What happens after I connect a repository?

Last updated: June 25, 2026

Use this article when you have connected a repository or VCS provider and want to know what Cysmiq does next.

What to check first

  • Open Assets to confirm the organization or repository appears.
  • Open Scans to watch scan rows move through their lifecycle status.
  • Use the repository, ref, pull request, SHA, or scan ID to find the scan you care about.

What Cysmiq does after connection

  • Syncs repository metadata: Cysmiq discovers connected organizations and repositories.
  • Starts initial scanning: newly onboarded repositories receive full scans.
  • Tracks future changes: branch and tag push events can trigger additional scans.
  • Publishes VCS feedback: when enabled, Cysmiq can publish status checks or pull request decoration for linked pull requests.

What appears in the Scans view

  • Scan: commit message, pull request title, ref name, short SHA, and pull request number when available.
  • Status: where the scan is in the lifecycle, such as queued, in progress, completed, or failed.
  • Result: the pull request, provider check, or scan outcome when Cysmiq has that data.
  • Vulnerability badges: fixed, actionable, inferred active, and policy violation counts when available.

Canonical docs

For the maintained reference, see Scans and Scan list view.

Contact support if

  • The repository does not appear after the VCS connection succeeds.
  • No scans are queued or running after repository onboarding.
  • The scan result in Cysmiq does not match what your VCS provider shows.