Repository Health - Checkmarx

FOR DEVELOPERS | Get a 1-month free trial of Developer Assist

Get Started

Checkmarx One

Repository Health

Improve your security posture with full visibility into the security, dependency management, and maintenance health of the code repositories used in your applications.

Repository Health Image - Checkmarx

Reduce Risk by Monitoring the Health of Your Code Repositories

Without repo health monitoring, repositories are at risk of unauthorized code changes, dangerous or low-quality code, regulatory non-compliance, and other security threats.

Continuous Repo Health Tracking

continuous_repo_health_scoring

Monitor the health of all repositories included in your applications based on factors such as security practices, testing practices, dependency management, CI/CD practices, and project maintenance.

Automatic SCM-Triggered Scans

automatic_scm_triggered_scans

Integration with SCM platforms enables scans to run automatically upon repository updates, ensuring up-to-date repo health assessments with no manual effort. 

Flexible On-Demand Scanning Options

flexible_on_demand_scanning_options

In addition to automatic SCM-triggered scans, developers and security teams can manually run repo health scans at any time via API, CLI, or the Checkmarx One UI.

Unified Risk Reporting

unified_risk_reporting

Repository health evaluations are included in Checkmarx One reports, providing visibility intoand efficient prioritization ofsecurity vulnerabilities, code quality issues, and repository health risks, all in one place. 

  • Continuous Repo Health Tracking

    Monitor the health of all repositories included in your applications based on factors such as security practices, testing practices, dependency management, CI/CD practices, and project maintenance.

  • Automatic SCM-Triggered Scans

    Integration with SCM platforms enables scans to run automatically upon repository updates, ensuring up-to-date repo health assessments with no manual effort. 

  • Flexible On-Demand Scanning Options

    In addition to automatic SCM-triggered scans, developers and security teams can manually run repo health scans at any time via API, CLI, or the Checkmarx One UI.

  • Unified Risk Reporting

    Repository health evaluations are included in Checkmarx One reports, providing visibility intoand efficient prioritization ofsecurity vulnerabilities, code quality issues, and repository health risks, all in one place. 

continuous_repo_health_scoring
automatic_scm_triggered_scans
flexible_on_demand_scanning_options
unified_risk_reporting
Mid Page CTA Background

Secure Your Software With Repository Health Checks

Learn how you can use repository health scoring to improve your application security posture.

What’s in it for you

How Enterprises Benefit From Repository Health Monitoring

Continuously tracking repository health helps minimize the threat exposure of vulnerable code repos, leading to improved security and enhanced transparency with stakeholders.

Security Chain

Maximum Security for the Software Supply Chain

Ongoing comprehensive visibility into the security health of all code repositories closes a critical gap in software supply chain security.

Prioritizing Remediation Efforts 

Holistic and Efficient Risk Prioritization

Identifying and prioritizing high-risk areas in all aspects of the software supply chain allows developers and security teams to focus their efforts on the most critical security issues.

Build Trust

Enhanced Transparency and Communication

Having unified assessments of the security posture of code repositories improves transparency, communication, and collaboration among stakeholders.

What Our Customers Say About Us

See why enterprises trust our approach to AppSec to secure their business-critical applications.

“We view Checkmarx as our trusted partner. They’ve elevated our security posture by consolidating our SAST, SCA, and API Security into a unified platform, Checkmarx One, enabling us to achieve vulnerability remediation, reduce noise, and benefit from strong support.”

“Incorporating Checkmarx’s technology has revolutionized our development culture. It’s more than just technology; it serves as the foundation of our security strategy, ensuring that our applications are secure by design.”

“Checkmarx One definitely checks all my boxes from a security standpoint and has a great interface that’s engaging and easy to use. Some of the solutions we considered were more complicated. With Checkmarx One, it’s easy to get right to the problem with little to no learning curve.”

“The success of our AppSec program can be directly attributed to the tooling, processes and support provided by Checkmarx managed services. Our mission revolves around providing secure and compliant lottery and gaming applications and services to our clients around the globe, and with Checkmarx SAST, SCA and associated components enhanced by their stellar service support, we deliver on this promise with confidence and certainty.”

“After nearly nine years of using Checkmarx’s SAST, CGI’s journey has been one of seamless integration and consistent satisfaction. The last three years have been particularly smooth, reflecting the solution’s reliability and our successful partnership.”

“After reviewing the Checkmarx platform, I’m not sure how Veracode is able to exist while being at a similar price point.”

“By Far The Best AppSec Tooling Decision We Have Made!!”

“We were thrilled to find Checkmarx, which helped us improve the SLA for identifying and remediating risk, reduce risk and the number of vulnerabilities, and eliminate high- and medium-risk issues.”

“Checkmarx made security team and developers life easier.”

FAQ

Why is automated repository health monitoring important?

Modern code repositories store application source code, CI/CD configurations, IaC files and other sensitive data. Software supply chain attacks are rising steeply; poorly managed internal code repos are a weak point in an organization’s software supply chain security posture. Because large enterprises typically maintain thousands of repos, it is impossible to manually track how well each of them is configured, maintained, and secured. An automated solution is needed to continuously determine the security and code-quality health of internal code repos. 

What assessments are made to determine repository health?

Checkmarx’ Repository Health helps you maximize the security posture of your applications by automatically and continuously tracking the security and quality practices applied to your code repositories. Each repo is evaluated on its security policies and best practices, including: 

  • Code review before merge 
  • Branch protection 
  • Pinned dependencies 
  • Dependencies actively maintained 
  • Presence of executable (binary) artifacts 
  • Fuzzing required 
  • Presence of a detailed security policy 
  • CI pipeline tests 
  • Dangerous GitHub Action workflows 
  • Signed releases 
  • Secure packaging 

What is OSSF Scorecard?

OSSF Scorecard is an open-source project created by the Open-Source Security Foundation (OpenSSF) that assesses code repositories for security risks through a series of automated checks. Checkmarx One incorporates the results of OSSF Scorecard evaluations in its reports so that developers and security teams can improve their visibility into security vulnerabilities, code quality issues, repository maintenance standards, and other repository health risks. 

How often should repositories be scanned for health checks?

Frequent scans on a regular basis (weekly or monthly) are recommended to continuously monitor repositories for emerging risks. In addition, it is considered a best practice to re-scan a repository any time it is updated, preferably through SCM integration and automation. 

What actions should be taken if a repository is deemed risky?

A poor repo health evaluation indicates that the repository may have security or operational risks, prompting further investigation and remediation steps. To maximize application security posture, repositories must be protected from the risks of unauthorized code changes, dangerous or low-quality code, regulatory non-compliance, and other security threats. 

Checkmarx One

The Cloud-Native Enterprise Application Security Platform

Everything enterprises need to secure application development from code to cloud on a unified platform.

Explore Checkmarx One Packaging & Pricing

Application Security Posture
Management (ASPM) Consolidated, correlated, prioritized insights to help your team manage risk

  • Developer Assist

  • Remediation Assist

  • SAST

  • DAST

  • API Security

  • AI-Generated Code Analysis

Supply Chain

Agentic Security
  • Triage Assist

  • SCA

  • Malicious Packages

  • Secrets Detection

  • Repository Health

  • AI Supply Chain Governance

  • LLM & Agent Governance

  • Container Security

  • IaC Security

Dev Enablement

  • Codebashing

DevSecOps

  • 75+ Languages

  • 100+ Frameworks

  • 75+ Technologies

  • SDLC Integrations

  • ADLC Integrations

  • IDE Integrations

  • Pipeline Policy Enforcement

Services

  • Premium Support

  • Premium Services

  • Maturity Assessment

Dev Enablement

  • Codebashing

    Codebashing

DevSecOps

  • 75+ Languages

    75+ Languages

  • 100+ Frameworks

    100+ Frameworks

  • 75+ Technologies

    75+ Technologies

  • SDLC Integrations

    SDLC Integrations

  • ADLC Integrations

    ADLC Integrations

  • IDE Integrations

    IDE Integrations

  • Pipeline Policy Enforcement

    Pipeline Policy Enforcement

Unified Dashboard, Reporting & Risk Management

Application Security Posture
Management (ASPM)

Consolidated, correlated, prioritized insights to help your team manage risk

Agentic Security

Code

  • Developer Assist

    Developer Assist

  • Remediation Assist

    Remediation Assist

  • SAST

    SAST

  • DAST

    DAST

  • API Security

    API Security

  • AI-Generated Code Analysis

    AI-Generated Code Analysis

Supply Chain

  • Triage Assist

    Triage Assist

  • SCA

    SCA

  • Malicious Packages

    Malicious Packages

  • Secrets Detection

    Secrets Detection

  • Repository Health

    Repository Health

  • AI Supply Chain Governance

    AI Supply Chain Governance

  • LLM & Agent Governance

    LLM & Agent Governance

Cloud

  • Container Security

    Container Security

  • IaC Security

    IaC Security

Services

  • Premium Support

    Premium Support

  • Premium Services

    Premium Services

  • Maturity Assessment

    Maturity Assessment

See it in action

Discover Checkmarx Repository Health

Learn how automatic repository health tracking strengthens your software supply chain security.

Continuously Score & Improve Repository Health

  • Continuous repo scoring: Track code quality, dependency hygiene, CI/CD practices & maintenance at scale.

  • Always current: Automatic SCM‑triggered scans + on‑demand via API/CLI/UI.

  • Unify risk reporting: See repo‑health insights alongside AppSec findings to prioritize efficiently.

  • Policy guardrails: Use insights to gate merges and reduce blast radius.

Trusted By: