XCA
OverviewFeatures & RoadmapHow It WorksGetting StartedResourcesFAQsMeet the Team
Home ProductsCybersecurityXCAFAQs

FAQs

Is XCA meant to replace my primary code-scanning solution?

No, XCA augments existing code scanning solutions, including custom rules based on past vulnerabilities that may not be available in generic default rulesets. As such, it targets specific, known vulnerable code patterns with a high true positive rate instead of general code hygiene or potential vulnerabilities.

Why does XCA use Semgrep instead of any other code-scanning engine?

The Semgrep OSS Engine is already integrated into GitLab SAST and does not require additional modifications.

Where are the vulnerabilities logged?

Vulnerabilities discovered from XCA are stored in the GitLab project as a Vulnerability Report.

Last updated 07 Mar 2025