Source Code
Source Code
Static analysis of a local source path for cryptographic usage, with SARIF output for CI pipelines
Overview
The Source Code source performs static analysis of a local source path to identify cryptographic usage. It detects the algorithms, key sizes, and vulnerable function calls present in the code and emits findings. In CI mode it can produce SARIF output for integration with code-scanning workflows.
Scanning remote repositories from GitHub, GitLab, and Azure DevOps is gated behind a feature flag. Scanning a local source path is always available.
What It Scans
| Item | Details |
|---|---|
| Algorithms | Cryptographic algorithms referenced in source code |
| Key sizes | Key sizes used with detected algorithms |
| Vulnerable calls | Function calls associated with quantum-vulnerable cryptography |
| Findings | Per-location findings with severity and quantum risk |
| SARIF | Machine-readable findings for CI when running in CI mode |
When to Use
Shift-Left in CI/CD
Catch quantum-vulnerable cryptographic usage during code review and builds
Codebase Inventory
Understand which algorithms and key sizes your code depends on
How to Run
The Source Code source has a dedicated CLI subcommand. Point it at a local directory:
dke-scanner-agent source-code --path <DIR>
You can also run it from the Cockpit scan wizard:
Open Run a Scan
In the Cockpit, go to Run a Scan.
Select the source
In Step 1 (Source), choose Source Code.
Provide the source path
Supply the local source path (or a feature-enabled Git provider), then start the scan and review the findings.