Skip to content

FAQ ​

Does dagsec see my code? ​

Not with the GitHub Action, GitLab CI, CLI or AI agent integrations: they scan on your machine or runner. The GitHub App and dashboard clone the repository to the dagsec server for the scan and delete it right after. See Security and privacy.

Why scan all of git history? ​

Deleting a secret from the code doesn't remove it from history. Anyone who can clone the repository, including every fork, can read old commits.

Will dagsec fail my build on old findings? ​

No. On pull requests only commits the pull request adds are checked for secrets. Dependencies are checked as they are now.

Why didn't a moderate vulnerability fail the check? ​

Only critical and high vulnerabilities fail a scan. Moderate and low ones are listed in the report.

A test file has a fake key. Will that fail the check? ​

No, if it's in a test, docs or example location; it's listed as a fixture. See where a secret is.

Does dagsec use a real leaked credential? ​

Only to ask its provider, read-only, whether it still works, and only in your own CI or the GitHub App, where the repository's owner authorized the scan. Turn it off with --no-verify.

What happens if dagsec is down? ​

AI agent hooks let commands through. CI jobs fail to download the scanner and report why; the GitHub App reports a neutral check.

Which languages are supported? ​

JavaScript and TypeScript (npm, Yarn, pnpm, Bun), Python (pip, Poetry), Rust (Cargo), Go, Java and Kotlin (Maven, Gradle) and .NET (NuGet). See Supported ecosystems.

Can I run dagsec on my own servers? ​

The scanner runs on your own runners today. A fully self-hosted dagsec server isn't offered yet; write to hello@dagsec.net if you need it.