The Sec1 CLI installation used when Scan Mode is CLI — one
installation serves both scans. Configure it once under
Manage Jenkins > Tools > Sec1 CLI with the
"Install from sec1.io" installer; it is auto-downloaded to each agent
(refreshed daily) and carries both binaries:
- sec1-cli — resolves the project's dependencies on the agent
(using the agent's own build tools and registry credentials),
generates an SBOM for the SCA scan and uploads it.
- sec1-sast — the SAST engine that analyzes the workspace
locally and uploads only the findings report.
The scan log prints the version of each binary used.