Skip to main content

Overview

ZeroPath CLI provides command-line access to ZeroPath’s AI-powered security scanning platform. Upload and scan your code directly from your terminal with support for multiple output formats and CI/CD integration.

Get the CLI

Download the latest release from our GitHub repository

What ZeroPath CLI Detects

The CLI scans for a comprehensive range of security vulnerabilities:
  • Authentication and authorization vulnerabilities
  • Application logic flaws
  • Dependency issues
  • Security misconfigurations
  • Command injection vulnerabilities
  • File inclusion and path traversal attacks
  • Secrets and hardcoded credentials

Quick Start

Core Commands

Authentication

Local Directory Scanning

Repository Scanning

On-Demand Code Scans Beta

Use scan-code to submit a diff, file, file set, or snippet for asynchronous security review without starting a full repository scan.
By default, scan-code uses your Git remote URL to automatically use linked repository context when exactly one accessible ZeroPath repository matches. If there is no match, it runs as a standalone scan.
On-Demand Code Scans are currently in beta. Behavior, limits, and response fields may change before general availability.
See On-Demand Code Scans Beta for request formats, target modes, limits, and API examples.

Container Scanning

Use the container commands to scan built container images for OS-package and bundled-dependency vulnerabilities. Images can be pulled by registry reference — including from private registries with credentials — or uploaded as a local docker save archive. Findings are surfaced under the Supply Chain section with per-layer attribution and base-image upgrade recommendations.
To scan an image in a private registry, pass registry credentials. ZeroPath authenticates with them when pulling the image; tokens are transmitted over TLS and stored encrypted.
For air-gapped images that cannot be pulled, export the image to a tarball with docker save and scan that archive directly with --file. Give it a label with --name so it is identifiable in results.
Uploaded archives are scanned once and cannot be monitored: there is no registry reference to re-pull on a schedule, so container monitor rejects --file. Use a registry image reference for recurring re-scans.
By default, container test waits for the scan to finish and prints a human-readable report. The following flags control that behavior:
  • --json — print the raw response payload as JSON instead of the formatted report.
  • --wait / --no-wait — wait for the scan to complete (the default). Pass --no-wait to submit the scan and return immediately with the container image ID.
  • --timeout <seconds> — maximum seconds to wait for completion before exiting with an error. Must be a positive number.
To keep watching an image after it ships, register it for recurring re-scans. Monitoring surfaces newly disclosed CVEs against an already-built image without a manual re-run. container monitor also accepts --json to print the raw response payload.

Repository Linking

Container images can be linked to an onboarded repository so findings appear alongside that repository’s code-scan results. By default, container commands auto-detect the repository from the current checkout’s git remote. You can control this with:
  • --repository-id <id> — explicitly link the image to a specific repository, overriding auto-detection.
  • --no-auto-repository — disable auto-detection entirely; the image will not be linked to any repository unless --repository-id is also provided.
Auto-linking works for container test, container monitor, and container link.

Linking an Existing Image

Use container link to link (or re-link) a previously scanned container image to a repository. This is useful when the image was scanned without a repository context, or when you need to move it to a different repository.
See Container Scanning for the end-to-end flow, per-layer findings, private-registry and local-archive scanning, and base-image upgrade recommendations.

CI/CD Integration

The CLI is designed for seamless CI/CD integration — it exits with code 1 when security issues are found or when an error occurs during scanning:

Scan Timeout

Local directory scans have a maximum polling timeout of approximately 50 minutes. If the scan does not complete within this window, the CLI exits with an error. This prevents CI/CD pipelines from hanging indefinitely on long-running scans.

Output Formats

ZeroPath CLI supports multiple output formats for different use cases:
  • SARIF: Standard format for static analysis results (local scans)
  • Console: Human-readable formatted output for terminal viewing

Getting API Credentials

To use the CLI, you’ll need API credentials from your ZeroPath account:
  1. Sign in to ZeroPath Dashboard
  2. Navigate to API Settings
  3. Generate new API credentials (Client ID and Client Secret)
  4. Use these credentials with zeropath auth
CLI requests are automatically identified as originating from the CLI in your organization’s audit logs, so you can distinguish CLI-triggered actions from browser and other API-token activity without any additional configuration.

Next Steps