Frequently asked questions (FAQ)
We have gathered the questions you commonly run into while using Vulinder. Each answer includes a link to a document with more detail, so follow whatever item you need.
What targets can I analyze?
You can analyze source code (Git), container images, running web services, servers (hosts), and uploaded SBOMs. Each type has different requirements and different analyses you can enable. For registration methods, see Source code, Container image, Web service, Server / host, and SBOM upload. If you are new, we recommend starting with the Quick Start.
How long does a scan take?
It depends on the size of the target. Scans run asynchronously, so you do not need to keep the screen open, and progress is shown in real time. When a scan finishes, a result summary and deep link are delivered to your configured notification channel.
There are too many false positives.
Suppress items that are not a real risk as false positives. The same item is identified by fingerprint and will not reappear from the next scan on, so your list gradually gets tidier. Items you have decided not to fix now can be tracked separately by marking them as accepted risk. (Triage)
Can I scan any website with DAST?
No. To prevent abuse and SSRF, you can only scan domains whose ownership has been verified. Domain ownership is verified during registration using a verification file or a meta tag. (Web service (DAST))
I received a new vulnerability alert even though I did not run a scan.
That is normal behavior. Because SBOM inventory and dependency (SCA) information are monitored continuously, when a new CVE is published for a component you have already registered, it is detected and reported without a rescan. You can see whether you are affected and which assets are involved. (Security news)
How do I share results externally?
You can export a summary as a PDF report, or export a VEX document that captures the response status of vulnerabilities. You can use these directly for audits and customer responses. (Reports · VEX)
I cannot see a certain feature.
Depending on your plan or contract, some features (DAST, server monitoring, VPN, and so on) may not be provided, in which case the menu is locked or hidden. Check your current plan in Billing · Plans, and refer to Plans and feature coverage for what is provided.
I have another question.
If you did not find your answer here, reach out via Contact. If the terminology is unfamiliar, the Glossary helps, and if you have questions about status labels, the Status dictionary helps too.