Where scans run. One setting for both SCA and SAST.
- API (default) - the Sec1 server clones the repository and runs
the scans on its side. Requires the server to reach your SCM and any
artifact registries.
- CLI - everything runs on the Jenkins agent via the selected
Sec1 CLI Installation, so nothing needs to leave your network:
SAST analyzes the workspace locally and uploads only the report; SCA
generates an SBOM on the agent (with your own toolchain and
registry credentials) and uploads it. Works behind private SCMs and
private artifact registries (Nexus, Artifactory, private npm).
The scan log always prints the engine/CLI version used, so it is clear which
build produced the findings. (Pipelines that already generate an
SBOM can pass it via the sbomFile parameter instead of CLI
generation.)