GOOSY|Docs
← Home

Security scanning

Repo Scan

The default scan: a fast pattern pass plus an AI pass, run on every push and pull request.

Repo Scan is a two-stage pipeline. A rule/pattern stage finds the obvious cases quickly and cheaply. Anything the patterns can't resolve on their own goes to a semantic pass, where a wide-net model drafts a candidate finding and a stronger model verifies it before it's ever shown to you — the same draft-then-verify split Goosy uses everywhere it calls a model, so a single hallucinated guess from the fast tier doesn't become a finding in your queue.

What triggers a scan

  • Every push to a connected repository's branches.
  • Every pull request, scanning the diff against its base.
  • A manual “Run scan” from the repository's dashboard page.

Findings

Each finding includes the affected file and lines, a severity, a plain-language explanation of the risk, and — when Goosy is confident in the fix — a suggested patch as a unified diff. You decide whether to apply it locally or open it as a pull request; Goosy never commits or pushes without that decision.

SeverityMeaning
CriticalDirectly exploitable — e.g. injection, auth bypass, secret exposure.
HighReal risk, usually needs a specific condition to trigger.
MediumWeakness worth fixing, lower direct exploitability.
LowHardening — best practice, not a live vulnerability.

Autofix

Where a fix is mechanical enough to generate safely, Goosy proposes one alongside the finding. Fixes are scoped to the file the finding is in — a suggested patch never edits a file outside the one that triggered it.

Incremental by default
On a repository with prior scan history, Repo Scan diffs against the last scanned commit instead of re-scanning everything — a small pull request stays fast even on a large repository. A full rescan is available whenever you want one.
← QuickstartDeep Scan →