Skip to main content
Everything else in Discover inventories things that are running. Code repository scans read source code instead. A code scan runs from the Console and needs only a GitHub connection. You install nothing.

Run a Code Repository Scan

1

Open the New Scan Modal

Open Discover in the sidebar and press + New Scan. Choose the Source code tab in the modal that opens.
2

Choose the GitHub Connection

Enter the GitHub connection identifier provided by your GitHub administrator, then choose the installation it belongs to. The repository list loads once this is valid.
3

Select a Repository

Pick a repository from the Repositories list, filtering by name or path if the list is long, and confirm the Repository owner.
The Scan button stays disabled until you select a repository from the list. Typing a name into the filter only narrows the list, so remember to click a repository.
4

Start the Scan

Click Scan. Progress appears in the Code scan progress panel, where you can also cancel a scan that is still running.

Read the Results

A finished scan appears on the Targets tab as a Target of kind Source code. Expand its row for the counts of Agents, tools, data sources, sensitive data, and workflows found. A succeeded scan also lists the Agents it discovered, each with a Register action. See Register a Discovered Agent.

Troubleshooting

No GitHub connection appears. The connection identifier comes from your GitHub administrator, who installs the Vijil GitHub App against the organization. Wait for that install before you try again. The scan failed. Check the connection identifier, repository access, and organization permissions before retrying. A repository the installation cannot read fails with an error.

Next Steps

Register a Discovered Agent

Move a finding into the Agent Registry.

Run an Evaluation

Test an Agent you registered.
Last modified on October 2, 2026