Data handling

What V12 reads and keeps from your repositories, what a shared report publishes, and how credentials are stored.

V12 reads the repositories you add and keeps their history and findings. This page says what it keeps, what a shared run report makes public, and how it stores your API keys and OAuth tokens.

Repositories

V12 works on the repositories you add to a workspace. See Add a repository to V12.

  • Git history. When you add a repository, V12 imports its Git history ("V12 is preparing its Git history"). For a public repository you add by name under Public repositories, the import runs when you sync it or when a run on it finishes.
  • What the history holds. Each commit's message, author name and email, and dates; its file paths, each with a hash of the file's contents; and the line ranges it changed. Also the branches, tags, and pull requests with their titles and authors.
  • Findings. A finding keeps its title and description, plus the commit, file paths and lines it points to. It can also keep a note and a short snippet of code.
  • Code on a finding page. V12 reads the code a finding points to from GitHub when you open the page. If it can't, the page says "Source unavailable for …" and shows any note or snippet the finding kept.
  • Lost access. If V12 can no longer reach a repository, it keeps the repository's runs, findings and history, but you can't start new runs on it. See Archived and disconnected repositories.

Public run reports

Share on a run page publishes a report at /share/<run number>. Anyone with the link can read it without signing in. The page asks search engines not to index it.

The report shows:

  • the title of each focus the run carried, the run number and when the run finished;
  • each repository's name, the commit reviewed and the number of files in scope;
  • for a change review, the branches or pull request, the head and base commits, and the paths of the changed files;
  • each finding's title, severity, status and repository.

It shows no code, finding descriptions or comments. The app has no control to stop sharing a report once it is published. See Share a run report.

Credentials

  • An API key is shown once, when you create it. V12 stores only a SHA-256 hash of the key, plus its first 13 characters, which the Developer page shows as Prefix.
  • The OAuth tokens that authorized apps use are also stored only as hashes.
  • To revoke a key or an app, see Rename or revoke and Authorized apps.

On this page