Choose an Interface¶
Choose the interface that fits your team's work. Scanning interfaces discover cryptographic assets in the selected source and generate inventory and assessment reports. Use the standalone Report Viewer when you need to review completed results without running a scan.
| Interface | Choose it when | Host requirements |
|---|---|---|
| Command Line | You need scripts, local automation, or CI control | Java and OpenGrep |
| VS Code | Developers need scans, report history, Problems, and source navigation | VS Code, Java, OpenGrep |
| Eclipse | Eclipse or Spring Tools teams need project scans and report review | IDE, Java, OpenGrep |
| Container Runner | You need a fixed non-interactive Linux runtime | Docker or Podman |
| Report Viewer | Reviewers need completed reports but should not run scans | Desktop browser |
| CI/CD | You need repeatable repository scans and retained evidence | CLI or container runner |
Shared behavior¶
- Completed scans provide an inventory, assessment, and source evidence.
- Repository and folder scans require a valid license in the current beta; limited file scans are available without a license.
- The Report Viewer is read-only and does not require activation.
- A finding does not cause a nonzero process exit by itself.
- Report data can contain source paths and code evidence and should be handled as sensitive engineering information.
For a first evaluation, use Quick Start.