Projects and repositories

How Nebu organizes repositories, scans, findings, and team access.

Updated

Nebu organizes source code in two levels: Projects contain Repositories.

What is a project?

A project is the top-level workspace for an application, product, service group, or team. It groups:

  • repositories that belong to the same system or ownership boundary;
  • the scans and findings created from those repositories; and
  • the people who can access that work.

Use separate projects when repositories have different owners, access requirements, billing boundaries, or unrelated security goals.

What is a repository?

A repository is one connected or uploaded source code target inside a project. Nebu can receive it through the GitHub App, a public Git URL, or a zip upload.

A repository has its own source connection, tracked revision, preparation status, scan history, and automation defaults. The same project can contain several repositories, such as a web application, API, and worker.

How the hierarchy works

Project
├── Repository
│ └── Scan
│ └── Findings
└── Repository
└── Scan
└── Findings

A single-repository scan targets one repository. A multi-repository scan can target two or more Ready repositories, but every selected repository must belong to the same project.

Repos in a project

Repository status

A repository must have a prepared source snapshot before it can be selected for a scan. If it is still preparing, failed, was cancelled, or has no ready snapshot, wait for preparation to finish or repair the connection first.

Naming guidance

  • Name projects after the system or team, not a single repository.
  • Keep repository names aligned with the connected source so people can recognize them.
  • Avoid putting secrets, customer data, or environment credentials in either name.