Agentless code scanning – GitHub support and customizable coverage now available (Preview)
What's new in Defender for Cloud features
June 2025
Agentless code scanning – GitHub support and customizable coverage now available (Preview)
June 18, 2025
We have updated the agentless code scanning feature to include key capabilities that extend both coverage and control. These updates include:
- Support for GitHub repositories, in addition to Azure DevOps
- Customizable scanner selection – select which tools (e.g., Bandit, Checkov, ESLint) to run
- Granular scope configuration – include or exclude specific organizations, projects, or repositories
Agentless code scanning provides scalable security scanning for code and infrastructure-as-code (IaC) without requiring changes to CI/CD pipelines. It helps security teams detect vulnerabilities and misconfigurations without interrupting developer workflows.