[{"data":1,"prerenderedAt":2302},["ShallowReactive",2],{"navigation_docs":3,"-guides-analyze-a-project-without-github":114,"-guides-analyze-a-project-without-github-surround":2297},[4,23,85,99],{"title":5,"path":6,"stem":7,"children":8},"Getting Started","\u002Fgetting-started","1.getting-started",[9,13,18],{"title":10,"path":6,"stem":11,"icon":12},"Getting started","1.getting-started\u002Findex","i-lucide-rocket",{"title":14,"path":15,"stem":16,"icon":17},"Try the demo","\u002Fgetting-started\u002Ftry-the-demo","1.getting-started\u002F1.try-the-demo","i-lucide-monitor-play",{"title":19,"path":20,"stem":21,"icon":22},"Quickstart","\u002Fgetting-started\u002Fquickstart","1.getting-started\u002F2.quickstart","i-lucide-play",{"title":24,"path":25,"stem":26,"children":27},"Guides","\u002Fguides","2.guides",[28,31,37,42,47,53,58,63,68,74,80],{"title":24,"path":25,"stem":29,"icon":30},"2.guides\u002Findex","i-lucide-map",{"title":32,"path":33,"stem":34,"icon":35,"group":36},"Connect a GitHub repository","\u002Fguides\u002Fconnect-a-github-repository","2.guides\u002F01.connect-a-github-repository","i-lucide-git-branch","Connect a project",{"title":38,"path":39,"stem":40,"icon":41,"group":36},"Analyze a project without GitHub","\u002Fguides\u002Fanalyze-a-project-without-github","2.guides\u002F02.analyze-a-project-without-github","i-lucide-upload",{"title":43,"path":44,"stem":45,"icon":46,"group":36},"Exclude dependency scopes","\u002Fguides\u002Fexclude-dependency-scopes","2.guides\u002F04.exclude-dependency-scopes","i-lucide-filter",{"title":48,"path":49,"stem":50,"icon":51,"group":52},"Scan from GitHub Actions","\u002Fguides\u002Fscan-from-github-actions","2.guides\u002F05.scan-from-github-actions","i-lucide-workflow","Automate",{"title":54,"path":55,"stem":56,"icon":57,"group":52},"Scan from another CI","\u002Fguides\u002Fscan-from-another-ci","2.guides\u002F06.scan-from-another-ci","i-lucide-square-terminal",{"title":59,"path":60,"stem":61,"icon":62,"group":52},"Manage API keys","\u002Fguides\u002Fmanage-api-keys","2.guides\u002F07.manage-api-keys","i-lucide-key-round",{"title":64,"path":65,"stem":66,"icon":67,"group":52},"Create many projects at once","\u002Fguides\u002Fcreate-many-projects-at-once","2.guides\u002F08.create-many-projects-at-once","i-lucide-layers",{"title":69,"path":70,"stem":71,"icon":72,"group":73},"Export reports and SBOMs","\u002Fguides\u002Fexport-reports-and-sboms","2.guides\u002F11.export-reports-and-sboms","i-lucide-download","Act on the results",{"title":75,"path":76,"stem":77,"icon":78,"group":79},"Organizations and plans","\u002Fguides\u002Forganizations-and-plans","2.guides\u002F13.organizations-and-plans","i-lucide-building-2","Organization and team",{"title":81,"path":82,"stem":83,"icon":84,"group":79},"Invite your team","\u002Fguides\u002Finvite-your-team","2.guides\u002F14.invite-your-team","i-lucide-users",{"title":86,"path":87,"stem":88,"children":89},"Core Concepts","\u002Fcore-concepts","3.core-concepts",[90,94],{"title":91,"path":87,"stem":92,"icon":93},"Core concepts","3.core-concepts\u002Findex","i-lucide-lightbulb",{"title":95,"path":96,"stem":97,"icon":98},"The health score","\u002Fcore-concepts\u002Fhealth-score","3.core-concepts\u002F1.health-score","i-lucide-gauge",{"title":100,"path":101,"stem":102,"children":103},"Reference","\u002Freference","5.reference",[104,107],{"title":100,"path":101,"stem":105,"icon":106},"5.reference\u002Findex","i-lucide-book-marked",{"title":108,"path":109,"stem":110,"children":111,"icon":113},"Supported ecosystems","\u002Freference\u002Fecosystems","5.reference\u002F1.ecosystems\u002Findex",[112],{"title":108,"path":109,"stem":110,"icon":113},"i-lucide-package",{"id":115,"title":38,"body":116,"description":2290,"extension":2291,"links":2292,"meta":2293,"navigation":2294,"path":39,"seo":2295,"stem":40,"__hash__":2296},"docs\u002F2.guides\u002F02.analyze-a-project-without-github.md",{"type":117,"value":118,"toc":2271},"minimark",[119,128,131,136,139,152,168,174,178,181,184,202,213,229,235,239,250,365,368,371,377,384,390,394,397,402,405,434,440,444,481,485,498,971,974,992,1003,1006,1010,1013,1125,1147,1155,1168,1172,1282,1288,1292,1298,1333,1388,1690,1712,1951,1954,1958,1961,1964,1967,1976,1980,1993,2000,2011,2015,2018,2222,2225,2229,2234,2248,2251,2255,2267],[120,121,122,123,127],"p",{},"When Deptools cannot read your repository, your pipeline sends the build files\ninstead. You create a ",[124,125,126],"strong",{},"CI upload project",", add one job to your pipeline, and\nevery run produces an analysis identical to the one a GitHub project gets: same\ngraph, same score, same dashboard.",[120,129,130],{},"Deptools only sees what a push delivers, and that push contains only your build\nfiles.",[132,133,135],"h2",{"id":134},"when-you-need-this","When you need this",[120,137,138],{},"Take this path when your code lives somewhere Deptools cannot reach:",[140,141,142,146,149],"ul",{},[143,144,145],"li",{},"A self hosted GitLab, an internal Bitbucket, or any server closed to the\noutside.",[143,147,148],{},"A platform Deptools does not integrate with yet.",[143,150,151],{},"A repository your team will not grant access to, whatever the tool.",[153,154,155,156,159,160,163,164,167],"note",{},"If your code ",[124,157,158],{},"is"," on GitHub and you only want to start a scan from your\npipeline, you do not need this page. Connect the repository normally and call\nthe scan endpoint from your CI, as described in\n",[161,162,54],"a",{"href":55},". Triggering a scan on a\nGitHub project is allowed on every plan, while pushing build files requires\n",[124,165,166],{},"Pro",", including for Open Source Max.",[120,169,170,171,173],{},"This path is Pro only. A CI upload project has no public repository behind it,\nso it is always private and always occupies one private slot.\n",[161,172,75],{"href":76}," explains what\noccupies a slot and what buying one bills you.",[132,175,177],{"id":176},"create-an-organization-without-github","Create an organization without GitHub",[120,179,180],{},"A personal organization and a GitHub organization both accept upload projects,\nas soon as they are on Pro. You can stop reading this section and go create the\nproject.",[120,182,183],{},"Create a separate organization when you want one of these:",[140,185,186,192,199],{},[143,187,188,191],{},[124,189,190],{},"Team members",", since a personal organization can never have any.",[143,193,194,195,198],{},"A ",[124,196,197],{},"separate bill and separate plan"," for a client or a department.",[143,200,201],{},"A clean split between what you analyze for yourself and what your team owns.",[120,203,204,205,208,209,212],{},"Open the organization switcher in the navbar, ",[124,206,207],{},"Add Organization",", then the\n",[124,210,211],{},"Create manually"," tab, and give it a name. No GitHub account is involved, and\nnone can be attached later: the organization has no GitHub tab and holds upload\nprojects only.",[214,215,216,217,220,221,224,225,228],"warning",{},"It is created on the ",[124,218,219],{},"Free"," plan, and upload projects need Pro, so it can hold\nnothing until you upgrade. The projects screen says ",[124,222,223],{},"This organization uses CI\nupload projects, which require the Pro plan."," Upgrade from there, or from the\n",[124,226,227],{},"Plan"," tab of the organization settings.",[120,230,231,232,234],{},"The three kinds of organization, and how the plan attaches to one, are covered\nin ",[161,233,75],{"href":76},".",[132,236,238],{"id":237},"create-an-upload-project","Create an upload project",[120,240,241,242,245,246,249],{},"Open ",[124,243,244],{},"New project"," and choose ",[124,247,248],{},"Upload from CI",". In an organization created\nmanually and already on Pro, the form opens directly, since it is the only\npossible source there.",[251,252,253,269],"table",{},[254,255,256],"thead",{},[257,258,259,263,266],"tr",{},[260,261,262],"th",{},"Field",[260,264,265],{},"Required",[260,267,268],{},"What it does",[270,271,272,286,319,337,349],"tbody",{},[257,273,274,280,283],{},[275,276,277],"td",{},[124,278,279],{},"Project name",[275,281,282],{},"yes",[275,284,285],{},"Unique inside the organization.",[257,287,288,293,295],{},[275,289,290],{},[124,291,292],{},"Build system",[275,294,282],{},[275,296,297,301,302,301,305,301,308,311,312,315,316],{},[298,299,300],"code",{},"Maven",", ",[298,303,304],{},"Gradle",[298,306,307],{},"sbt",[298,309,310],{},"npm"," or ",[298,313,314],{},"Composer",". ",[124,317,318],{},"Fixed at creation.",[257,320,321,326,329],{},[275,322,323],{},[124,324,325],{},"Dependency scopes",[275,327,328],{},"no",[275,330,331,332,334,335],{},"The scopes counted in the graph and in the score. Every scope is selected by default except the test one. ",[124,333,318],{}," See ",[161,336,43],{"href":44},[257,338,339,344,346],{},[275,340,341],{},[124,342,343],{},"Branch",[275,345,328],{},[275,347,348],{},"A label displayed in the interface. Deptools reads no branch here, your pipeline decides what it sends. Editable later",[257,350,351,356,358],{},[275,352,353],{},[124,354,355],{},"Subfolder \u002F module",[275,357,328],{},[275,359,360,361,364],{},"The module to analyze, for example ",[298,362,363],{},"services\u002Fapi",". Empty analyzes the repository root. Editable later",[120,366,367],{},"Two of those five are decided once. The build system and the dependency scopes\ncannot be changed: to correct either one, delete the project and create it\nagain. The freed slot stays paid and reusable, so that costs nothing.",[120,369,370],{},"The subfolder is the opposite. Deptools has no files to look at yet, so nothing\ncan be validated at creation. Enter your best guess: the first push checks it\nagainst your archive, and if it matches no module, the error lists the modules it\ndid find. Change it in the project settings, and the next push uses\nthe new value.",[372,373],"u-color-mode-image",{"alt":374,"dark":375,"light":376},"New CI upload project form, with the build system, dependency scopes, branch and subfolder fields","\u002Fimages\u002Fdocs\u002Fguides\u002Fanalyze-a-project-without-github-1-create-form-dark.webp","\u002Fimages\u002Fdocs\u002Fguides\u002Fanalyze-a-project-without-github-1-create-form-light.webp",[120,378,379,380,383],{},"The project appears immediately, with ",[124,381,382],{},"no analysis",". That is expected: there\nare no files yet. The first analysis comes from the first push.",[385,386,387,388,234],"tip",{},"Creating more than a handful of projects by hand can mean an hour of clicking.\nOne API request creates them all and returns the name to UUID table your\npipelines need:\n",[161,389,64],{"href":65},[132,391,393],{"id":392},"push-your-build-files-from-your-pipeline","Push your build files from your pipeline",[120,395,396],{},"Three things go into your pipeline: a key, two variables, and one job.",[398,399,401],"h3",{"id":400},"get-an-api-key","Get an API key",[120,403,404],{},"Two scopes are possible:",[140,406,407,421],{},[143,408,194,409,412,413,416,417,420],{},[124,410,411],{},"project key"," (",[298,414,415],{},"dt_proj_...","), valid on this project only. To create it,\nopen the project, then the ",[124,418,419],{},"Integrations"," tab.",[143,422,423,424,412,427,430,431,420],{},"An ",[124,425,426],{},"organization key",[298,428,429],{},"dt_org_...","), valid on every project of the\norganization. Pick this one when several repositories push from the same CI,\nsince one shared variable then serves them all. To create it, open the\norganization settings, then the ",[124,432,433],{},"API keys",[120,435,436,437,439],{},"The key is shown once, at creation. You must be an owner or an admin. See\n",[161,438,59],{"href":60}," for expiration and rotation.",[398,441,443],{"id":442},"declare-two-variables","Declare two variables",[251,445,446,456],{},[254,447,448],{},[257,449,450,453],{},[260,451,452],{},"Variable",[260,454,455],{},"Value",[270,457,458,468],{},[257,459,460,465],{},[275,461,462],{},[298,463,464],{},"DEPTOOLS_API_KEY",[275,466,467],{},"The key you just created. Store it as a masked or secret variable, never in the YAML",[257,469,470,475],{},[275,471,472],{},[298,473,474],{},"DEPTOOLS_PROJECT_UUID",[275,476,477,478,480],{},"The project UUID, shown in the project's ",[124,479,419],{}," tab with a copy button",[398,482,484],{"id":483},"add-the-scan-job","Add the scan job",[120,486,487,488,301,491,494,495,234],{},"Deptools serves a POSIX shell script that collects the build files, archives\nthem and pushes them. It needs ",[298,489,490],{},"sh",[298,492,493],{},"tar"," and ",[298,496,497],{},"curl",[499,500,501,599,707,858],"code-group",{},[502,503,509],"pre",{"className":504,"code":505,"filename":506,"language":507,"meta":508,"style":508},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","# One-off scan from your machine, the quickest way to test your setup\n# Run from the repository root\ncurl -fsSL https:\u002F\u002Fapi.deptools.io\u002Fdeptools-scan.sh -o deptools-scan.sh\n\nDEPTOOLS_API_KEY=\"dt_proj_...\" \\\nDEPTOOLS_PROJECT_UUID=\"b9c105b0-...\" \\\nsh deptools-scan.sh --wait\n","Local run","bash","",[298,510,511,520,526,545,552,572,587],{"__ignoreMap":508},[512,513,516],"span",{"class":514,"line":515},"line",1,[512,517,519],{"class":518},"sHwdD","# One-off scan from your machine, the quickest way to test your setup\n",[512,521,523],{"class":514,"line":522},2,[512,524,525],{"class":518},"# Run from the repository root\n",[512,527,529,532,536,539,542],{"class":514,"line":528},3,[512,530,497],{"class":531},"sBMFI",[512,533,535],{"class":534},"sfazB"," -fsSL",[512,537,538],{"class":534}," https:\u002F\u002Fapi.deptools.io\u002Fdeptools-scan.sh",[512,540,541],{"class":534}," -o",[512,543,544],{"class":534}," deptools-scan.sh\n",[512,546,548],{"class":514,"line":547},4,[512,549,551],{"emptyLinePlaceholder":550},true,"\n",[512,553,555,558,562,565,567,569],{"class":514,"line":554},5,[512,556,464],{"class":557},"sTEyZ",[512,559,561],{"class":560},"sMK4o","=",[512,563,564],{"class":560},"\"",[512,566,415],{"class":534},[512,568,564],{"class":560},[512,570,571],{"class":531}," \\\n",[512,573,575,578,580,583,585],{"class":514,"line":574},6,[512,576,577],{"class":557},"DEPTOOLS_PROJECT_UUID=",[512,579,564],{"class":560},[512,581,582],{"class":534},"b9c105b0-...",[512,584,564],{"class":560},[512,586,571],{"class":557},[512,588,590,593,596],{"class":514,"line":589},7,[512,591,592],{"class":557},"sh ",[512,594,595],{"class":534},"deptools-scan.sh",[512,597,598],{"class":534}," --wait\n",[502,600,605],{"className":601,"code":602,"filename":603,"language":604,"meta":508,"style":508},"language-yaml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","deptools-scan:\n  stage: test\n  image: alpine:3.20\n  before_script:\n    - apk add --no-cache curl tar\n  script:\n    - curl -fsSL https:\u002F\u002Fapi.deptools.io\u002Fdeptools-scan.sh -o deptools-scan.sh\n    # add --wait to block until the result and use this job as a CI gate\n    - sh deptools-scan.sh\n  rules:\n    - if: '$CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH'\n",".gitlab-ci.yml","yaml",[298,606,607,616,627,637,644,652,659,666,672,680,688],{"__ignoreMap":508},[512,608,609,613],{"class":514,"line":515},[512,610,612],{"class":611},"swJcz","deptools-scan",[512,614,615],{"class":560},":\n",[512,617,618,621,624],{"class":514,"line":522},[512,619,620],{"class":611},"  stage",[512,622,623],{"class":560},":",[512,625,626],{"class":534}," test\n",[512,628,629,632,634],{"class":514,"line":528},[512,630,631],{"class":611},"  image",[512,633,623],{"class":560},[512,635,636],{"class":534}," alpine:3.20\n",[512,638,639,642],{"class":514,"line":547},[512,640,641],{"class":611},"  before_script",[512,643,615],{"class":560},[512,645,646,649],{"class":514,"line":554},[512,647,648],{"class":560},"    -",[512,650,651],{"class":534}," apk add --no-cache curl tar\n",[512,653,654,657],{"class":514,"line":574},[512,655,656],{"class":611},"  script",[512,658,615],{"class":560},[512,660,661,663],{"class":514,"line":589},[512,662,648],{"class":560},[512,664,665],{"class":534}," curl -fsSL https:\u002F\u002Fapi.deptools.io\u002Fdeptools-scan.sh -o deptools-scan.sh\n",[512,667,669],{"class":514,"line":668},8,[512,670,671],{"class":518},"    # add --wait to block until the result and use this job as a CI gate\n",[512,673,675,677],{"class":514,"line":674},9,[512,676,648],{"class":560},[512,678,679],{"class":534}," sh deptools-scan.sh\n",[512,681,683,686],{"class":514,"line":682},10,[512,684,685],{"class":611},"  rules",[512,687,615],{"class":560},[512,689,691,693,696,698,701,704],{"class":514,"line":690},11,[512,692,648],{"class":560},[512,694,695],{"class":611}," if",[512,697,623],{"class":560},[512,699,700],{"class":560}," '",[512,702,703],{"class":534},"$CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH",[512,705,706],{"class":560},"'\n",[502,708,711],{"className":601,"code":709,"filename":710,"language":604,"meta":508,"style":508},"name: Deptools scan\non:\n  push:\n    branches: [main]\njobs:\n  deptools-scan:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions\u002Fcheckout@v4\n      # add --wait to block until the result and use this job as a CI gate\n      - run: |\n          curl -fsSL https:\u002F\u002Fapi.deptools.io\u002Fdeptools-scan.sh -o deptools-scan.sh\n          sh deptools-scan.sh\n        env:\n          DEPTOOLS_API_KEY: ${{ secrets.DEPTOOLS_API_KEY }}\n          DEPTOOLS_PROJECT_UUID: ${{ vars.DEPTOOLS_PROJECT_UUID }}\n",".github\u002Fworkflows\u002Fdeptools.yml",[298,712,713,723,731,738,754,761,768,778,785,798,803,816,822,828,836,847],{"__ignoreMap":508},[512,714,715,718,720],{"class":514,"line":515},[512,716,717],{"class":611},"name",[512,719,623],{"class":560},[512,721,722],{"class":534}," Deptools scan\n",[512,724,725,729],{"class":514,"line":522},[512,726,728],{"class":727},"sfNiH","on",[512,730,615],{"class":560},[512,732,733,736],{"class":514,"line":528},[512,734,735],{"class":611},"  push",[512,737,615],{"class":560},[512,739,740,743,745,748,751],{"class":514,"line":547},[512,741,742],{"class":611},"    branches",[512,744,623],{"class":560},[512,746,747],{"class":560}," [",[512,749,750],{"class":534},"main",[512,752,753],{"class":560},"]\n",[512,755,756,759],{"class":514,"line":554},[512,757,758],{"class":611},"jobs",[512,760,615],{"class":560},[512,762,763,766],{"class":514,"line":574},[512,764,765],{"class":611},"  deptools-scan",[512,767,615],{"class":560},[512,769,770,773,775],{"class":514,"line":589},[512,771,772],{"class":611},"    runs-on",[512,774,623],{"class":560},[512,776,777],{"class":534}," ubuntu-latest\n",[512,779,780,783],{"class":514,"line":668},[512,781,782],{"class":611},"    steps",[512,784,615],{"class":560},[512,786,787,790,793,795],{"class":514,"line":674},[512,788,789],{"class":560},"      -",[512,791,792],{"class":611}," uses",[512,794,623],{"class":560},[512,796,797],{"class":534}," actions\u002Fcheckout@v4\n",[512,799,800],{"class":514,"line":682},[512,801,802],{"class":518},"      # add --wait to block until the result and use this job as a CI gate\n",[512,804,805,807,810,812],{"class":514,"line":690},[512,806,789],{"class":560},[512,808,809],{"class":611}," run",[512,811,623],{"class":560},[512,813,815],{"class":814},"s7zQu"," |\n",[512,817,819],{"class":514,"line":818},12,[512,820,821],{"class":534},"          curl -fsSL https:\u002F\u002Fapi.deptools.io\u002Fdeptools-scan.sh -o deptools-scan.sh\n",[512,823,825],{"class":514,"line":824},13,[512,826,827],{"class":534},"          sh deptools-scan.sh\n",[512,829,831,834],{"class":514,"line":830},14,[512,832,833],{"class":611},"        env",[512,835,615],{"class":560},[512,837,839,842,844],{"class":514,"line":838},15,[512,840,841],{"class":611},"          DEPTOOLS_API_KEY",[512,843,623],{"class":560},[512,845,846],{"class":534}," ${{ secrets.DEPTOOLS_API_KEY }}\n",[512,848,850,853,855],{"class":514,"line":849},16,[512,851,852],{"class":611},"          DEPTOOLS_PROJECT_UUID",[512,854,623],{"class":560},[512,856,857],{"class":534}," ${{ vars.DEPTOOLS_PROJECT_UUID }}\n",[502,859,864],{"className":860,"code":861,"filename":862,"language":863,"meta":508,"style":508},"language-groovy shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","stage('Deptools scan') {\n  environment {\n    DEPTOOLS_API_KEY = credentials('deptools-api-key')\n    DEPTOOLS_PROJECT_UUID = 'your-project-uuid'\n  }\n  steps {\n    sh 'curl -fsSL https:\u002F\u002Fapi.deptools.io\u002Fdeptools-scan.sh -o deptools-scan.sh'\n    sh 'sh deptools-scan.sh --wait'\n  }\n}\n","Jenkinsfile","groovy",[298,865,866,888,893,915,929,934,939,951,962,966],{"__ignoreMap":508},[512,867,868,871,874,877,880,882,885],{"class":514,"line":515},[512,869,870],{"class":557},"stage",[512,872,873],{"class":560},"(",[512,875,876],{"class":560},"'",[512,878,879],{"class":534},"Deptools scan",[512,881,876],{"class":560},[512,883,884],{"class":560},")",[512,886,887],{"class":557}," {\n",[512,889,890],{"class":514,"line":522},[512,891,892],{"class":557},"  environment {\n",[512,894,895,898,900,903,905,907,910,912],{"class":514,"line":528},[512,896,897],{"class":557},"    DEPTOOLS_API_KEY ",[512,899,561],{"class":560},[512,901,902],{"class":557}," credentials",[512,904,873],{"class":560},[512,906,876],{"class":560},[512,908,909],{"class":534},"deptools-api-key",[512,911,876],{"class":560},[512,913,914],{"class":560},")\n",[512,916,917,920,922,924,927],{"class":514,"line":547},[512,918,919],{"class":557},"    DEPTOOLS_PROJECT_UUID ",[512,921,561],{"class":560},[512,923,700],{"class":560},[512,925,926],{"class":534},"your-project-uuid",[512,928,706],{"class":560},[512,930,931],{"class":514,"line":554},[512,932,933],{"class":557},"  }\n",[512,935,936],{"class":514,"line":574},[512,937,938],{"class":557},"  steps {\n",[512,940,941,944,946,949],{"class":514,"line":589},[512,942,943],{"class":557},"    sh ",[512,945,876],{"class":560},[512,947,948],{"class":534},"curl -fsSL https:\u002F\u002Fapi.deptools.io\u002Fdeptools-scan.sh -o deptools-scan.sh",[512,950,706],{"class":560},[512,952,953,955,957,960],{"class":514,"line":668},[512,954,943],{"class":557},[512,956,876],{"class":560},[512,958,959],{"class":534},"sh deptools-scan.sh --wait",[512,961,706],{"class":560},[512,963,964],{"class":514,"line":674},[512,965,933],{"class":557},[512,967,968],{"class":514,"line":682},[512,969,970],{"class":557},"}\n",[120,972,973],{},"The script takes two options:",[140,975,976,986],{},[143,977,978,981,982,985],{},[298,979,980],{},"--wait"," polls until the analysis ends and exits ",[298,983,984],{},"1"," if it fails, which turns\nthe job into a pipeline gate. Without it, the job pushes and returns\nimmediately.",[143,987,988,991],{},[298,989,990],{},"--dir \u003Cpath>"," collects from another directory than the current one.",[120,993,994,995,998,999,1002],{},"It also reads the branch and the commit SHA from GitLab CI, from GitHub Actions\nor from the local git checkout, and sends them as labels. ",[298,996,997],{},"DEPTOOLS_BRANCH"," and\n",[298,1000,1001],{},"DEPTOOLS_COMMIT_SHA"," override that detection.",[120,1004,1005],{},"A cron job works as well as a pipeline. There is no cooldown on Pro, so you can\npush on every commit.",[398,1007,1009],{"id":1008},"what-gets-collected","What gets collected",[120,1011,1012],{},"The script and the server apply the same allowlist. Everything else in the\narchive is discarded, so archiving too much is harmless, only slower to transfer.",[251,1014,1015,1025],{},[254,1016,1017],{},[257,1018,1019,1022],{},[260,1020,1021],{},"Ecosystem",[260,1023,1024],{},"Files collected",[270,1026,1027,1037,1065,1089,1113],{},[257,1028,1029,1031],{},[275,1030,300],{},[275,1032,1033,1036],{},[298,1034,1035],{},"pom.xml",", at any depth",[257,1038,1039,1041],{},[275,1040,304],{},[275,1042,1043,1044,494,1047,1050,1051,1054,1055,494,1058,315,1061,1064],{},"every ",[298,1045,1046],{},"*.gradle",[298,1048,1049],{},"*.gradle.kts",", including ",[298,1052,1053],{},"settings.gradle",", convention plugins and local platform files, plus ",[298,1056,1057],{},"gradle.properties",[298,1059,1060],{},"libs.versions.toml",[298,1062,1063],{},"init.gradle"," is ignored",[257,1066,1067,1069],{},[275,1068,307],{},[275,1070,1043,1071,1074,1075,494,1078,1081,1082,1085,1086],{},[298,1072,1073],{},"*.sbt"," at any depth, plus ",[298,1076,1077],{},"project\u002F*.scala",[298,1079,1080],{},"project\u002Fbuild.properties",". Never the Scala sources under ",[298,1083,1084],{},"src\u002F",", never the meta build ",[298,1087,1088],{},"project\u002Fproject\u002F",[257,1090,1091,1093],{},[275,1092,310],{},[275,1094,1095,301,1098,301,1101,301,1104,301,1107,301,1110],{},[298,1096,1097],{},"package.json",[298,1099,1100],{},"package-lock.json",[298,1102,1103],{},"npm-shrinkwrap.json",[298,1105,1106],{},"yarn.lock",[298,1108,1109],{},"pnpm-lock.yaml",[298,1111,1112],{},"pnpm-workspace.yaml",[257,1114,1115,1117],{},[275,1116,314],{},[275,1118,1119,494,1122],{},[298,1120,1121],{},"composer.json",[298,1123,1124],{},"composer.lock",[120,1126,1127,1128,301,1131,301,1134,301,1137,494,1140,1143,1144,234],{},"The content of ",[298,1129,1130],{},"node_modules\u002F",[298,1132,1133],{},".git\u002F",[298,1135,1136],{},"target\u002F",[298,1138,1139],{},"build\u002F",[298,1141,1142],{},"vendor\u002F"," is\nnever collected, at any depth, and neither are the macOS metadata files ",[298,1145,1146],{},"._*",[214,1148,1149,1150,311,1152,1154],{},"A build file committed under ",[298,1151,1139],{},[298,1153,1136],{}," is dropped with the rest of\nthose directories, since they normally hold compilation output. If that is where\nyour real build file lives, this path cannot read it.",[385,1156,1157,1158,301,1160,1162,1163,311,1165,1167],{},"Commit your lockfile. With ",[298,1159,1100],{},[298,1161,1109],{},",\n",[298,1164,1124],{},[298,1166,1106],{}," in the archive, the analysis describes the tree\nyou actually install instead of resolving your version constraints. It is also\nwhat limits the damage when a package is private and cannot be resolved from the\npublic registry.",[398,1169,1171],{"id":1170},"limits-on-the-archive","Limits on the archive",[251,1173,1174,1186],{},[254,1175,1176],{},[257,1177,1178,1181,1183],{},[260,1179,1180],{},"Rule",[260,1182,455],{},[260,1184,1185],{},"Error",[270,1187,1188,1201,1213,1226,1239,1252,1269],{},[257,1189,1190,1193,1196],{},[275,1191,1192],{},"Compressed archive",[275,1194,1195],{},"15 MB",[275,1197,1198],{},[298,1199,1200],{},"413 BUNDLE_TOO_LARGE",[257,1202,1203,1206,1209],{},[275,1204,1205],{},"Total uncompressed size",[275,1207,1208],{},"50 MB",[275,1210,1211],{},[298,1212,1200],{},[257,1214,1215,1218,1221],{},[275,1216,1217],{},"One collected file, uncompressed",[275,1219,1220],{},"5 MB",[275,1222,1223],{},[298,1224,1225],{},"413 FILE_TOO_LARGE",[257,1227,1228,1231,1234],{},[275,1229,1230],{},"Entries in the archive",[275,1232,1233],{},"5 000",[275,1235,1236],{},[298,1237,1238],{},"413 TOO_MANY_ENTRIES",[257,1240,1241,1244,1247],{},[275,1242,1243],{},"Encoding of collected files",[275,1245,1246],{},"strict UTF-8",[275,1248,1249],{},[298,1250,1251],{},"400 INVALID_ENCODING",[257,1253,1254,1257,1264],{},[275,1255,1256],{},"Paths",[275,1258,1259,1260,1263],{},"relative, no ",[298,1261,1262],{},"..",", no absolute path",[275,1265,1266],{},[298,1267,1268],{},"400 INVALID_ENTRY_PATH",[257,1270,1271,1274,1277],{},[275,1272,1273],{},"Entry types",[275,1275,1276],{},"regular files only, no symbolic links",[275,1278,1279],{},[298,1280,1281],{},"400 UNSUPPORTED_ENTRY_TYPE",[120,1283,1284,1285,1287],{},"The entry count is checked on the archive, before the allowlist runs. So prune\n",[298,1286,1130],{}," on your side to keep a large project under the ceiling, even\nthough the server would have discarded those files anyway.",[398,1289,1291],{"id":1290},"without-the-script","Without the script",[120,1293,1294,1295,623],{},"Any HTTP client works. The request is one multipart ",[298,1296,1297],{},"POST",[502,1299,1303],{"className":1300,"code":1301,"language":1302,"meta":508,"style":508},"language-http shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","POST https:\u002F\u002Fapi.deptools.io\u002Fv1\u002Fprojects\u002F\u003Cuuid>\u002Fscan\nAuthorization: Bearer dt_org_...\nContent-Type: multipart\u002Fform-data\n","http",[298,1304,1305,1312,1323],{"__ignoreMap":508},[512,1306,1307,1309],{"class":514,"line":515},[512,1308,1297],{"class":814},[512,1310,1311],{"class":557}," https:\u002F\u002Fapi.deptools.io\u002Fv1\u002Fprojects\u002F\u003Cuuid>\u002Fscan\n",[512,1313,1314,1317,1320],{"class":514,"line":522},[512,1315,1316],{"class":611},"Authorization",[512,1318,623],{"class":1319},"sbssI",[512,1321,1322],{"class":534}," Bearer dt_org_...\n",[512,1324,1325,1328,1330],{"class":514,"line":528},[512,1326,1327],{"class":611},"Content-Type",[512,1329,623],{"class":1319},[512,1331,1332],{"class":534}," multipart\u002Fform-data\n",[251,1334,1335,1346],{},[254,1336,1337],{},[257,1338,1339,1341,1343],{},[260,1340,262],{},[260,1342,265],{},[260,1344,1345],{},"Description",[270,1347,1348,1364,1376],{},[257,1349,1350,1355,1357],{},[275,1351,1352],{},[298,1353,1354],{},"bundle",[275,1356,282],{},[275,1358,1359,1360,1363],{},"The ",[298,1361,1362],{},"tar.gz"," archive, paths relative to the repository root",[257,1365,1366,1371,1373],{},[275,1367,1368],{},[298,1369,1370],{},"branch",[275,1372,328],{},[275,1374,1375],{},"Branch label, for traceability",[257,1377,1378,1383,1385],{},[275,1379,1380],{},[298,1381,1382],{},"commitSha",[275,1384,328],{},[275,1386,1387],{},"Commit SHA, for traceability",[502,1389,1392],{"className":1390,"code":1391,"language":490,"meta":508,"style":508},"language-sh shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","# From the repository root: archive the build files\ntar czf bundle.tar.gz $(git ls-files '*pom.xml' '*.gradle' '*.gradle.kts' \\\n  '*gradle.properties' '*libs.versions.toml' '*.sbt' '*project\u002F*.scala' \\\n  '*project\u002Fbuild.properties' '*package.json' '*package-lock.json' \\\n  '*yarn.lock' '*pnpm-lock.yaml' '*pnpm-workspace.yaml' '*npm-shrinkwrap.json' \\\n  '*composer.json' '*composer.lock' \\\n  ':(exclude,glob)**\u002Fnode_modules\u002F**' ':(exclude,glob)**\u002Fvendor\u002F**' \\\n  ':(exclude,glob)**\u002Ftarget\u002F**' ':(exclude,glob)**\u002Fbuild\u002F**')\n\n# Push archive to Deptools\ncurl --fail-with-body -sS \\\n  -H \"Authorization: Bearer $DEPTOOLS_API_KEY\" \\\n  -F \"bundle=@bundle.tar.gz\" \\\n  -F \"branch=$CI_COMMIT_REF_NAME\" \\\n  -F \"commitSha=$CI_COMMIT_SHA\" \\\n  \"https:\u002F\u002Fapi.deptools.io\u002Fv1\u002Fprojects\u002F$DEPTOOLS_PROJECT_UUID\u002Fscan\"\n# → 202 { \"jobId\": \"abc123\", \"pollUrl\": \"\u002Fv1\u002Fscans\u002Fabc123\u002Fstatus\" }\n",[298,1393,1394,1399,1439,1471,1496,1528,1546,1564,1582,1586,1591,1603,1621,1635,1651,1667,1684],{"__ignoreMap":508},[512,1395,1396],{"class":514,"line":515},[512,1397,1398],{"class":518},"# From the repository root: archive the build files\n",[512,1400,1401,1403,1406,1409,1412,1415,1418,1420,1423,1425,1427,1429,1431,1433,1435,1437],{"class":514,"line":522},[512,1402,493],{"class":531},[512,1404,1405],{"class":534}," czf",[512,1407,1408],{"class":534}," bundle.tar.gz",[512,1410,1411],{"class":560}," $(",[512,1413,1414],{"class":531},"git",[512,1416,1417],{"class":534}," ls-files",[512,1419,700],{"class":560},[512,1421,1422],{"class":534},"*pom.xml",[512,1424,876],{"class":560},[512,1426,700],{"class":560},[512,1428,1046],{"class":534},[512,1430,876],{"class":560},[512,1432,700],{"class":560},[512,1434,1049],{"class":534},[512,1436,876],{"class":560},[512,1438,571],{"class":557},[512,1440,1441,1444,1447,1449,1451,1454,1456,1458,1460,1462,1464,1467,1469],{"class":514,"line":528},[512,1442,1443],{"class":560},"  '",[512,1445,1446],{"class":534},"*gradle.properties",[512,1448,876],{"class":560},[512,1450,700],{"class":560},[512,1452,1453],{"class":534},"*libs.versions.toml",[512,1455,876],{"class":560},[512,1457,700],{"class":560},[512,1459,1073],{"class":534},[512,1461,876],{"class":560},[512,1463,700],{"class":560},[512,1465,1466],{"class":534},"*project\u002F*.scala",[512,1468,876],{"class":560},[512,1470,571],{"class":557},[512,1472,1473,1475,1478,1480,1482,1485,1487,1489,1492,1494],{"class":514,"line":547},[512,1474,1443],{"class":560},[512,1476,1477],{"class":534},"*project\u002Fbuild.properties",[512,1479,876],{"class":560},[512,1481,700],{"class":560},[512,1483,1484],{"class":534},"*package.json",[512,1486,876],{"class":560},[512,1488,700],{"class":560},[512,1490,1491],{"class":534},"*package-lock.json",[512,1493,876],{"class":560},[512,1495,571],{"class":557},[512,1497,1498,1500,1503,1505,1507,1510,1512,1514,1517,1519,1521,1524,1526],{"class":514,"line":554},[512,1499,1443],{"class":560},[512,1501,1502],{"class":534},"*yarn.lock",[512,1504,876],{"class":560},[512,1506,700],{"class":560},[512,1508,1509],{"class":534},"*pnpm-lock.yaml",[512,1511,876],{"class":560},[512,1513,700],{"class":560},[512,1515,1516],{"class":534},"*pnpm-workspace.yaml",[512,1518,876],{"class":560},[512,1520,700],{"class":560},[512,1522,1523],{"class":534},"*npm-shrinkwrap.json",[512,1525,876],{"class":560},[512,1527,571],{"class":557},[512,1529,1530,1532,1535,1537,1539,1542,1544],{"class":514,"line":574},[512,1531,1443],{"class":560},[512,1533,1534],{"class":534},"*composer.json",[512,1536,876],{"class":560},[512,1538,700],{"class":560},[512,1540,1541],{"class":534},"*composer.lock",[512,1543,876],{"class":560},[512,1545,571],{"class":557},[512,1547,1548,1550,1553,1555,1557,1560,1562],{"class":514,"line":589},[512,1549,1443],{"class":560},[512,1551,1552],{"class":534},":(exclude,glob)**\u002Fnode_modules\u002F**",[512,1554,876],{"class":560},[512,1556,700],{"class":560},[512,1558,1559],{"class":534},":(exclude,glob)**\u002Fvendor\u002F**",[512,1561,876],{"class":560},[512,1563,571],{"class":557},[512,1565,1566,1568,1571,1573,1575,1578,1580],{"class":514,"line":668},[512,1567,1443],{"class":560},[512,1569,1570],{"class":534},":(exclude,glob)**\u002Ftarget\u002F**",[512,1572,876],{"class":560},[512,1574,700],{"class":560},[512,1576,1577],{"class":534},":(exclude,glob)**\u002Fbuild\u002F**",[512,1579,876],{"class":560},[512,1581,914],{"class":560},[512,1583,1584],{"class":514,"line":674},[512,1585,551],{"emptyLinePlaceholder":550},[512,1587,1588],{"class":514,"line":682},[512,1589,1590],{"class":518},"# Push archive to Deptools\n",[512,1592,1593,1595,1598,1601],{"class":514,"line":690},[512,1594,497],{"class":531},[512,1596,1597],{"class":534}," --fail-with-body",[512,1599,1600],{"class":534}," -sS",[512,1602,571],{"class":557},[512,1604,1605,1608,1611,1614,1617,1619],{"class":514,"line":818},[512,1606,1607],{"class":534},"  -H",[512,1609,1610],{"class":560}," \"",[512,1612,1613],{"class":534},"Authorization: Bearer ",[512,1615,1616],{"class":557},"$DEPTOOLS_API_KEY",[512,1618,564],{"class":560},[512,1620,571],{"class":557},[512,1622,1623,1626,1628,1631,1633],{"class":514,"line":824},[512,1624,1625],{"class":534},"  -F",[512,1627,1610],{"class":560},[512,1629,1630],{"class":534},"bundle=@bundle.tar.gz",[512,1632,564],{"class":560},[512,1634,571],{"class":557},[512,1636,1637,1639,1641,1644,1647,1649],{"class":514,"line":830},[512,1638,1625],{"class":534},[512,1640,1610],{"class":560},[512,1642,1643],{"class":534},"branch=",[512,1645,1646],{"class":557},"$CI_COMMIT_REF_NAME",[512,1648,564],{"class":560},[512,1650,571],{"class":557},[512,1652,1653,1655,1657,1660,1663,1665],{"class":514,"line":838},[512,1654,1625],{"class":534},[512,1656,1610],{"class":560},[512,1658,1659],{"class":534},"commitSha=",[512,1661,1662],{"class":557},"$CI_COMMIT_SHA",[512,1664,564],{"class":560},[512,1666,571],{"class":557},[512,1668,1669,1672,1675,1678,1681],{"class":514,"line":849},[512,1670,1671],{"class":560},"  \"",[512,1673,1674],{"class":534},"https:\u002F\u002Fapi.deptools.io\u002Fv1\u002Fprojects\u002F",[512,1676,1677],{"class":557},"$DEPTOOLS_PROJECT_UUID",[512,1679,1680],{"class":534},"\u002Fscan",[512,1682,1683],{"class":560},"\"\n",[512,1685,1687],{"class":514,"line":1686},17,[512,1688,1689],{"class":518},"# → 202 { \"jobId\": \"abc123\", \"pollUrl\": \"\u002Fv1\u002Fscans\u002Fabc123\u002Fstatus\" }\n",[120,1691,194,1692,1695,1696,1699,1700,1703,1704,1707,1708,1711],{},[298,1693,1694],{},"202"," means the archive was accepted and the analysis started. Poll ",[298,1697,1698],{},"pollUrl","\nwith the same key to follow it. The response carries ",[298,1701,1702],{},"status",", then a ",[298,1705,1706],{},"result","\nblock once it reads ",[298,1709,1710],{},"completed",". Gate your pipeline on that block:",[502,1713,1717],{"className":1714,"code":1715,"language":1716,"meta":508,"style":508},"language-json shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","{\n  \"jobId\": \"abc123\",\n  \"status\": \"completed\",\n  \"createdAt\": \"2026-08-09T10:00:00.000Z\",\n  \"result\": {\n    \"overall_score\": 7.4,\n    \"dependency_number\": 182,\n    \"vulnerabilities_by_severity\": { \"CRITICAL\": 0, \"HIGH\": 2, \"MODERATE\": 5, \"LOW\": 1 },\n    \"commercial_use\": false,\n    \"direct_up_to_date\": 84\n  },\n  \"error\": null\n}\n","json",[298,1718,1719,1724,1745,1763,1783,1795,1812,1828,1900,1914,1928,1933,1947],{"__ignoreMap":508},[512,1720,1721],{"class":514,"line":515},[512,1722,1723],{"class":560},"{\n",[512,1725,1726,1728,1732,1734,1736,1738,1741,1743],{"class":514,"line":522},[512,1727,1671],{"class":560},[512,1729,1731],{"class":1730},"spNyl","jobId",[512,1733,564],{"class":560},[512,1735,623],{"class":560},[512,1737,1610],{"class":560},[512,1739,1740],{"class":534},"abc123",[512,1742,564],{"class":560},[512,1744,1162],{"class":560},[512,1746,1747,1749,1751,1753,1755,1757,1759,1761],{"class":514,"line":528},[512,1748,1671],{"class":560},[512,1750,1702],{"class":1730},[512,1752,564],{"class":560},[512,1754,623],{"class":560},[512,1756,1610],{"class":560},[512,1758,1710],{"class":534},[512,1760,564],{"class":560},[512,1762,1162],{"class":560},[512,1764,1765,1767,1770,1772,1774,1776,1779,1781],{"class":514,"line":547},[512,1766,1671],{"class":560},[512,1768,1769],{"class":1730},"createdAt",[512,1771,564],{"class":560},[512,1773,623],{"class":560},[512,1775,1610],{"class":560},[512,1777,1778],{"class":534},"2026-08-09T10:00:00.000Z",[512,1780,564],{"class":560},[512,1782,1162],{"class":560},[512,1784,1785,1787,1789,1791,1793],{"class":514,"line":554},[512,1786,1671],{"class":560},[512,1788,1706],{"class":1730},[512,1790,564],{"class":560},[512,1792,623],{"class":560},[512,1794,887],{"class":560},[512,1796,1797,1800,1803,1805,1807,1810],{"class":514,"line":574},[512,1798,1799],{"class":560},"    \"",[512,1801,1802],{"class":531},"overall_score",[512,1804,564],{"class":560},[512,1806,623],{"class":560},[512,1808,1809],{"class":1319}," 7.4",[512,1811,1162],{"class":560},[512,1813,1814,1816,1819,1821,1823,1826],{"class":514,"line":589},[512,1815,1799],{"class":560},[512,1817,1818],{"class":531},"dependency_number",[512,1820,564],{"class":560},[512,1822,623],{"class":560},[512,1824,1825],{"class":1319}," 182",[512,1827,1162],{"class":560},[512,1829,1830,1832,1835,1837,1839,1842,1844,1847,1849,1851,1854,1857,1859,1862,1864,1866,1869,1871,1873,1876,1878,1880,1883,1885,1887,1890,1892,1894,1897],{"class":514,"line":668},[512,1831,1799],{"class":560},[512,1833,1834],{"class":531},"vulnerabilities_by_severity",[512,1836,564],{"class":560},[512,1838,623],{"class":560},[512,1840,1841],{"class":560}," {",[512,1843,1610],{"class":560},[512,1845,1846],{"class":1319},"CRITICAL",[512,1848,564],{"class":560},[512,1850,623],{"class":560},[512,1852,1853],{"class":1319}," 0",[512,1855,1856],{"class":560},",",[512,1858,1610],{"class":560},[512,1860,1861],{"class":1319},"HIGH",[512,1863,564],{"class":560},[512,1865,623],{"class":560},[512,1867,1868],{"class":1319}," 2",[512,1870,1856],{"class":560},[512,1872,1610],{"class":560},[512,1874,1875],{"class":1319},"MODERATE",[512,1877,564],{"class":560},[512,1879,623],{"class":560},[512,1881,1882],{"class":1319}," 5",[512,1884,1856],{"class":560},[512,1886,1610],{"class":560},[512,1888,1889],{"class":1319},"LOW",[512,1891,564],{"class":560},[512,1893,623],{"class":560},[512,1895,1896],{"class":1319}," 1",[512,1898,1899],{"class":560}," },\n",[512,1901,1902,1904,1907,1909,1911],{"class":514,"line":674},[512,1903,1799],{"class":560},[512,1905,1906],{"class":531},"commercial_use",[512,1908,564],{"class":560},[512,1910,623],{"class":560},[512,1912,1913],{"class":560}," false,\n",[512,1915,1916,1918,1921,1923,1925],{"class":514,"line":682},[512,1917,1799],{"class":560},[512,1919,1920],{"class":531},"direct_up_to_date",[512,1922,564],{"class":560},[512,1924,623],{"class":560},[512,1926,1927],{"class":1319}," 84\n",[512,1929,1930],{"class":514,"line":690},[512,1931,1932],{"class":560},"  },\n",[512,1934,1935,1937,1940,1942,1944],{"class":514,"line":818},[512,1936,1671],{"class":560},[512,1938,1939],{"class":1730},"error",[512,1941,564],{"class":560},[512,1943,623],{"class":560},[512,1945,1946],{"class":560}," null\n",[512,1948,1949],{"class":514,"line":824},[512,1950,970],{"class":560},[120,1952,1953],{},"The push endpoint accepts 60 requests per hour and per IP address, the status\nendpoint 120.",[398,1955,1957],{"id":1956},"what-deptools-keeps-from-your-archive","What Deptools keeps from your archive",[120,1959,1960],{},"This is the only path where your files reach Deptools at all.",[120,1962,1963],{},"The archive is filtered as it arrives. It is never written to disk and never\nextracted into a directory tree: it is read as a stream, every entry outside the\nallowlist above is dropped immediately, and the rest is kept as text in a single\nsnapshot. Nothing in it is ever executed.",[120,1965,1966],{},"That snapshot is deleted as soon as the analysis reaches a terminal state,\nwhether it succeeded or failed. Deptools keeps the analysis result afterwards,\nthe graph, the scores and the metrics, exactly as for a GitHub project.",[120,1968,1969,1970,1975],{},"So a source file that slipped into your archive is discarded before the analysis\nstarts, and a build file is deleted when the analysis ends. See\n",[161,1971,1972],{"href":1972,"rel":1973},"https:\u002F\u002Fdeptools.io\u002Fprivacy",[1974],"nofollow"," for retention and personal data.",[132,1977,1979],{"id":1978},"check-that-the-first-push-worked","Check that the first push worked",[120,1981,1359,1982,1984,1985,1988,1989,1992],{},[124,1983,419],{}," tab follows the setup end to end and updates on its own, no\nrefresh needed. Its last step reports what happened to your first push:\n",[124,1986,1987],{},"Waiting for your first push",", then the analysis running, then ",[124,1990,1991],{},"First\nanalysis received",", or the failure and its reason.",[372,1994],{"alt":1995,"dark":1996,"light":1997,"className":1998},"CI setup checklist of an upload project, waiting for the first push","\u002Fimages\u002Fdocs\u002Fguides\u002Fanalyze-a-project-without-github-2-ci-checklist-dark.webp","\u002Fimages\u002Fdocs\u002Fguides\u002Fanalyze-a-project-without-github-2-ci-checklist-light.webp",[1999],"wide-capture",[120,2001,2002,2003,2006,2007,2010],{},"Once the first analysis arrives, the project behaves like any other: the\ndashboard, the history and the exports all work the same way. One difference\nstays visible, and it is deliberate. Where a GitHub project offers a ",[124,2004,2005],{},"Run\nscan"," button, an upload project reads ",[124,2008,2009],{},"Scans are triggered from your CI",".\nDeptools has no way to fetch your files on its own, so every analysis comes from\na push.",[398,2012,2014],{"id":2013},"when-the-push-is-refused","When the push is refused",[120,2016,2017],{},"Rejections happen before the analysis starts, and the message names the cause. The\nscript prints it, and prints the module list or the detected build systems when\nthe response carries them.",[251,2019,2020,2033],{},[254,2021,2022],{},[257,2023,2024,2027,2030],{},[260,2025,2026],{},"HTTP",[260,2028,2029],{},"Code",[260,2031,2032],{},"Meaning and fix",[270,2034,2035,2048,2060,2073,2083,2099,2113,2125,2141,2157,2175,2194,2209],{},[257,2036,2037,2040,2042],{},[275,2038,2039],{},"401",[275,2041],{},[275,2043,2044,2045],{},"Key missing or malformed. The header is ",[298,2046,2047],{},"Authorization: Bearer dt_org_...",[257,2049,2050,2052,2057],{},[275,2051,2039],{},[275,2053,2054],{},[298,2055,2056],{},"API_KEY_EXPIRED",[275,2058,2059],{},"The key passed its expiration date. Create a new one",[257,2061,2062,2065,2070],{},[275,2063,2064],{},"403",[275,2066,2067],{},[298,2068,2069],{},"PRO_PLAN_REQUIRED",[275,2071,2072],{},"The organization is not on Pro, or no longer is",[257,2074,2075,2078,2080],{},[275,2076,2077],{},"404",[275,2079],{},[275,2081,2082],{},"Unknown UUID, or a project outside the key's scope. A project key reaches its own project only. The answer is deliberately the same in both cases",[257,2084,2085,2088,2093],{},[275,2086,2087],{},"400",[275,2089,2090],{},[298,2091,2092],{},"BUNDLE_REQUIRED",[275,2094,2095,2096,2098],{},"The request carries no multipart body, or no ",[298,2097,1354],{}," field",[257,2100,2101,2103,2108],{},[275,2102,2087],{},[275,2104,2105],{},[298,2106,2107],{},"INVALID_ARCHIVE",[275,2109,2110,2111],{},"The file is not a valid ",[298,2112,1362],{},[257,2114,2115,2117,2122],{},[275,2116,2087],{},[275,2118,2119],{},[298,2120,2121],{},"NO_BUILD_FILES_FOUND",[275,2123,2124],{},"No recognized build file in the archive. Check that the job runs at the repository root",[257,2126,2127,2129,2134],{},[275,2128,2087],{},[275,2130,2131],{},[298,2132,2133],{},"BUILD_SYSTEM_MISMATCH",[275,2135,2136,2137,2140],{},"The archive holds no build file of the project's build system. The response lists ",[298,2138,2139],{},"detectedBuildSystems",". The build system is fixed, so fix the archive or recreate the project",[257,2142,2143,2145,2150],{},[275,2144,2087],{},[275,2146,2147],{},[298,2148,2149],{},"SUBFOLDER_NOT_FOUND",[275,2151,2152,2153,2156],{},"The configured subfolder matches no module in the archive. The response lists ",[298,2154,2155],{},"availableModules",", copy the right one into the project settings",[257,2158,2159,2161,2172],{},[275,2160,2087],{},[275,2162,2163,301,2166,301,2169],{},[298,2164,2165],{},"INVALID_ENCODING",[298,2167,2168],{},"INVALID_ENTRY_PATH",[298,2170,2171],{},"UNSUPPORTED_ENTRY_TYPE",[275,2173,2174],{},"A collected file is not UTF-8, a path escapes the archive root, or an entry is not a regular file",[257,2176,2177,2180,2191],{},[275,2178,2179],{},"413",[275,2181,2182,301,2185,301,2188],{},[298,2183,2184],{},"BUNDLE_TOO_LARGE",[298,2186,2187],{},"FILE_TOO_LARGE",[298,2189,2190],{},"TOO_MANY_ENTRIES",[275,2192,2193],{},"A cap above is exceeded",[257,2195,2196,2199,2204],{},[275,2197,2198],{},"422",[275,2200,2201],{},[298,2202,2203],{},"UPLOAD_NOT_SUPPORTED_FOR_GIT_PROJECTS",[275,2205,2206,2207],{},"The UUID belongs to a project linked to a Git repository, which takes no body. Check ",[298,2208,474],{},[257,2210,2211,2214,2219],{},[275,2212,2213],{},"429",[275,2215,2216],{},[298,2217,2218],{},"SCAN_RATE_LIMITED",[275,2220,2221],{},"The 60 pushes per hour are used up",[120,2223,2224],{},"An archive is never partly accepted. When one of these errors occurs, no\nanalysis runs and no file is stored.",[398,2226,2228],{"id":2227},"when-the-analysis-itself-fails","When the analysis itself fails",[120,2230,194,2231,2233],{},[298,2232,1694],{}," means the archive was accepted, not that the analysis will succeed. Two\nfailures are specific to this path, and neither is a bug on your side:",[140,2235,2236,2242],{},[143,2237,2238,2241],{},[124,2239,2240],{},"Maven parents and BOMs hosted on an internal registry"," cannot be reached\nfrom outside your network. They surface as analysis errors, and the rest of\nthe analysis completes.",[143,2243,2244,2247],{},[124,2245,2246],{},"Private packages",", npm or otherwise, cannot be resolved from the public\nregistry and are listed as skipped. A committed lockfile limits the loss,\nsince the versions are then already pinned.",[120,2249,2250],{},"The other failures are the ordinary ones, and the project page names the cause.",[132,2252,2254],{"id":2253},"next-steps","Next steps",[140,2256,2257,2262],{},[143,2258,2259,2261],{},[161,2260,59],{"href":60}," to set an expiration and rotate a\nkey without breaking a pipeline.",[143,2263,2264,2266],{},[161,2265,64],{"href":65}," when a\nwhole portfolio has to be connected.",[2268,2269,2270],"style",{},"html pre.shiki code .sHwdD, html code.shiki .sHwdD{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#676E95;--shiki-dark-font-style:italic}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sfNiH, html code.shiki .sfNiH{--shiki-light:#FF5370;--shiki-default:#FF9CAC;--shiki-dark:#FF9CAC}html pre.shiki code .s7zQu, html code.shiki .s7zQu{--shiki-light:#39ADB5;--shiki-light-font-style:italic;--shiki-default:#89DDFF;--shiki-default-font-style:italic;--shiki-dark:#89DDFF;--shiki-dark-font-style:italic}html pre.shiki code .sbssI, html code.shiki .sbssI{--shiki-light:#F76D47;--shiki-default:#F78C6C;--shiki-dark:#F78C6C}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}",{"title":508,"searchDepth":522,"depth":522,"links":2272},[2273,2274,2275,2276,2285,2289],{"id":134,"depth":522,"text":135},{"id":176,"depth":522,"text":177},{"id":237,"depth":522,"text":238},{"id":392,"depth":522,"text":393,"children":2277},[2278,2279,2280,2281,2282,2283,2284],{"id":400,"depth":528,"text":401},{"id":442,"depth":528,"text":443},{"id":483,"depth":528,"text":484},{"id":1008,"depth":528,"text":1009},{"id":1170,"depth":528,"text":1171},{"id":1290,"depth":528,"text":1291},{"id":1956,"depth":528,"text":1957},{"id":1978,"depth":522,"text":1979,"children":2286},[2287,2288],{"id":2013,"depth":528,"text":2014},{"id":2227,"depth":528,"text":2228},{"id":2253,"depth":522,"text":2254},"Push your build files from any pipeline when your code does not live on GitHub.com.","md",null,{},{"icon":41,"group":36},{"title":38,"description":2290},"Jz3nck9cXqky8xUsUQkrSAa-GeGfXkxlI84LbBgqWkk",[2298,2300],{"title":32,"path":33,"stem":34,"description":2299,"icon":35,"group":36,"children":-1},"Install the GitHub App, choose what it can read, and add a public or a private repository.",{"title":43,"path":44,"stem":45,"description":2301,"icon":46,"group":36,"children":-1},"Control your dependency graph scope. Choose which dependency scopes are included in your analysis and score.",1787263156568]