Create a full scan by uploading one or more archives. Supported archive formats include .tar, .tar.gz/.tgz, and .zip.
Each uploaded archive is extracted server-side and any supported manifest files (like package.json, package-lock.json, pnpm-lock.yaml, etc.) are ingested for the scan. If you upload multiple archives in a single request, the manifests from every archive are merged into one full scan. The response includes any files that were ignored.
The maximum combined number of files extracted from your upload is 10000 and each extracted file can be no bigger than 268 MB.
To make a scan's alerts show up in notifications and the main dashboard, pass these query parameters:
branch: the repo's default branch, e.g.mainmake_default_branch=trueset_as_pending_head=true
Without them, the scan's alerts only appear in its own report. Repos created by this endpoint have no default branch until make_default_branch=true sets one, and set_as_pending_head is ignored on other branches.
This endpoint consumes 1 unit of your quota.
This endpoint requires the following org token scopes:
- full-scans:create
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||