---
title: "Code Analysis (White Box)"
description: "TurboPentest's white-box static analysis tools - Code Scanner, Dep Scanner, and Secret Scanner - that run against your source code once a GitHub repo is connected."
canonical: https://turbopentest.com/docs/tools/code-analysis
source: "TurboPentest Docs"
---

# Code Analysis (White Box)

These tools require a [GitHub connection](/docs/integrations/github) to access your source code. They run in addition to all black box tools.

## 📝 Code Scanner (SAST)

Static Application Security Testing - finds vulnerabilities in your source code. Code Scanner is a license-clean SAST engine, run with **IntegSec's own rule pack** (CWE Top 25 / OWASP Code Review Guide) rather than a public rule registry - so every check is one our operators wrote, reviewed, and own.

**What it finds:**
- Injection vulnerabilities (SQL, command, XSS)
- Insecure cryptography usage
- Hardcoded secrets
- Authentication bypass patterns
- Framework-specific anti-patterns (React, Django, Express, etc.)

**Languages supported:** Python, JavaScript/TypeScript, Java, Go, Ruby, PHP, C#, and more.

**Rules:** IntegSec's owned rule pack, aligned to CWE Top 25 and the OWASP Code Review Guide, bundled at `/rules`.

---

## 📦 Dep Scanner (SCA)

Software Composition Analysis - checks your dependency files for known vulnerabilities.

**What it finds:**
- Vulnerable npm/pip/Maven/Go dependencies
- Outdated packages with known CVEs (only vulnerabilities with available fixes are reported)
- Transitive dependency vulnerabilities

**Files checked:** `package-lock.json`, `requirements.txt`, `go.sum`, `pom.xml`, `Gemfile.lock`, etc.

---

## 🔑 Secret Scanner (Secret Detection)

Checks your repository's source tree for accidentally committed secrets.

**What it finds:**
- API keys (AWS, GCP, Azure, Stripe, etc.)
- Database connection strings
- OAuth tokens
- Private keys
- Passwords in configuration files

---

## Enabling white box analysis

1. Go to **Dashboard > Account > GitHub**
2. Connect via OAuth or install the TurboPentest GitHub App
3. Grant access to the repositories you want to test
4. When starting a pentest, provide the `repoUrl` parameter

The GitHub App is recommended as it provides fine-grained repository access without exposing your personal token.
