Security scanning
Repo Scan
The default scan: a fast pattern pass plus an AI pass, run on every push and pull request.
Repo Scan is a two-stage pipeline. A rule/pattern stage finds the obvious cases quickly and cheaply. Anything the patterns can't resolve on their own goes to a semantic pass, where a wide-net model drafts a candidate finding and a stronger model verifies it before it's ever shown to you — the same draft-then-verify split Goosy uses everywhere it calls a model, so a single hallucinated guess from the fast tier doesn't become a finding in your queue.
What triggers a scan
- Every push to a connected repository's branches.
- Every pull request, scanning the diff against its base.
- A manual “Run scan” from the repository's dashboard page.
Findings
Each finding includes the affected file and lines, a severity, a plain-language explanation of the risk, and — when Goosy is confident in the fix — a suggested patch as a unified diff. You decide whether to apply it locally or open it as a pull request; Goosy never commits or pushes without that decision.
Autofix
Where a fix is mechanical enough to generate safely, Goosy proposes one alongside the finding. Fixes are scoped to the file the finding is in — a suggested patch never edits a file outside the one that triggered it.