FAQs | Singapore Government Developer Portal
Features & Roadmap
How It Works
Getting Started
Meet The Team


Is XCA meant to replace my primary code-scanning solution?

No, XCA augments existing code scanning solutions, including custom rules based on past vulnerabilities that may not be available in generic default rulesets. As such, it targets specific, known vulnerable code patterns with a high true positive rate instead of general code hygiene or potential vulnerabilities.

Why does XCA use Semgrep instead of any other code-scanning engine?

The Semgrep OSS Engine is already integrated into GitLab SAST and does not require additional modifications.

Where are the vulnerabilities logged?

Vulnerabilities discovered from XCA are stored in the GitLab project as a Vulnerability Report.

Was this article useful?


A Set of Custom Rules That Detect Repeated Vulnerabilities in Code