Skip to main content

Prepare your repository

You give AISafe your source in one of three ways. The agents extract the code into an isolated environment, build a code graph from it, and retain no access to your repository after the audit finishes.

Source options​

Connected repositories — select a repository from GitHub, GitLab, or Bitbucket. Private and public repositories both require an authorized connection in your workspace. Each repository has its own branch and selected paths. You can connect up to five repositories from one provider as a single application; every plan includes five. AISafe pins the commit of every repository before it prepares one combined source tree. The tree has a directory named after each repository, with a number added when two names would collide. See Projects.

For a code audit linked to a Project with a connected repository, choose either a saved Project version or a Remote branch. A remote branch is fetched and pinned to an exact commit for that audit. Choosing the Project's tracked repository branch updates its tracked version and lets the audit update Project knowledge. Any other branch can use existing Project knowledge but cannot change it. Remote-branch selection is not shown for archive or public-URL Projects because they have no connected installation that can authorize the branch list.

Public repository URL — enter a public https://github.com/{owner}/{repo} URL. AISafe clones the default branch (or a specific commit or branch if you provide one). This is the quickest way to audit an open-source project.

Connected and public repositories use the same default file exclusions. The scope picker shows what it excluded and lets you include individual files or choose Include excluded. The size counter for each tree counts its checked files; All repositories shows the combined size when you select several repositories. Connected and public repositories both measure file sizes before compression and share the same source limit.

Uploaded archive — upload a ZIP or tar.gz of your codebase. Use this for code that is not in a supported git host, or for a specific snapshot you have not pushed to a remote. Include the full project tree so the agents can resolve cross-file dependencies. ZIP entries compressed with LZMA or BZIP2 are refused; repack those as a standard ZIP (store/deflate) or tar.gz before uploading.

The code graph resolves dependencies, so you do not need to install packages or run a build before uploading.

Before you start​

  • Connect the integration once, if you plan to audit private repositories. See Integrations and Integrations.
  • Decide the revision. Pick the branch, ref, or a specific commit to audit.
  • Add instructions, if useful, to steer the agents. See Steer the audit.
  • Check credit balance. Each audit consumes credits based on size and duration; you see the final price before starting.

AISafe shows the final price only after the offline source scan has finished and its saved result has passed integrity checks. The source picker does not show a provisional price based on bytes. If the parser reaches a recoverable limit, AISafe may list it with a valid partial result, provided that the saved counters account for every unreadable or quarantined file. Those files reduce the reported coverage, but AISafe keeps the code it could analyse. If the scan has a corrupt artifact, an unexplained partial result, a hard resource limit, or internally inconsistent results, AISafe shows no price and you cannot start the audit; fix the reported source problem or retry validation.

What one audit covers​

Connected repositoriesUp to 5, from the same provider
Source archiveUp to 300 MB compressed
Extracted sourceUp to 300 MB across all repositories, and up to 100 MB in any one file
FilesUp to 100,000
CodeUp to 1,000,000 lines

If your source is larger than that, scope the audit to the part of the repository you want read (most codebases have such a part), or talk to us and we will size a run for the whole codebase.

These limits apply to the combined source. Adding a repository does not increase the allowance. A public URL or upload remains a single source option.

Two details apply to individual files. A single file over 2 MB is listed in the inventory but not parsed, because such files are almost always bundles, lockfiles, or vendored blobs. Anything AISafe skips is reported in the audit's coverage, so nothing is left out without notice.

What an archive may contain​

An upload may be a zip, a gzip tar, a bzip2 tar, an xz tar, or a 7z, and it may contain archives of its own up to three levels deep. AISafe applies three rules to the archive's structure. If an upload breaks one of them, AISafe refuses the upload instead of silently changing it:

  • No two files may claim the same path. A zip file can legally contain the same name twice. We do not choose one of the two files for you, because the file we dropped might be the one you wanted audited.
  • No archive may expand to more than a hundred times what you uploaded. Real source code compresses by a factor of four to eight. A ratio far above that means the archive holds a file of repeated bytes rather than code, and the audit would spend its time reading that file.
  • AISafe never truncates an upload. If an upload crosses a limit, AISafe refuses it while reading it, and the message names the file. You never get a scan of part of your repository that looks like a scan of all of it.

Dependency inventory​

AISafe reads manifests and lockfiles locally to build dependency, licence, and SBOM facts. The pricing scan does not call OSV, package registries, or any provider. For that reason, an exact version in the inventory does not mean that the package is free of advisories; the audit still needs evidence to show that a vulnerability applies.