Scan Types
What LaunchSafe scans today: free public repository grades and Supabase settings checks today, and code scans of GitHub repositories when they open. Live-app testing is not open yet.
What runs today
| Scan | What it looks at | Cost |
|---|---|---|
| Code scan (when scans open) | A GitHub repository: the code, its dependencies, and secrets committed to it | Scan credits, by quote |
| Retest (when scans open) | One finding, to see whether it is fixed | Free within an allowance. See fix pull requests and retests |
| Supabase settings check | A connected Supabase project's security settings | Free. See Supabase |
| Public grade | A public GitHub repository, for anyone | Free. See the public grade |
When code scans open, a scan runs at one of three depths: quick (up to 60 minutes), standard (up to 6 hours) or deep (up to 24 hours). The quote shows the cost before you start.
What a scan tells you
Every scan records what it covered: code analysis, dependencies, committed secrets. A scan that did not cover something, or stopped early, says so. LaunchSafe never reports lost coverage as "nothing found".
A finding is never closed just because a later scan did not see it. See findings.
Not available yet
- Testing a live URL (black-box, or combined with code) is not open yet. You can prove you control a domain and save a target's scope settings now. See domain verification.
- Scheduled scans are not available.
- ZIP upload is not available.
- GitLab and Bitbucket scans. You can connect them, but scans cannot fetch their code yet.