Getting Started¶
Use this section to move from a release package to a reviewed first scan. A native installation requires Java and OpenGrep. A container installation requires Docker or Podman and does not require Java or OpenGrep on the host.
Recommended onboarding sequence¶
| Step | Outcome | Guide |
|---|---|---|
| 1. Choose a deployment | Native CLI/IDE, Linux container, CI/CD, or review-only viewer | Quick Start chooser |
| 2. Install prerequisites | Required third-party tools are installed from trusted sources | Prerequisites and official installation resources |
| 3. Check the workstation or runner | Required tools and versions are identified | Pre-install check |
| 4. Install the PostQ artifact | CLI, IDE integration, container, or viewer is available | Install |
| 5. Activate scanning | The offline trial validates successfully | Activate a License |
| 6. Scan the Java sample | A complete report folder is generated | Download the Java Quick Start project or use your own representative code |
| 7. Review evidence | Findings and unresolved context are assigned for action | Interpret Results |
Choose native or container execution¶
Use the native CLI when developers need direct source paths, IDE integration, or simple local automation. Use the container when platform teams need a controlled Linux runtime with fixed runtime dependencies and read-only source mounts.
The standalone Report Viewer does not scan and does not require a license. It can be distributed to authorized reviewers who only need completed reports.