Article
Repository audits
Add a code repository, audit it on demand or on a schedule, and read the results of each audit.
A repository audit checks your website or app's source code for problems, such as out-of-date dependencies, known security advisories, insecure configuration and maintainability issues, plus extra checks for the platform you use. You add the repository under Diagnose → Repositories, run an audit whenever you like or on a schedule, and get a score, a list of findings and a picture of the technology in the project.
To audit a whole site, including its servers, domains and live pages, see Audits, targets and health reports.
Before you start
- Audits must be included in your package. See Package and add-ons.
- You need permission to view repositories and audits, and separate permission to add repositories and start audits. See Users, teams, groups and permissions.
- For a private repository, you need a GitHub, GitLab, Bitbucket or Custom Git Repository connection. You can create one while adding the repository. See Connecting a provider.
Adding a repository
- Go to Diagnose → Repositories.
- Under Add repository, choose a Connection to your Git provider. If you don't have one yet, select Add connection to create it in a new window.
- Leave Repository URL empty to use the connection's repository. Each connection covers one repository, and a different repository's URL is refused. For a public repository without a connection, enter its URL instead, such as
https://github.com/organisation/repository. - Optionally, enter the Default branch to audit.
- Select Add repository. You'll see "Repository added."
The repository appears in the list with its connection, Provider, Default branch and Detected version. Select View to open it, or Remove and confirm to remove it.
When you add a repository, Structurell also creates an audit target of the same name, with the repository as one of its parts. You can add servers and domains to that target later. See Audits, targets and health reports.
Choosing checks and scheduling audits
Open the repository with View. The Audit schedule panel decides what every audit of this repository checks, whether you start it yourself or it runs on a schedule, so set it up before your first audit.
- Choose every Check groups option that applies to the project: Adobe Commerce, Magento Open Source, PHP, PHP web, JavaScript, Laravel, WordPress, Next.js or React. At least one is required.
- Optionally, choose the live site's Domain from your subscription's domains, so the audit can include checks against the live site. Domains are added under Account → Domains. See Domains.
- To audit automatically, switch on Enabled, then choose Daily, Weekly or Monthly under Audit schedule (each runs at 22:00), or Advanced to build your own timing.
- Choose the Timezone the schedule follows.
- Select Save. You'll see "Audit schedule saved."
When the schedule is on, the panel shows when the Next audit will run. If a scheduled audit couldn't start, the reason is shown in the panel. Select Cancel to undo changes you haven't saved.
The schedule also appears on Assure → Schedules as Repository schedule, where you can select Run now. Scheduled repository audits send an alert for every finished run. See Assurance reviews and audit schedules.
Running an audit
- Open the repository.
- Select Start audit.
Structurell takes a copy of the repository's code and runs the checks in the background. The audit's page opens straight away and updates live as each step completes. When it finishes, you get an Audit Results notification, and so do your subscription administrators.
Every audit of the repository is listed below the schedule panel, with tiles for Runs, Failed, Avg score and Last run. Diagnose → Audits lists audits from all your repositories and targets. An audit's status is Pending, In Progress, Completed, Failed, Skipped or Blocked.
Reading the results
Select View on an audit to open it. The Audit Run summary shows its status, current Step, Elapsed time, Started At, Finished At and Progress. The results are split into tabs:
- Outcome: the overall Score, findings By Severity and By Status, a Recommendation and the Priority Findings to look at first. If the audit failed, the Failure Reason is shown here.
- Steps: each step with its status, start and finish times, Step Duration and any Message.
- Details: a log of what happened during the audit.
- Findings: every finding with its severity, description and recommendation. Change a finding's status in the Status list, or select View to open it. Passed checks can't be changed.
- Technology: the Platform, Platform Version and Framework Versions detected, and the modules, Plugins and Themes found, with their required and installed versions.
Only a completed audit's score counts towards Avg score. A failed audit isn't a result.
Findings from every audit are gathered under Diagnose → Findings. See Managing findings.
Troubleshooting
- The URL is refused when adding a repository. With a connection chosen, leave Repository URL empty or use that connection's own repository. Without a connection, Structurell can only fetch repositories it can reach publicly, so add a connection for private ones.
- The audit failed. Open it and check the Failure Reason on the Outcome tab and the messages on the Steps tab. A common cause is that the repository couldn't be downloaded. Check the connection on Account → Connections, then select Start audit again. See Troubleshooting connections.
- Checks I expected didn't run. Make sure you've chosen the right Check groups and selected Save before starting the audit.
- Save is greyed out. Nothing has changed since the last save, or no Check groups option is selected.