# Endor Labs Documentation: Documentation

> Endor Labs documentation - secure your software supply chain

## Documentation

### Introduction

- [About Endor Labs](https://docs.endorlabs.com/index.md)
- [Getting started](https://docs.endorlabs.com/introduction/getting-started/index.md): Set up and configure Endor Labs to run your first project scan.
- [Endor Labs user interface](https://docs.endorlabs.com/introduction/endor-labs-ui/index.md): Understand Endor Labs user interface and how to navigate through it.
- [Endor Labs licenses](https://docs.endorlabs.com/introduction/licenses/index.md): Licensing model, SKUs, and per-seat entitlements for the Endor Labs platform.

#### Doc Tools

- [Documentation tools](https://docs.endorlabs.com/introduction/doc-tools/index.md): Interactive builders, generators, and wizards across the Endor Labs docs, plus machine-readable surfaces that connect the documentation to your AI tools.
- [Documentation MCP server](https://docs.endorlabs.com/introduction/doc-tools/docs-mcp-server/index.md): Connect the Endor Labs documentation MCP server to your AI tools for accurate, up-to-date answers about Endor Labs.

### Setup & Deployment

- [Setup & Deployment](https://docs.endorlabs.com/setup-deployment/index.md): Learn multiple methods to deploy the Endor Labs application across your repositories and pipelines.

#### SCM Integrations

- [SCM Integrations](https://docs.endorlabs.com/setup-deployment/scm-integrations/index.md): Connect your source code management platforms for continuous monitoring and scanning. Includes an interactive setup wizard.
- [Set up Jenkins pipeline for supervisory scans](https://docs.endorlabs.com/setup-deployment/scm-integrations/jenkins-supervisory-scan/index.md): Learn how to use Endor Labs Jenkins pipeline to conduct organization wide supervisory scans.

##### GitHub Cloud App Pro

- [Deploy Endor Labs GitHub Cloud App Pro](https://docs.endorlabs.com/setup-deployment/scm-integrations/github-app/index.md): Learn how to continuously monitor your environment with the Endor Labs GitHub Cloud App Pro.
- [Manage GitHub Cloud App Pro on Endor Labs](https://docs.endorlabs.com/setup-deployment/scm-integrations/github-app/manage-github-app/index.md): Learn how to manage your GitHub App integration in Endor Labs.
- [Scan capabilities of the Endor Labs GitHub Apps](https://docs.endorlabs.com/setup-deployment/scm-integrations/github-app/scan-with-githubapp/index.md): Learn how to scan projects using the Endor Labs GitHub App.
- [Rescan projects](https://docs.endorlabs.com/setup-deployment/scm-integrations/github-app/re-scan-projects/index.md): Rescan your GitHub projects with Endor Labs
- [Technical limitations of the Endor Labs GitHub App](https://docs.endorlabs.com/setup-deployment/scm-integrations/github-app/technical-limitations/index.md): Understand the technical limitations associated with the GitHub App.
- [Migrate to GitHub Cloud App Pro](https://docs.endorlabs.com/setup-deployment/scm-integrations/github-app/migrate-to-github-app-pro/index.md): Learn how to migrate from the standard GitHub App to GitHub Cloud App Pro.

###### GitHub Enterprise Server App

- [Deploy Endor Labs GitHub Enterprise Server App](https://docs.endorlabs.com/setup-deployment/scm-integrations/github-app/github-enterprise-app/index.md): Learn how to continuously monitor your GitHub Enterprise Server environment with the Endor Labs GitHub Enterprise Server App.
- [Manage GitHub Enterprise Server App on Endor Labs](https://docs.endorlabs.com/setup-deployment/scm-integrations/github-app/github-enterprise-app/manage-githubapp-enterprise/index.md): Learn how to manage your GitHub App Enterprise integration in Endor Labs.

##### Azure DevOps App

- [Deploy Endor Labs Azure DevOps App](https://docs.endorlabs.com/setup-deployment/scm-integrations/azure-app/index.md): Get up and running with Endor Labs Azure DevOps App.
- [Azure DevOps App PR scans](https://docs.endorlabs.com/setup-deployment/scm-integrations/azure-app/azure-pr-scans/index.md): <Badge color="green">Beta</Badge> <br /> Learn how to enable PR scans using the Azure DevOps App.
- [Manage Azure DevOps App on Endor Labs](https://docs.endorlabs.com/setup-deployment/scm-integrations/azure-app/manage-azure-app/index.md): Learn how to manage your Azure DevOps App integration in Endor Labs.

##### GitLab App

- [Deploy Endor Labs GitLab App](https://docs.endorlabs.com/setup-deployment/scm-integrations/gitlab-app/index.md): Learn how to continuously monitor your environment with the Endor Labs GitLab App.
- [GitLab App MR scans](https://docs.endorlabs.com/setup-deployment/scm-integrations/gitlab-app/gitlab-mr-scan/index.md): Learn how to enable MR scans using the GitLab App.
- [Manage GitLab App on Endor Labs](https://docs.endorlabs.com/setup-deployment/scm-integrations/gitlab-app/manage-gitlab-app/index.md): Learn how to manage your GitLab App integration in Endor Labs.

##### Bitbucket Data Center App

- [Deploy Endor Labs Bitbucket App in Bitbucket Data Center](https://docs.endorlabs.com/setup-deployment/scm-integrations/bitbucket-datacenter-app/index.md): Learn how to continuously monitor your environment with the Endor Labs Bitbucket App.
- [Bitbucket Data Center App PR scans](https://docs.endorlabs.com/setup-deployment/scm-integrations/bitbucket-datacenter-app/bitbucket-datacenter-pr-scans/index.md): Learn how to enable PR scans using the Bitbucket Data Center App.
- [Manage Bitbucket Data Center App on Endor Labs](https://docs.endorlabs.com/setup-deployment/scm-integrations/bitbucket-datacenter-app/manage-bitbucket-datacenter-app/index.md): Learn how to manage your Bitbucket App integration in Endor Labs.

##### Bitbucket Cloud App

- [Deploy Endor Labs Bitbucket App in Bitbucket Cloud](https://docs.endorlabs.com/setup-deployment/scm-integrations/bitbucket-cloud/index.md): Learn how to continuously monitor your environment with the Endor Labs Bitbucket App.
- [Bitbucket Cloud App PR scans](https://docs.endorlabs.com/setup-deployment/scm-integrations/bitbucket-cloud/bitbucket-cloud-pr-scans/index.md): Learn how to enable PR scans using the Bitbucket Cloud App.
- [Manage Bitbucket Cloud App on Endor Labs](https://docs.endorlabs.com/setup-deployment/scm-integrations/bitbucket-cloud/manage-bitbucket-cloud/index.md): Learn how to manage your Bitbucket App integration in Endor Labs.

#### Endor Outpost

- [Endor Outpost](https://docs.endorlabs.com/setup-deployment/outpost/index.md): Deploy on-premises scanning within your Kubernetes cluster for air-gapped environments.
- [Outpost requirements](https://docs.endorlabs.com/setup-deployment/outpost/outpost-requirements/index.md): Learn about the requirements for Outpost.
- [Outpost authentication](https://docs.endorlabs.com/setup-deployment/outpost/outpost-authentication/index.md): Learn how to authenticate Outpost.
- [Outpost configuration](https://docs.endorlabs.com/setup-deployment/outpost/outpost-configuration/index.md): Learn about the configuration for Outpost.

#### MCP Server

- [MCP Server](https://docs.endorlabs.com/setup-deployment/mcp/index.md): Deploy and run the Endor Labs MCP server in your AI-powered coding workflows.
- [Endor Labs MCP server in Cursor](https://docs.endorlabs.com/setup-deployment/mcp/cursor/index.md): Learn how to deploy and run the Endor Labs MCP server in Cursor.
- [Endor Labs MCP server in Claude Code](https://docs.endorlabs.com/setup-deployment/mcp/claude-code/index.md): Learn how to deploy and run the Endor Labs MCP server in Claude Code.
- [Endor Labs MCP server in OpenAI Codex](https://docs.endorlabs.com/setup-deployment/mcp/codex/index.md): Learn how to deploy and run the Endor Labs MCP server in OpenAI Codex.
- [Endor Labs MCP server in Visual Studio Code](https://docs.endorlabs.com/setup-deployment/mcp/vscode/index.md): Learn how to deploy and run the Endor Labs MCP server in Visual Studio Code.
- [Endor Labs MCP server in Devin](https://docs.endorlabs.com/setup-deployment/mcp/devin/index.md): Learn how to deploy and run the Endor Labs MCP server in Devin.
- [Endor Labs MCP server in Gemini CLI](https://docs.endorlabs.com/setup-deployment/mcp/gemini/index.md): Learn how to deploy and run the Endor Labs MCP server in Gemini CLI.
- [Endor Labs MCP server in Augment Code](https://docs.endorlabs.com/setup-deployment/mcp/augment-code/index.md): Learn how to deploy and run the Endor Labs MCP server in Augment Code.
- [Endor Labs MCP server in IntelliJ IDEA](https://docs.endorlabs.com/setup-deployment/mcp/intellij/index.md): Learn how to deploy and run the Endor Labs MCP server in IntelliJ IDEA with GitHub Copilot.
- [Endor Labs MCP server in Google Antigravity](https://docs.endorlabs.com/setup-deployment/mcp/antigravity/index.md): Learn how to deploy and run the Endor Labs MCP server in Google Antigravity.
- [Endor Labs GitHub AgentHQ](https://docs.endorlabs.com/setup-deployment/mcp/github-agenthq/index.md): <Badge color="green">Beta</Badge> <br /> Check dependency vulnerabilities and open source package risk in GitHub Copilot, with no API key required.
- [Endor Labs MCP server in OpenCode](https://docs.endorlabs.com/setup-deployment/mcp/opencode/index.md): Learn how to deploy and run the Endor Labs MCP server in OpenCode.

#### endorctl CLI

- [endorctl CLI](https://docs.endorlabs.com/setup-deployment/cli/index.md): Install, configure, and authenticate with the Endor Labs command-line interface.
- [Scan using endorctl](https://docs.endorlabs.com/setup-deployment/cli/scan-using-endorctl/index.md): Scan for open source risk, SAST findings, leaked secrets, and GitHub misconfigurations using endorctl.

#### CI/CD Integration

- [CI/CD Integration](https://docs.endorlabs.com/setup-deployment/ci-cd/index.md): Integrate Endor Labs scanning into your CI/CD pipelines.
- [Scanning with GitHub Actions](https://docs.endorlabs.com/setup-deployment/ci-cd/scan-with-github-actions/index.md): Learn how to implement Endor Labs in GitHub action workflows.
- [Scanning with Jenkins](https://docs.endorlabs.com/setup-deployment/ci-cd/scan-with-jenkins/index.md): Learn how to implement Endor Labs in a Jenkins pipeline.
- [Scanning in GitLab Pipelines](https://docs.endorlabs.com/setup-deployment/ci-cd/scan-with-gitlab/index.md): Learn how to implement Endor Labs across a GitLab CI pipeline.
- [Scanning in Azure Pipelines](https://docs.endorlabs.com/setup-deployment/ci-cd/scan-with-azuredevops/index.md): Learn how to implement Endor Labs in an Azure Pipeline.
- [Scanning in Bitbucket Pipelines](https://docs.endorlabs.com/setup-deployment/ci-cd/scan-with-bitbucket/index.md): Learn how to implement Endor Labs in a Bitbucket pipeline.
- [Scanning with CircleCI](https://docs.endorlabs.com/setup-deployment/ci-cd/scan-with-circleci/index.md): Learn how to implement Endor Labs in a CircleCI pipeline.
- [Scanning with Google Cloud Build](https://docs.endorlabs.com/setup-deployment/ci-cd/scan-with-google-cloud-build/index.md): Learn how to implement Endor Labs with Google Cloud Build.
- [Scanning with Buildkite](https://docs.endorlabs.com/setup-deployment/ci-cd/scan-with-buildkite/index.md): Learn how to implement Endor Labs in Buildkite pipelines.

##### Set up keyless authentication

- [Set up keyless authentication](https://docs.endorlabs.com/setup-deployment/ci-cd/keyless-authentication/index.md): Learn how to implement keyless authentication for CI environments.
- [Keyless authentication in AWS](https://docs.endorlabs.com/setup-deployment/ci-cd/keyless-authentication/aws-keyless-auth/index.md): Learn how to implement keyless authentication for AWS.
- [Keyless authentication for Azure](https://docs.endorlabs.com/setup-deployment/ci-cd/keyless-authentication/azure-keyless-auth/index.md): Learn how to implement keyless authentication for Azure.
- [Keyless authentication in GitHub](https://docs.endorlabs.com/setup-deployment/ci-cd/keyless-authentication/github-keyless-auth/index.md): Learn how to implement keyless authentication in GitHub.
- [Keyless authentication in Google Cloud](https://docs.endorlabs.com/setup-deployment/ci-cd/keyless-authentication/google-keyless-auth/index.md): Learn how to implement keyless authentication in Google Cloud.

### Inventory & Insights

- [Inventory & Insights](https://docs.endorlabs.com/inventory-insights/index.md): View and analyze your projects, findings, packages, dependencies, and security posture.
- [Packages](https://docs.endorlabs.com/inventory-insights/packages/index.md): Browse the buildable units Endor Labs discovers in your projects, and review their resolution and reachability status.
- [Licenses](https://docs.endorlabs.com/inventory-insights/licenses/index.md): View and manage license information across projects for legal and compliance review.
- [Reports](https://docs.endorlabs.com/inventory-insights/reports/index.md): Learn how to create analytics and findings reports for your organization.
- [Scan history](https://docs.endorlabs.com/inventory-insights/scan-history/index.md): View the history of scans performed on a project.
- [PR runs](https://docs.endorlabs.com/inventory-insights/pr-runs/index.md): View the history of PR scans performed on a project.
- [Notifications](https://docs.endorlabs.com/inventory-insights/notifications/index.md): Learn how to view, search, and manage policy notifications in Endor Labs.
- [Namespaces](https://docs.endorlabs.com/inventory-insights/namespaces/index.md): Organize your tenant into logical partitions based on organizational units, business units, or teams.

#### Projects

- [Projects](https://docs.endorlabs.com/inventory-insights/projects/index.md): View and manage your source code repositories scanned by Endor Labs.
- [Working with project filters](https://docs.endorlabs.com/inventory-insights/projects/project-filters/index.md): Learn how to implement and use project filters to search, prioritize, and manage projects across your organization. Includes an interactive filter builder.

#### Findings

- [Findings](https://docs.endorlabs.com/inventory-insights/findings/index.md): View, filter, and manage security findings across your projects and packages.
- [Working with finding filters](https://docs.endorlabs.com/inventory-insights/findings/finding-filters/index.md): Learn how to implement and use finding filters to search, prioritize, and manage security findings across your organization. Includes an interactive filter builder.
- [Dismiss findings](https://docs.endorlabs.com/inventory-insights/findings/dismiss-findings/index.md): Exclude findings from your active workflow using exception policies, ignore files, or snooze.
- [Manage findings](https://docs.endorlabs.com/inventory-insights/findings/manage-findings/index.md): Configure finding and action policies, export findings to CSV, and organize findings with tags.

#### Dashboards

- [Dashboards](https://docs.endorlabs.com/inventory-insights/dashboards/index.md): View analytics, security posture, and vulnerability insights.
- [OSS overview](https://docs.endorlabs.com/inventory-insights/dashboards/oss-overview/index.md): Visualize complete software security posture of your organization.
- [Endor Patches](https://docs.endorlabs.com/inventory-insights/dashboards/endor-patches/index.md): Explore the benefits of Endor Patches on the dependencies identified within your organization.
- [First-party code](https://docs.endorlabs.com/inventory-insights/dashboards/first-party-code/index.md): Visualize the first-party code vulnerabilities in your organization.
- [Analytics](https://docs.endorlabs.com/inventory-insights/dashboards/analytics/index.md): Visualize metrics on volume and efficiency of issue resolution.
- [AI security code review](https://docs.endorlabs.com/inventory-insights/dashboards/ai-security-review/index.md): Visualize the AI security review results in your organization.
- [OSS Coverage](https://docs.endorlabs.com/inventory-insights/dashboards/oss-coverage/index.md): <Badge color="green">Beta</Badge> <br /> Visualize dependency resolution and reachability analysis coverage across your organization.

#### Dependencies

- [Dependencies](https://docs.endorlabs.com/inventory-insights/dependencies/index.md): Explore the third-party packages your projects consume, with reachability, Endor Scores, and risk context.
- [Working with dependency filters](https://docs.endorlabs.com/inventory-insights/dependencies/dependency-filters/index.md): Learn how to implement and use dependency filters to search, prioritize, and manage dependencies across your organization. Includes an interactive filter builder.

#### SBOM

- [SBOM](https://docs.endorlabs.com/inventory-insights/sbom/index.md): Generate and manage Software Bill of Materials.
- [Export SBOMs and VEX](https://docs.endorlabs.com/inventory-insights/sbom/exporting-sboms/index.md): Learn more about software transparency and the role of SBOMs in your organization.
- [Import SBOMs](https://docs.endorlabs.com/inventory-insights/sbom/importing-sboms/index.md): Learn more about software transparency and the role of importing SBOMs in your organization.

### Scan with Endor Labs

- [Scan with Endor Labs](https://docs.endorlabs.com/scan/index.md): Explore user-initiated and system-triggered scan types for vulnerabilities, secrets, license issues, malware, and more.
- [Scan GitHub Actions](https://docs.endorlabs.com/scan/github-actions/index.md): Scan the GitHub Actions used in your workflow files for vulnerabilities, malware, and risky configuration.
- [Malware detection](https://docs.endorlabs.com/scan/malware/index.md): Understand how malware is detected, classified, and scored in Endor Labs.
- [AI Models](https://docs.endorlabs.com/scan/ai-models/index.md): Discover and govern AI models in your codebase.
- [OSS Licenses](https://docs.endorlabs.com/scan/oss-licenses/index.md): Identify and manage open source license compliance.
- [RSPM (Repository Security Posture Management)](https://docs.endorlabs.com/scan/rspm/index.md): Manage repository security posture and SCM configurations.
- [Working with monorepos](https://docs.endorlabs.com/scan/working-with-monorepos/index.md): Learn strategies to best work with large monorepos.

#### Scan Profiles

- [Scan Profiles](https://docs.endorlabs.com/scan/scan-profiles/index.md): Configure scan profiles to customize how your projects are scanned.
- [Configure build tools](https://docs.endorlabs.com/scan/scan-profiles/build-tools/index.md): Learn about build tools to build repeatable patterns in your scan environment.
- [Enable auto detection](https://docs.endorlabs.com/scan/scan-profiles/auto-detect-toolchains/index.md): Learn how to automatically detect toolchains used in your repository.
- [Configure scan profile through Endor Labs API](https://docs.endorlabs.com/scan/scan-profiles/configure-scanprofile-api/index.md): Learn how to configure scan profile through Endor Labs API
- [Configure scan profile through Endor Labs user interface](https://docs.endorlabs.com/scan/scan-profiles/configure-scanprofile-ui/index.md): Learn how to configure scan profile through the Endor Labs user interface.
- [Configure scan profile through scanprofile.yaml](https://docs.endorlabs.com/scan/scan-profiles/configure-scanprofile-yaml/index.md): Learn how to configure scan profile through scanprofile.yaml file
- [Configure scan workflow through Endor Labs API](https://docs.endorlabs.com/scan/scan-profiles/configure-scan-workflow-through-api/index.md): Learn how to configure scan workflow through Endor Labs API
- [Configure scan workflow through Endor Labs user interface](https://docs.endorlabs.com/scan/scan-profiles/configure-scanworkflow-through-ui/index.md): Learn how to configure scan workflow through the Endor Labs user interface.

#### SCA

- [SCA (Software Composition Analysis)](https://docs.endorlabs.com/scan/sca/index.md): Identify vulnerabilities in open source dependencies with reachability analysis.
- [Call graphs](https://docs.endorlabs.com/scan/sca/call-graphs/index.md): Mitigate open source vulnerabilities with call graph visualizations, pinpointing and understanding the invocation of vulnerable methods for actionable developer insights.
- [Scanning strategies](https://docs.endorlabs.com/scan/sca/scanning-strategies/index.md): Learn strategies to best scan your projects with Endor Labs.
- [Java](https://docs.endorlabs.com/scan/sca/java/index.md): Learn how to implement Endor Labs in repositories with Java packages.
- [Python](https://docs.endorlabs.com/scan/sca/python/index.md): Learn how to implement Endor Labs in repositories with Python packages.
- [Go](https://docs.endorlabs.com/scan/sca/golang/index.md): Learn how to implement Endor Labs in repositories with Go packages.
- [JavaScript/TypeScript](https://docs.endorlabs.com/scan/sca/javascript/index.md): Learn how to implement Endor Labs in repositories with JavaScript or TypeScript packages.
- [C/C++](https://docs.endorlabs.com/scan/sca/c/index.md): Learn how to implement Endor Labs in C and C++ repositories.
- [PHP](https://docs.endorlabs.com/scan/sca/php/index.md): Learn how to implement Endor Labs in repositories with PHP packages using composer.
- [Kotlin](https://docs.endorlabs.com/scan/sca/kotlin/index.md): Learn how to implement Endor Labs in repositories with Kotlin packages.
- [Scala](https://docs.endorlabs.com/scan/sca/scala/index.md): Learn how to implement Endor Labs in repositories with Scala packages.
- [.NET](https://docs.endorlabs.com/scan/sca/dotnet/index.md): Learn how to implement Endor Labs in repositories with .NET packages.
- [Swift/Objective-C](https://docs.endorlabs.com/scan/sca/swift-objective-c/index.md): Learn how to implement Endor Labs in repositories with CocoaPods and Swift Package Manager (SwiftPM) packages.
- [Ruby](https://docs.endorlabs.com/scan/sca/ruby/index.md): Learn how to implement Endor Labs in repositories with Ruby packages.
- [Rust](https://docs.endorlabs.com/scan/sca/rust/index.md): Learn how to implement Endor Labs in repositories with Rust packages.
- [Scan artifacts and binaries](https://docs.endorlabs.com/scan/sca/binary-artifact-scan/index.md): Detect and manage software supply chain risks by scanning software binaries and artifacts using Endor Labs.
- [Approximate scans](https://docs.endorlabs.com/scan/sca/approximate-scans/index.md): Learn about approximate scans in Endor Labs

##### Reachability analysis

- [Reachability analysis](https://docs.endorlabs.com/scan/sca/reachability-analysis/index.md): Learn how Endor Labs helps you identify which vulnerabilities are exploitable, potentially exploitable, and false positives.
- [Pre-computed Reachability analysis](https://docs.endorlabs.com/scan/sca/reachability-analysis/pre-computed-reachability/index.md): Pragmatically assess vulnerability reachability in transitive dependencies without builds. Filter out irrelevant vulnerabilities and focus your team's time.

##### Endor scores

- [Endor scores](https://docs.endorlabs.com/scan/sca/scores/index.md): Understand how packages and AI Models are scored in Endor Labs.

###### Package scores

- [Package scores](https://docs.endorlabs.com/scan/sca/scores/repository-scores/index.md): Understand how packages are scored in Endor Labs.
- [Activity score factors](https://docs.endorlabs.com/scan/sca/scores/repository-scores/activity-score-factors/index.md)
- [Popularity score factors](https://docs.endorlabs.com/scan/sca/scores/repository-scores/popularity-score-factors/index.md)
- [Security score factors](https://docs.endorlabs.com/scan/sca/scores/repository-scores/security-score-factors/index.md)
- [Code quality score factors](https://docs.endorlabs.com/scan/sca/scores/repository-scores/code-quality-score-factors/index.md)

#### SAST

- [SAST (Static Application Security Testing)](https://docs.endorlabs.com/scan/sast/index.md): Find security vulnerabilities in your first-party code with rule-based SAST or AI SAST.

##### Rule-based SAST

- [Rule-based SAST](https://docs.endorlabs.com/scan/sast/rule-based-sast/index.md): Run rule-based static analysis on your first-party code using Opengrep.
- [Run a SAST scan](https://docs.endorlabs.com/scan/sast/run-a-sast-scan/index.md): Run SAST scans with endorctl to identify security vulnerabilities and code quality issues in your source code.
- [Create Exception Policy for SAST Findings](https://docs.endorlabs.com/scan/sast/create-exception-policy/index.md)
- [View SAST Findings](https://docs.endorlabs.com/scan/sast/viewing-sast-findings/index.md): View, filter, and export SAST findings in Endor Labs.

###### SAST Rules

- [SAST Rules](https://docs.endorlabs.com/scan/sast/manage-sast-rules/index.md)
- [Clone a SAST rule](https://docs.endorlabs.com/scan/sast/manage-sast-rules/clone-sast-rule/index.md)
- [Create a SAST rule](https://docs.endorlabs.com/scan/sast/manage-sast-rules/create-sast-rule/index.md)
- [Edit a SAST rule](https://docs.endorlabs.com/scan/sast/manage-sast-rules/edit-a-sast-rule/index.md)
- [Import SAST rules](https://docs.endorlabs.com/scan/sast/manage-sast-rules/import-sast-rule/index.md)
- [Add metadata to a SAST rule](https://docs.endorlabs.com/scan/sast/manage-sast-rules/add-metadata-sast-rule/index.md)

#### AI SAST

- [AI SAST scan](https://docs.endorlabs.com/scan/ai-sast/index.md): Use AI SAST to triage findings and detect security vulnerabilities beyond traditional rule-based scanning.
- [AI SAST triage agent](https://docs.endorlabs.com/scan/ai-sast/triage-agent/index.md): Use an AI agent to automatically triage rule-based SAST findings as true positives or false positives and reduce manual review effort.
- [AI SAST detection agent](https://docs.endorlabs.com/scan/ai-sast/detection-agent/index.md): Use an AI agent to detect security vulnerabilities beyond traditional rule-based SAST and generate new findings labeled with an AI finding tag.
- [AI SAST PR scans](https://docs.endorlabs.com/scan/ai-sast/ai-sast-pr-scans/index.md): Run incremental AI SAST scans on pull requests to surface only the new findings introduced by the change.
- [AI context rules](https://docs.endorlabs.com/scan/ai-sast/ai-context/index.md): Use AI context rules to give the AI SAST detection agent codebase-specific guidance to improve detection accuracy and reduce false positives.

#### Secrets Detection

- [Secrets detection](https://docs.endorlabs.com/scan/secrets/index.md): Detect leaked credentials and sensitive data in your codebase.
- [Manage secret rules](https://docs.endorlabs.com/scan/secrets/secret-rules/index.md): Use secret rules to scan and detect secrets
- [Scan for secrets](https://docs.endorlabs.com/scan/secrets/scan-secrets/index.md): Scan for secrets in your source code
- [View secret findings](https://docs.endorlabs.com/scan/secrets/view-secret-findings/index.md): Review, prioritize, and remediate findings from a secrets scan.

#### Container Scanning

- [Container Scanning](https://docs.endorlabs.com/scan/containers/index.md): Scan container images for vulnerabilities and secure your deployments.
- [Scan containers using endorctl](https://docs.endorlabs.com/scan/containers/scan-containers-using-endorctl/index.md): Learn how to scan container images using the endorctl container scan command for security vulnerabilities, dependencies, and compliance.
- [Incremental container scanning](https://docs.endorlabs.com/scan/containers/incremental-container-scanning/index.md): Compare a container scan against a baseline to see only the findings a build introduced, fixed, or shares with the baseline.
- [Container inventory](https://docs.endorlabs.com/scan/containers/container-findings/index.md): Learn how to view, filter, and analyze container images in the Endor Labs platform.
- [Container reachability](https://docs.endorlabs.com/scan/containers/container-reachability/index.md): Determine if the packages inside a container image are actually used by your application at runtime.
- [Instrumented container reachability](https://docs.endorlabs.com/scan/containers/instrumented-reachability/index.md): <Badge color="green">Beta</Badge> <br /> Learn how to derive advanced OS package reachability when your container depends on complex external services.
- [Base image remediation](https://docs.endorlabs.com/scan/containers/base-image-remediation/index.md): Identify base image vulnerabilities in your containers and choose the update that fixes the most findings with the least risk.
- [Container registry scanning](https://docs.endorlabs.com/scan/containers/container-registry-scan/index.md): List and scan container images directly from a registry using filters and scan plans.
- [Sign artifacts](https://docs.endorlabs.com/scan/containers/artifact-signing/index.md): Learn how to use Endor Labs to sign container images and build artifacts in the CI pipeline.
- [Migrate to new container scan commands](https://docs.endorlabs.com/scan/containers/container-migration/index.md): Learn how to migrate from deprecated container scan flags to the new `endorctl container scan` command.

#### Pull Request scans

- [Pull Request scans](https://docs.endorlabs.com/scan/pr-scans/index.md): Scan pull requests created in your repository.
- [Configure PR scans](https://docs.endorlabs.com/scan/pr-scans/configure-pr-scans/index.md): Set up automated scanning through SCM apps, CI pipelines, scan profiles, monitored branches, and ignore files.
- [Run PR scans with endorctl](https://docs.endorlabs.com/scan/pr-scans/run-pr-scans-with-endorctl/index.md): Scan pull requests from the command line, including incremental scans and performance tuning.
- [Block pull requests on findings](https://docs.endorlabs.com/scan/pr-scans/block-pull-requests/index.md): Gate merges on PR scan findings using action policies and required status checks.
- [Pull Request comments](https://docs.endorlabs.com/scan/pr-scans/pr-comments/index.md): Learn how to enable and configure automated PR comments.

#### Bazel

- [Bazel](https://docs.endorlabs.com/scan/bazel/index.md): Learn how to implement Endor Labs in monorepos using Bazel
- [Bazel Aspects](https://docs.endorlabs.com/scan/bazel/bazel-aspects/index.md): Learn how to implement Endor Labs in monorepos using Bazel aspects

### Risk Remediation

- [Risk Remediation](https://docs.endorlabs.com/risk-remediation/index.md): Learn how Endor Labs helps address security vulnerabilities through strategic software updates and patches.
- [Upgrade impact analysis](https://docs.endorlabs.com/risk-remediation/upgrade-impact-analysis/index.md): Learn how Endor Labs helps you fix issues in your dependencies with remediation guidance.
- [Automated Pull Requests](https://docs.endorlabs.com/risk-remediation/automated-pull-requests/index.md): Automatically generate pull requests with dependency upgrades and security fixes.

#### Endor Patches

- [Endor Patches](https://docs.endorlabs.com/risk-remediation/endor-patches/index.md): Learn how to use Endor Patches and understand why they are beneficial.
- [Connect to the Endor Labs Patch Factory](https://docs.endorlabs.com/risk-remediation/endor-patches/connecting-to-the-factory/index.md): Learn how to connect to the Endor Labs Patch Factory and use an Endor patch.
- [Automatic patching with Endor Patches](https://docs.endorlabs.com/risk-remediation/endor-patches/auto-patching/index.md): Learn how to minimize changes for an Endor patch.
- [Patch transparency](https://docs.endorlabs.com/risk-remediation/endor-patches/trust/index.md): Build trust in your Endor Patches.
- [Configure JFrog Artifactory to use Endor Patches](https://docs.endorlabs.com/risk-remediation/endor-patches/configure-jfrog-artifactory/index.md): Learn how to configure your JFrog Artifactory setup to use Endor Patches.
- [Configure Sonatype Nexus Repository to use Endor Patches](https://docs.endorlabs.com/risk-remediation/endor-patches/configure-nexus-repository/index.md): Learn how to configure your Sonatype Nexus Repository setup to use Endor Patches.
- [Accessing the Endor Patch repository](https://docs.endorlabs.com/risk-remediation/endor-patches/access-endor-patch-repository/index.md): Learn how to retrieve and use Endor Patches versions of dependencies using direct URLs and build tool configurations.

### Integrations

- [Integrations](https://docs.endorlabs.com/integrations/index.md)
- [SCM Integrations](https://docs.endorlabs.com/integrations/scm/index.md): Connect source code management platforms for continuous monitoring.
- [Set up integrations using webhooks](https://docs.endorlabs.com/integrations/webhooks/index.md): Learn how to create webhooks and enable custom integrations with Endor Labs application
- [Set up Microsoft Defender for Cloud integration with Endor Labs](https://docs.endorlabs.com/integrations/microsoft-defender-for-cloud/index.md): Learn how to integrate Defender for Cloud with Endor Labs to close the gap between Application and Cloud security.
- [Set up Vanta integration with Endor Labs](https://docs.endorlabs.com/integrations/vanta/index.md): Learn how to integrate Vanta with Endor Labs and automate compliance requirements
- [Set up email integration](https://docs.endorlabs.com/integrations/email/index.md): Learn how to integrate your email addresses with Endor Labs and receive finding notifications
- [Set up Slack integration](https://docs.endorlabs.com/integrations/slack/index.md): Learn how to integrate Slack with Endor Labs and receive finding notifications
- [Third-party integrations](https://docs.endorlabs.com/integrations/third-party-integrations/index.md): Integrate Endor Labs with third-party security and vulnerability management platforms.

#### Package Repositories

- [Set up custom package repositories](https://docs.endorlabs.com/integrations/package-managers/index.md): Learn how to configure custom package repositories for dependency resolution.
- [Authenticate to private packages using mTLS](https://docs.endorlabs.com/integrations/package-managers/mtls-authentication/index.md): Learn how to configure custom package repositories for dependency resolution using mTLS.
- [Configure integration with AWS](https://docs.endorlabs.com/integrations/package-managers/aws-codeartifact/index.md): Learn how to configure package manager integrations with AWS CodeArtifact.
- [Configure integration with Google Artifact Registry](https://docs.endorlabs.com/integrations/package-managers/google-artifact-registry/index.md): Learn how to configure Endor Labs to authenticate with Google Artifact Registry for agentless dependency scanning.
- [Private package manager integration for Maven](https://docs.endorlabs.com/integrations/package-managers/maven-private-package-manager/index.md): Learn how to configure Endor Labs to access private Maven repositories for dependency resolution and security scanning.
- [Private package manager integration for Gradle](https://docs.endorlabs.com/integrations/package-managers/gradle-private-package-manager/index.md): Learn how to configure Endor Labs to access private Gradle repositories for dependency resolution and security scanning.
- [Private package manager integration for npm](https://docs.endorlabs.com/integrations/package-managers/npm-private-package-manager/index.md): Learn how to configure Endor Labs to access private npm repositories for dependency resolution and security scanning.
- [Private package manager integration for PyPI](https://docs.endorlabs.com/integrations/package-managers/pypi-private-package-manager/index.md): Learn how to configure Endor Labs to access private PyPI repositories for dependency resolution and security scanning.
- [Private package manager integration for RubyGems](https://docs.endorlabs.com/integrations/package-managers/rubygems-private-package-manager/index.md): Learn how to configure Endor Labs to access private RubyGems repositories for dependency resolution and security scanning.
- [Private package manager integration for NuGet](https://docs.endorlabs.com/integrations/package-managers/nuget-private-package-manager/index.md): Learn how to configure Endor Labs to access private NuGet repositories for dependency resolution and security scanning.
- [Private package manager integration for Swift](https://docs.endorlabs.com/integrations/package-managers/swift-private-package-manager/index.md): Learn how to configure Endor Labs to access private Swift package repositories for dependency resolution and security scanning.
- [Private package manager integration for Packagist](https://docs.endorlabs.com/integrations/package-managers/packagist-private-package-manager/index.md): Learn how to configure Endor Labs to access private Packagist repositories for dependency resolution and security scanning.
- [Git-based private dependencies](https://docs.endorlabs.com/integrations/package-managers/git-based-dependencies/index.md): <Badge color="green">Beta</Badge> <br /> Configure Endor Labs to resolve private Git-based dependencies hosted in SCM repositories during scans.

#### Jira

- [Set up Jira integration with Endor Labs](https://docs.endorlabs.com/integrations/jira/index.md): Learn how to implement ticketing workflows for Jira.
- [Manage security findings in Jira](https://docs.endorlabs.com/integrations/jira/jira-with-endor-labs/index.md): Learn how Endor Labs creates and manages Jira tickets for security findings, and choose the right notification aggregation type for your workflow.

#### Data exporters

- [Data exporters](https://docs.endorlabs.com/integrations/data-exporters/index.md): Learn how to export findings and scan data from Endor Labs to external storage and security platforms using the export framework.
- [Export findings to GitHub Advanced Security](https://docs.endorlabs.com/integrations/data-exporters/export-to-ghas/index.md): Learn how to export findings to GitHub Advanced Security.
- [Export findings to S3](https://docs.endorlabs.com/integrations/data-exporters/export-to-s3/index.md): Learn how to export findings and scan data to an AWS S3 storage bucket using the Endor Labs export framework.
- [Export findings to Wiz](https://docs.endorlabs.com/integrations/data-exporters/export-to-wiz/index.md): Learn how to export findings from Endor Labs to Wiz to enable code-to-cloud correlation in the Wiz Security Graph.

### Secure AI Coding

- [Secure AI Coding](https://docs.endorlabs.com/secure-ai-coding/index.md): Secure your AI-powered development workflows and govern AI model usage.
- [Agentic UI (AppSec Assistant)](https://docs.endorlabs.com/secure-ai-coding/agentic-ui/index.md): Use AI-powered assistance to ask questions about findings and troubleshoot issues.
- [AI model scores](https://docs.endorlabs.com/secure-ai-coding/ai-model-scores/index.md): Understand how AI Models are scored in Endor Labs.

#### Endor Labs Agent Kit

- [Endor Labs Agent Kit](https://docs.endorlabs.com/secure-ai-coding/agent-kit/index.md): Ready-to-use Endor Labs security agents for AI coding assistants.
- [Endor Labs Agent Kit in Claude Code](https://docs.endorlabs.com/secure-ai-coding/agent-kit/claude-code/index.md): Install and use the Endor Labs Agent Kit in Claude Code.
- [Endor Labs Agent Kit in Cursor](https://docs.endorlabs.com/secure-ai-coding/agent-kit/cursor/index.md): Install and use the Endor Labs Agent Kit in Cursor.
- [Endor Labs Agent Kit in OpenAI Codex](https://docs.endorlabs.com/secure-ai-coding/agent-kit/codex/index.md): Install and use the Endor Labs Agent Kit in OpenAI Codex.
- [Endor Labs Agent Kit in Gemini CLI](https://docs.endorlabs.com/secure-ai-coding/agent-kit/gemini-cli/index.md): Install and use the Endor Labs Agent Kit in Gemini CLI.
- [Endor Labs Agent Kit in Antigravity CLI](https://docs.endorlabs.com/secure-ai-coding/agent-kit/antigravity-cli/index.md): Install and use the Endor Labs Agent Kit in Antigravity CLI.
- [Endor Labs Agent Kit Cursor SDK](https://docs.endorlabs.com/secure-ai-coding/agent-kit/cursor-sdk/index.md): Run Endor Labs Agent Kit workflows programmatically with the Cursor Python SDK.
- [Portable agents](https://docs.endorlabs.com/secure-ai-coding/agent-kit/portable/index.md): Run runtime-neutral Endor Labs Agent Kit workflows in your own agent runtime.
- [Safety model and output contract](https://docs.endorlabs.com/secure-ai-coding/agent-kit/safety-model/index.md): The safety classes, approval gates, and output contract for Endor Labs Agent Kit agents.

#### Agents Hub

- [Agents Hub](https://docs.endorlabs.com/secure-ai-coding/agents-hub/index.md): <Badge color="green">Beta</Badge> <br /> Browse Endor Labs security agents and see how they are used across your tenant.
- [Browse agents in the Agents Hub](https://docs.endorlabs.com/secure-ai-coding/agents-hub/browse-agents/index.md): <Badge color="green">Beta</Badge> <br /> Find an agent in the catalog, read what it does, and install it in your AI coding assistant.
- [Delegated agent credentials](https://docs.endorlabs.com/secure-ai-coding/agents-hub/delegated-credentials/index.md): <Badge color="green">Beta</Badge> <br /> How an agent reaches Endor Labs data under a short-lived, read-only token attributed to you.
- [Agent activity](https://docs.endorlabs.com/secure-ai-coding/agents-hub/activity/index.md): <Badge color="green">Beta</Badge> <br /> Read the usage metrics the Agents Hub reports for each agent in your tenant.
- [Trust and attribution](https://docs.endorlabs.com/secure-ai-coding/agents-hub/trust-and-attribution/index.md): <Badge color="green">Beta</Badge> <br /> How Endor Labs signs the agent catalog and attributes every agent action to a person.

#### AI Security Review

- [AI Security Review](https://docs.endorlabs.com/secure-ai-coding/ai-security-review/index.md): Identify potential security issues in your pull requests using AI-powered review.
- [Prerequisites for AI security code review](https://docs.endorlabs.com/secure-ai-coding/ai-security-review/ai-security-prerequisites/index.md): Verify the prerequisites for AI security review
- [Set up AI security code review with GitHub App](https://docs.endorlabs.com/secure-ai-coding/ai-security-review/ai-security-review-settings/index.md): Learn how to set up and configure AI security code review for your projects
- [Set up AI security code review with endorctl](https://docs.endorlabs.com/secure-ai-coding/ai-security-review/ai-security-review-endorctl/index.md): Use endorctl to run AI security code review with GitHub environment variables.
- [View AI security code review results](https://docs.endorlabs.com/secure-ai-coding/ai-security-review/ai-security-review-results/index.md): Learn how to view the AI security code review results.
- [PR Comments for AI security code review](https://docs.endorlabs.com/secure-ai-coding/ai-security-review/ai-security-review-pr-comments/index.md): Learn how AI security code review PR comments work and how to interpret them as a developer

#### AI Model Discovery

- [AI Model Discovery](https://docs.endorlabs.com/secure-ai-coding/ai-model-discovery/index.md): Discover and evaluate AI models with comprehensive scoring for security and operational risk.
- [AI model findings](https://docs.endorlabs.com/secure-ai-coding/ai-model-discovery/ai-model-findings/index.md): Find and manage priority issues related to AI models.
- [AI model policies](https://docs.endorlabs.com/secure-ai-coding/ai-model-discovery/ai-model-policies/index.md): Learn about the predefined finding policy templates for CI/CD tools used in your software development environment.

#### Hugging Face Organizations

- [Hugging Face organization models](https://docs.endorlabs.com/secure-ai-coding/huggingface-organization/index.md): Connect a Hugging Face organization to Endor Labs to scan and score all its AI models.
- [Manage Hugging Face integrations on Endor Labs](https://docs.endorlabs.com/secure-ai-coding/huggingface-organization/manage-huggingface/index.md): Learn how to manage your Hugging Face integrations in Endor Labs.
- [View Hugging Face organization models](https://docs.endorlabs.com/secure-ai-coding/huggingface-organization/view-models/index.md): View, filter, and explore AI models discovered in your Hugging Face organization.

### Platform Administration

- [Platform Administration](https://docs.endorlabs.com/platform-administration/index.md): Configure and manage important settings of the Endor Labs platform.
- [License](https://docs.endorlabs.com/platform-administration/license/index.md): View your license details and license consumption across your organization.
- [Manage API keys](https://docs.endorlabs.com/platform-administration/api-keys/index.md): Manage your Endor Labs API keys for automation.
- [Configure system settings](https://docs.endorlabs.com/platform-administration/configure-system-settings/index.md): Configure Endor Labs application system settings to define the application behavior.
- [Set up namespaces](https://docs.endorlabs.com/platform-administration/namespaces/index.md): Use namespaces to organize your projects logically and define hierarchy.
- [Configure proxy server settings](https://docs.endorlabs.com/platform-administration/proxy-server-configuration/index.md): Configure proxy settings on machines that need to connect to Endor Labs when Internet access is limited to proxy-only connections.

#### Access to Endor Labs

- [Manage access to Endor Labs](https://docs.endorlabs.com/platform-administration/rbac/index.md): Learn how to manage access user and machine access to Endor Labs.
- [Authorization roles](https://docs.endorlabs.com/platform-administration/rbac/authorization-roles/index.md): Learn how to set permissions using authorization roles.
- [Authorization policies](https://docs.endorlabs.com/platform-administration/rbac/authorization-policies/index.md): Learn how to manage authorization policies in Endor Labs.
- [Manage user invitations](https://docs.endorlabs.com/platform-administration/rbac/invitations/index.md): Invite your team to work with you on Endor Labs.

##### Authentication providers

- [Authentication providers](https://docs.endorlabs.com/platform-administration/rbac/authentication-providers/index.md): Learn about authentication providers and their session token durations in Endor Labs.

###### Set up SSO with Endor Labs

- [Set up SSO with Endor Labs](https://docs.endorlabs.com/platform-administration/rbac/authentication-providers/custom-identity-providers/index.md): Set up SAML or OIDC single sign on for Endor Labs with in your organization.
- [Set up Okta for SSO using SAML](https://docs.endorlabs.com/platform-administration/rbac/authentication-providers/custom-identity-providers/okta-saml/index.md): Learn how to setup Okta as a custom external identity provider for SSO with Endor Labs
- [Set up Okta for SSO using OIDC](https://docs.endorlabs.com/platform-administration/rbac/authentication-providers/custom-identity-providers/okta-oidc/index.md): Learn how to setup Okta as a custom external identity provider for SSO with Endor Labs
- [Set up Entra ID for SSO using SAML](https://docs.endorlabs.com/platform-administration/rbac/authentication-providers/custom-identity-providers/entraid-saml/index.md): Set up Microsoft Entra ID as a custom identity provider for SSO with Endor Labs.
- [Set up Entra ID for SSO using OIDC](https://docs.endorlabs.com/platform-administration/rbac/authentication-providers/custom-identity-providers/entraid-oidc-azure/index.md): Learn how to setup Microsoft Entra ID as a custom external identity provider for SSO with Endor Labs.

#### Policies

- [Policies](https://docs.endorlabs.com/platform-administration/policies/index.md): Create and manage finding, action, exception, and remediation policies.
- [Remediation policies](https://docs.endorlabs.com/platform-administration/policies/remediation-policies/index.md): Learn about remediation policies and how to use them.
- [Tag projects](https://docs.endorlabs.com/platform-administration/policies/tagging-projects/index.md): Learn about tagging projects to manage policies in Endor Labs

##### Finding policies

- [Finding policies](https://docs.endorlabs.com/platform-administration/policies/finding-policies/index.md): Learn about finding policies and how to use them.
- [Container policies](https://docs.endorlabs.com/platform-administration/policies/finding-policies/container-policies/index.md): Learn about the predefined finding policy templates for containers.
- [License policies](https://docs.endorlabs.com/platform-administration/policies/finding-policies/license-policies/index.md): Learn about the predefined finding policy templates for open source license risk management.
- [RSPM policies](https://docs.endorlabs.com/platform-administration/policies/finding-policies/managing-scm-configuration/index.md): Learn about the out-of-the-box finding policies for repository security posture management (RSPM).
- [Open-source policies](https://docs.endorlabs.com/platform-administration/policies/finding-policies/oss-policies/index.md): Learn about the out-of-the-box finding policies for open source risk management.
- [SAST policies](https://docs.endorlabs.com/platform-administration/policies/finding-policies/sast-policies/index.md): Learn about the predefined finding policy templates for SAST used in your software development environment.
- [Secret policies](https://docs.endorlabs.com/platform-administration/policies/finding-policies/secret-policies/index.md): Learn about the out-of-the-box finding policies and templates for secret detection.
- [GitHub Action policies](https://docs.endorlabs.com/platform-administration/policies/finding-policies/github-action-policies/index.md): Learn about the out-of-the-box finding policies for GitHub Actions.

##### Exception policies

- [Exception policies](https://docs.endorlabs.com/platform-administration/policies/exception-policies/index.md): Learn about exception policies and how to use them.
- [Exception policy templates](https://docs.endorlabs.com/platform-administration/policies/exception-policies/templates/index.md): Learn about the predefined exception policy templates and how to customize them.

##### Action policies

- [Action policies](https://docs.endorlabs.com/platform-administration/policies/action-policies/index.md): Learn about action policies and how to use them.
- [Action policy templates](https://docs.endorlabs.com/platform-administration/policies/action-policies/templates/index.md): Learn about the predefined action policy templates and how to customize them.

### Best Practices

- [Best Practices](https://docs.endorlabs.com/best-practices/index.md): Learn how to integrate Endor Labs most effectively into your organization's workflows.
- [Best Practices: Branches and workflows](https://docs.endorlabs.com/best-practices/operational-best-practices/index.md): Learn how to scan different branches, set up baseline branches, and integrate PR scans into your development workflow.
- [Best Practices: API key management](https://docs.endorlabs.com/best-practices/manage-api-keys/index.md): Learn how to manage API keys, check for expiring keys, and automate key rotation.
- [Best Practices: Scoping scans](https://docs.endorlabs.com/best-practices/scoping-scans/index.md): Learn how to effectively scope your scans with Endor Labs inclusion and exclusion patterns.
- [Best Practices: GitHub Security Campaign](https://docs.endorlabs.com/best-practices/github-security-campaign/index.md): Learn how to plan, execute, and monitor GitHub security campaigns using Endor Labs and GitHub Advanced Security.
- [Best Practices: Build tools use cases](https://docs.endorlabs.com/best-practices/build-tools-use-case/index.md): Explore common build tool scenarios and strategies to configure scan profiles for accurate and reliable scans

#### Troubleshooting

- [Troubleshooting](https://docs.endorlabs.com/best-practices/troubleshooting/index.md): Diagnose and resolve common issues with Endor Labs scans.
- [endorctl CLI exit codes](https://docs.endorlabs.com/best-practices/troubleshooting/endorctl-exitcodes/index.md): Learn about the exit codes that you may encounter while using the endorctl CLI.
- [Firewall & Proxy Rules](https://docs.endorlabs.com/best-practices/troubleshooting/firewall-rules/index.md): Learn about firewall and web proxy rules for using Endor Labs.
- [Scanning Podman built container images](https://docs.endorlabs.com/best-practices/troubleshooting/podman/index.md): Troubleshoot errors while scanning container images built using Podman

### Research Open Source Risks

- [Research Open Source Risks](https://docs.endorlabs.com/discover/index.md)
- [Search for Open Source Packages](https://docs.endorlabs.com/discover/open-source-packages/index.md): Search open source packages and review the security, dependency, and license details of a specific package version.
- [Endor Labs Vulnerability Database](https://docs.endorlabs.com/discover/vulnerability-db/index.md): Understand how to search, analyze, and navigate vulnerabilities.

### Trust & Compliance

- [Trust & Compliance](https://docs.endorlabs.com/trust-compliance/index.md): Learn about how Endor Labs handles your data and compliance
