Scan a repository using an AppScan Presence
You can run static analysis directly on a GitHub Enterprise repository, a GitLab Self-Managed repository, or a GitLab SaaS repository using an AppScan Presence.
AppScan Presence includes optional support for running static analysis on repositories from a GitHub Enterprise server, a GitLab Self-Managed repository server, or a GitLab SaaS cloud-based repository using a GitHub or GitLab app. The repository server doesn’t have to be publicly accessible; however, the AppScan user must have network access to the repository server and permission to access the repositories.
Before configuring the scan, set up the AppScan Presence and install and configure a GitHub or GitLab app.
- Use the Create scan wizard to configure your scan. Select .
- At the Repository connection tab, click , , or .

- Select appropriate enabled AppScan Presence from the drop-down list.
- Click Authorize Presence to login to GitHub or
GitLab.Once authorized, available repositories are listed on the Repositories tab. Authorization is required only once.Note:If you see the message, "Cannot connect to Git repository," verify the Presence agent is running and try again.
- At the Select repository tab, specify the repository
and branch to scan either from a list of available repositories, or provide
the repository URL.
When choosing a repository from the list of available repositories, choose the parent first, then the branch.
- From the Schedule tab, specify that the scan should
run immediately, save the scan configuration to use later, or schedule
recurrent scanning:
- Scan now
The scan runs as soon as you click the Scan button. If the maximum number of concurrent scans are running at this time, the scan will be added to a queue, and will start when it reaches the head of the queue.
- Save for later
The configuration for your scan is ready to run and added to the Scans page with the status "Configuration saved." Saved configurations cannot be edited.
- Schedule
- Indicate start date and time for the scan.
- If you want the scan to repeat on a schedule, specify frequency (daily, weekly, monthly) and further details.
- Indicate when rescans should stop.

- Scan now
- Indicate additional scan preferences on the Scan
options tab:
- Opt to run your scan as a personal scan whose security issues will not be added to the issues for the application as a whole.
- You can also select the default option that sends you an email when the scan completes.
- Allow intervention by our scan enablement team.

- At the Summary tab, edit the default name that was
given to the scan, if desired, and review scan choices.

- Click Scan when ready to scan.