Skip to main content

Source Code

Applies to:
Local Source PathCryptographic Usage DetectionVulnerable Function CallsSARIF Output (CI mode)

Overview​

The Source Code source performs static analysis of a local source path to identify cryptographic usage. It detects the algorithms, key sizes, and vulnerable function calls present in the code and emits findings. In CI mode it can produce SARIF output for integration with code-scanning workflows.

Git providers are feature-gated

Scanning remote repositories from GitHub, GitLab, and Azure DevOps is gated behind a feature flag. Scanning a local source path is always available.

What It Scans​

ItemDetails
AlgorithmsCryptographic algorithms referenced in source code
Key sizesKey sizes used with detected algorithms
Vulnerable callsFunction calls associated with quantum-vulnerable cryptography
FindingsPer-location findings with severity and quantum risk
SARIFMachine-readable findings for CI when running in CI mode

When to Use​

💻

Shift-Left in CI/CD

Catch quantum-vulnerable cryptographic usage during code review and builds

🔍

Codebase Inventory

Understand which algorithms and key sizes your code depends on

How to Run​

The Source Code source has a dedicated CLI subcommand. Point it at a local directory:

dke-scanner-agent source-code --path <DIR>

You can also run it from the Cockpit scan wizard:

1

Open Run a Scan

In the Cockpit, go to Run a Scan.

2

Select the source

In Step 1 (Source), choose Source Code.

3

Provide the source path

Supply the local source path (or a feature-enabled Git provider), then start the scan and review the findings.