Data handling

What V12 reads and keeps from your repositories, what a shared report publishes, and how credentials are stored.

V12 reads the repositories you add and keeps their history and findings. This page says what it keeps, what a shared run report makes public, and how it stores your API keys and OAuth tokens.

Repositories

V12 works on the repositories you add to a workspace. See Add a repository to V12.

  • Git history. When you add a repository V12's GitHub App has access to, V12 imports its Git history; its row in Settings → Repositories reads Ready once it has. For a public repository V12 reads without the app, the import runs when a run on it finishes, or when an Admin syncs it.
  • What the history holds. Each commit's message, author name and email, and dates; its file paths, each with a hash of the file's contents; and the line ranges it changed. Also the branches, tags, and pull requests with their titles and authors.
  • Findings. A finding keeps its title and description, plus the commit, file paths and lines it points to. It can also keep a note and a short snippet of code.
  • Code on a finding page. V12 reads the code a finding points to from GitHub when you open the page. If it can't, the page says "Source unavailable for …" and shows any note or snippet the finding kept.
  • Lost access. If V12 can no longer reach a repository, it keeps the repository's runs, findings and history, but you can't start new runs on it. See Archived and disconnected repositories.

Public run reports

Share on a run page creates a link to a report: /share/ followed by a random code. Anyone with the link can read it without signing in. The page asks search engines not to index it, and links out of it do not pass its address on.

The report shows:

  • the title of each Steer the run carried, the run number and when the run finished;
  • each repository's name, the commit reviewed and the number of files in scope;
  • for a change review, the branches or pull request, the head and base commits, and the paths of the changed files;
  • each finding's title, severity, status and repository.

It shows no code, finding descriptions or comments. Stop sharing on the run page turns the link off at once. See Share a run report.

A guest link shows whoever holds it one run's findings: their reports, evidence and whole discussion, with members named by username, never by email. It shows no other runs, repositories or Steers. Its pages ask search engines not to index them, and links out of them do not pass their address on. V12 keeps the name each guest goes by and when they joined and were last active, and shows them to whoever manages the run's links. Revoking a link ends access at once and leaves its guests' comments and changes in your inbox.

Credentials

  • An API key is shown once, when you create it. V12 stores only a SHA-256 hash of the key, plus its first 13 characters, which the Developer page shows as Prefix.
  • The OAuth tokens that authorized apps use are also stored only as hashes.
  • To revoke a key or an app, see Rename or revoke and Authorized apps.

On this page