. A card shows audit steps and estimated credits. Deep scans require a Pro account plan or above; selecting a project deployment tier does not unlock them.

  2. 2

    Review the estimate

    Wait for and review the estimate. It depends on project size and is not a fixed final price. If it keeps calculating or unexpectedly shows zero, cancel and reopen the card; do not treat it as a promise of a free scan.

  3. 3

    Confirm or cancel

    Click “Agree, start scan” if you accept using credits, or cancel. If your plan is ineligible, review billing. Dependency scans remain free.

  4. 4

    Follow the task in chat

    Codey starts a chat task to read and analyze the code, rather than automatically fix it. Follow the task until completion; there is no fixed duration, and larger projects can take longer.

  5. 5

    Review the report and choose a fix

    On completion, “Security” updates if the report can be imported. If results remain old or no report appears, read the chat outcome and scan date before starting another paid scan. If startup fails, resolve the cause and retry.

The audit reviews sign-in and access logic, inputs, secrets, requests, files, and protective settings. It reports findings and suggested fixes; applying them needs a separate repair task.

Why did the deployment scan block my attempt?

Before deployment, the platform attempts a free basic code scan. Findings classified as critical block deployment, including certain exposed secrets or dangerous commands. Medium and low findings do not block it on their own. Deployment may continue if the scanner itself fails, so success does not replace reviewing the results.

  1. 1

    Read the blocking finding

    In “Deploy”, review the report below the blocking message. Identify the critical finding and suggested fix. A working preview does not resolve it.

  2. 2

    Send it to Codey

    Open “Security” and use “Fix with Codey” when findings appear. For a failed deployment, you can also use “Solve with Codey” in the deployment panel. These buttons start a repair task that may use credits.

  3. 3

    Wait for and test the fix

    Follow the task to completion and test preview. For an exposed secret, use Secrets to store the value and ask Codey to remove the literal value from code.

  4. 4

    Redeploy to check again

    Return to “Deploy” and try again. The files are scanned again; there is no button to bypass a critical finding. If no repair button appears, describe the finding to Codey without including secrets.

Dependency scanning

  1. 1

    Refresh the dependency scan

    In “Security”, find the dependency scan section and click “Refresh”. Scanning is free and does not start a repair task. Wait for the scanning indicator to finish.

  2. 2

    Review affected packages

    The table lists package names, severity, and status, and may mark a fix as available. This scan is advisory and does not block deployment on its own.

  3. 3

    Choose what to fix

    Select packages using the checkboxes and fix the selection with Codey. With none selected, the button fixes all listed packages. Repairs are separate tasks and may use credits.

  4. 4

    Check after updating

    Wait for the task, test the app, then refresh the dependency scan again. If loading the scan fails, wait briefly and retry.

Dependency scanning needs a package lock file. A missing lock file or a scan failure can produce an empty list without a completed scan. The panel does not currently show every reason for skipping. If unsure, ask Codey to check that the scan completed rather than treating an empty table as proof of safety.