The following table lists the manifest files known to the scanner. Code repository scans is handled by Console. Prisma Cloud doesnt modify or write to your repos. repoFull control of private repositories, repo_deploymentAccess deployment status, repo:inviteAccess repository invitations, security_eventsRead and write security events. Generate a personal access token in GitHub, and then save it in the Prisma Cloud Credentials Store so that the scanner can access your repositories for scanning. Specify any additional file names that should be included for analysis. Configure GitHub webhooks to rescan your repositories on push events. If you have a custom naming scheme for your manifest files, specify them here so that the scanner can find and parse them. prisma access saas prima Save the token in Prisma Clouds credentials store. Specify credentials for the repository owner. prisma Even if youre only scanning public repos, we recommend that you set up an access token for authenticated access. If the credentials have already been created in the Prisma Cloud credentials store, select it. In Defend > Vulnerabilities > Code Repositories, create vulnerability rules to tailor whats reported. They arent supported when the type is Public. For Compute Edition, you can enable SSL verification if your Console runs under a domain with a valid certificate signed by a known authority. Advanced settings > Explicit manifest names. sso integration GitHub Cloud and GitHub Enterprise are currently the only supported providers. If there are manifests the scanner should ignore, specify them here as well. The benefit of creating an access token for scanning public repos is that GitHub grants you a higher rate limit to their API, which Prisma Cloud utilizes for scanning. Prisma Cloud ships with a default rule that alerts on vulnerabilities. For each repo in scope, Prisma Cloud searches for well-known package manifest files, and enumerates the dependencies listed in them. Modern apps are increasingly composed of external, open source dependencies, so its important to give developers tools to assess those components early in the development lifecycle. Click Generate token. Those dependencies are assessed against the latest threat data in the Intelligence Stream. The GitHub API is. To scan all repos in an organization, including both public and private repos, set the type to Private. When type is Public, credentials are not required, although API access to GitHub is capped to a very low value. Currently, Prisma Cloud supports Python, Java, and JavaScript (Node.js). Go to Defend > Vulnerabilities > Code Repositories. 