Data handling
What V12 reads and keeps from your repositories, what a shared report publishes, and how credentials are stored.
V12 reads the repositories you add and keeps their history and findings. This page says what it keeps, what a shared run report makes public, and how it stores your API keys and OAuth tokens.
Repositories
V12 works on the repositories you add to a workspace. See Add a repository to V12.
- Git history. When you add a repository, V12 imports its Git history ("V12 is preparing its Git history"). For a public repository you add by name under Public repositories, the import runs when you sync it or when a run on it finishes.
- What the history holds. Each commit's message, author name and email, and dates; its file paths, each with a hash of the file's contents; and the line ranges it changed. Also the branches, tags, and pull requests with their titles and authors.
- Findings. A finding keeps its title and description, plus the commit, file paths and lines it points to. It can also keep a note and a short snippet of code.
- Code on a finding page. V12 reads the code a finding points to from GitHub when you open the page. If it can't, the page says "Source unavailable for …" and shows any note or snippet the finding kept.
- Lost access. If V12 can no longer reach a repository, it keeps the repository's runs, findings and history, but you can't start new runs on it. See Archived and disconnected repositories.
Public run reports
Share on a run page publishes a report at /share/<run number>. Anyone with the link can read it without signing in. The page asks search engines not to index it.
The report shows:
- the title of each focus the run carried, the run number and when the run finished;
- each repository's name, the commit reviewed and the number of files in scope;
- for a change review, the branches or pull request, the head and base commits, and the paths of the changed files;
- each finding's title, severity, status and repository.
It shows no code, finding descriptions or comments. The app has no control to stop sharing a report once it is published. See Share a run report.
Credentials
- An API key is shown once, when you create it. V12 stores only a SHA-256 hash of the key, plus its first 13 characters, which the Developer page shows as Prefix.
- The OAuth tokens that authorized apps use are also stored only as hashes.
- To revoke a key or an app, see Rename or revoke and Authorized apps.