Scan Modes

Choose the right scan depth for your use case

Edit on GitHub

Launchsafe offers three scan modes to balance speed and thoroughness.

Quick

launchsafe --target ./app --scan-mode quick

Fast checks for obvious vulnerabilities. Best for:

  • CI/CD pipelines
  • Pull request validation
  • Rapid smoke tests

Duration: Minutes

Standard

launchsafe --target ./app --scan-mode standard

Balanced testing for routine security reviews. Best for:

  • Regular security assessments
  • Pre-release validation
  • Development milestones

Duration: 30 minutes to 1 hour

White-box behavior: Uses source-aware mapping and static triage to prioritize dynamic exploit validation paths.

Deep

launchsafe --target ./app --scan-mode deep

Thorough penetration testing. Best for:

  • Comprehensive security audits
  • Pre-production reviews
  • Critical application assessments

Duration: 1-4 hours depending on target complexity

White-box behavior: Runs broad source-aware triage (semgrep, AST structural search, secrets, supply-chain checks) and then systematically validates top candidates dynamically.

Choosing a Mode

ScenarioRecommended Mode
Every PRQuick
Weekly scansStandard
Before major releaseDeep
Bug bounty huntingDeep

On this page