Back to Cerbi Scanner

Documentation

Security & privacy

Scanner is designed to be useful before an organization grants a new vendor access to source or telemetry. Local and CI scans stay on infrastructure you control unless an upload is explicitly enabled.

Execution model

Cerbi Scanner is a static-analysis tool. It reads source files under the scan target, evaluates logging calls against built-in or repository policy, and writes findings on the machine or CI runner where it executes. It does not modify the application or require a Cerbi control-plane connection.

cerbi-scanner scan . --fail-on none --no-snippets

No account required

A Scanner run does not require a Cerbi account, Azure deployment, or CerbiShield subscription. GitHub Actions users can run the published Marketplace Action without granting Cerbi access to the repository.

What leaves the runner or machine

DataDefault behaviorNotes
Source codeNot uploaded by defaultScanner performs static analysis on the local machine or CI runner and does not modify source files.
Source snippetsNot serialized in standard CI reportsThe GitHub Action and Azure DevOps wrapper pass --no-snippets by default for shared CI artifacts.
File pathsMay appear in findingsTreat generated reports as internal artifacts unless paths have been reviewed or normalized.
Log message templatesMay appearTemplates can contain field names; Scanner does not observe runtime field values.
Sensitive literalsBest-effort redactionReport explanations pass through Scanner redaction before serialization.
Telemetry / analyticsNoneThe Scanner pipeline has no analytics or telemetry sink.
CerbiShield uploadOff by defaultNetwork upload requires explicit opt-in and the required credential.

Report redaction

Before finding explanations are serialized, Scanner applies best-effort redaction for password/secret/token assignments, connection-string password fields, and long credential-like token values. This reduces accidental exposure in reports, but it is not a substitute for reviewing an artifact before making it public.

Do not publish reports blindly

Reports can contain local file paths and log-message templates. Treat them like other static-analysis artifacts and review them before sharing outside the intended engineering or security audience.

GitHub Actions data flow

The GitHub Marketplace Action runs Scanner on the GitHub Actions runner selected by your workflow. The wrapper sets up .NET 10, restores the tested Cerbi.Scanner package from NuGet, and writes JSON, SARIF, and Markdown reports into the runner workspace. It does not send source code or findings to a Cerbi service by default.

GitHub receives generated SARIF only when upload-sarif: 'true' is explicitly configured and the workflow grants security-events: write. The Action keeps source snippets disabled and fail-on: none enabled by default.

View the Cerbi Scanner Action in GitHub Marketplace

Azure DevOps data flow

The Azure DevOps task runs Scanner on the existing build agent. It does not send source code, findings, or report files to a Cerbi service by default. Generated reports stay in the pipeline workspace and can be published as Azure DevOps artifacts or summaries when configured.

The wrapper may access the network to install prerequisites when those options are enabled: .NET 10 can be installed on an agent that does not have it, and the Cerbi.Scanner global tool can be restored from the configured NuGet feed. Locked-down self-hosted agents can preinstall both and disable those install steps.

Explicit upload

Scanner has an upload path for optional CerbiShield workflows, but it is disabled unless the caller explicitly opts in and supplies the required authentication configuration. Omitting the opt-in keeps CerbiShield upload off.

If your organization only needs discovery or CI gating, you can use Scanner indefinitely without enabling CerbiShield upload. See CI/CD integration for GitHub Actions, Azure DevOps, and generic CLI examples.

NEXTChoose your next proof

Review a Scanner finding or logging requirement against your existing controls. If a recurring gap remains, scope one CerbiShield workload, policy, evaluation window, and evidence review.

One initial workload/Customer-hosted in Azure/Existing destinations remain
Scanner Security & Privacy — Cerbi Docs