Onboarding multiple repositories for scanning

Configure connections to repositories from the Applications page for static analysis and Software Composition Analysis scanning.

You can onboard multiple repositories at once by connecting directly to external repository providers and selecting relevant repositories. Onboarding repositories in this manner creates applications associated with the repositories. During onboarding, you can configure and schedule scans.

To onboard repositories:
  1. From the Applications page, click Onboard repositories.

  2. Select a repository provider:
    • GitHub Enterprise
    • Bitbucket
    • GitLab


  3. Select an AppScan Presence from the available Presence list, and click Authorize Presence.
  4. Once the connection is confirmed, click Next: Mapping.

  5. Choose the repositories to map to an asset group, then click Next.

  6. Configure settings to be associated with the mapped repositories, then click Next.
    • Asset group: The asset group that controls the associated applications.
    • Scan technology: Static analysis (SAST) or Software Composition Analysis (SCA)
    • Scan execution: Schedule scanning, scan now, or only link the repository to AppScan on Cloud

      When scheduling scanning, specify start date and time, and frequency.





  7. Review your choices then click Initiate Onboarding.

    HCL AppScan on Cloud creates an application for each connected repository.

  8. When onboarding is complete, HCL AppScan on Cloud displays results. Click Done to exit the wizard.