Skip to content

Choose an Interface

Choose the interface that fits your team's work. Scanning interfaces discover cryptographic assets in the selected source and generate inventory and assessment reports. Use the standalone Report Viewer when you need to review completed results without running a scan.

Interface Choose it when Host requirements
Command Line You need scripts, local automation, or CI control Java and OpenGrep
VS Code Developers need scans, report history, Problems, and source navigation VS Code, Java, OpenGrep
Eclipse Eclipse or Spring Tools teams need project scans and report review IDE, Java, OpenGrep
Container Runner You need a fixed non-interactive Linux runtime Docker or Podman
Report Viewer Reviewers need completed reports but should not run scans Desktop browser
CI/CD You need repeatable repository scans and retained evidence CLI or container runner

Shared behavior

  • Completed scans provide an inventory, assessment, and source evidence.
  • Repository and folder scans require a valid license in the current beta; limited file scans are available without a license.
  • The Report Viewer is read-only and does not require activation.
  • A finding does not cause a nonzero process exit by itself.
  • Report data can contain source paths and code evidence and should be handled as sensitive engineering information.

For a first evaluation, use Quick Start.