Skip to main content

SCA Scanner Parameters

When configured globally, these parameters will apply to SCA scans across all projects. When configured at the project level, they will apply only to SCA scans for that project.

The table below presents all the optional parameters, and their values.

Notice

CLI flags are submitted on the scan level with the scan create command. API configs can be configured on the account or project level using the Configuration API or on the scan level as part of the request body of the POST /scans API. When using the POST /scans API the scan.config.sca prefix is left out.

Parameter

Values

Notes

CLI

API

Config as Code

Folder/file filter

Allow users to select specific folders or files that they want to include or exclude from the code scanning process.

  • Including a file type - *.java

  • Excluding a file type - !*.java

  • Use “,” sign to chain file types.

    for example: *.java,*.js

  • The parameter also supports including/excluding folders.

  • regex is not supported.

--sca-filter <string>

scan.config.sca.filter

  {
    "key": "scan.config.sca.filter",
    "value": "*.java,*.js",
    "allowOverride": true
  }

filter

Exploitable Path

Toggle On/Off

When Exploitable Path is activated, scans that use the SCA scanner will identify whether or not there is an exploitable path from your source code to the vulnerable 3rd party package.

Learn more about Exploitable Path.

--sca-exploitable-path <string>

scan.config.sca.ExploitablePath

  {
    "key": "scan.config.sca.ExploitablePath",
    "value": "true",
    "allowOverride": true
  }

ExploitablePath

New Vulnerability Comparison Mode

Project-Wide (default) or Branch-Based

Determines what is used as the base-line for determining whether or not a vulnerability is a New finding in the current scan.

  • Project-wide - compares to the most recent scan of any branch of the project.

  • Branch-based - compares to the most recent scan of the specific branch that was scanned.

scan.config.sca.vulnerabilityComparisonMode

  {
    "key": "scan.config.sca.vulnerabilityComparisonMode",
    "value": "Branch-Based",
    "allowOverride": true
  }

vulnerabilityComparisonMode

Java Language Version

8, 11, 17, 21 (default) or 25

Specify the Java version used for dependency resolution for gradle package manager. This version does not affect Java version used for maven resolution. If not defined, gradle scans will run with Java version 21 by default.

scan.config.sca.javaLanguageVersion

  {
    "key": "scan.config.sca.javaLanguageVersion",
    "value": "17",
    "allowOverride": true
  }

javaLanguageVersion

UV Resolution

true/false

Uses the UV package manager instead of pip for Python dependency resolution.

scan.config.sca.useUvResolution

  {
    "key": "scan.config.sca.useUvResolution",
    "value": "true",
    "allowOverride": true
  }

useUvResolution

Python Language Version

2.7, 3.11, 3.12, 3.13 (default) or 3.14

Specify the Python version used for dependency resolution for pip and poetry package managers. Poetry does not support Python prior to version 3, if version 2.7 is supplied, the default version is used instead. If not defined, scans will run with Python version 3.13 by default.

scan.config.sca.pythonLanguageVersion

  {
    "key": "scan.config.sca.pythonLanguageVersion",
    "value": "3.12",
    "allowOverride": true
  }

pythonLanguageVersion