Official website links end with .gov.sg
XCAAll project code hosted on SHIP-HATS 2.0 GitLab are transparently onboarded to XCA.
XCA runs when new code is committed directly to the default branch, or when a Merge Request is completed: Scan changed files in the default branch.
To access XCA findings:
When new code is committed to the default branch: Following the scan’s completion, any identified findings will be accessible on the project’s Security & Compliance > Vulnerability Report page. XCA findings are marked as “XCA” under the Identifier and Tool columns.
Was this article useful?