US 12,346,457 B1
System and method for scanning private code and CI/CD registries
Arnon Trabelsi, Tel Aviv (IL); and Daniel Hershko Shemesh, Givat-Shmuel (IL)
Assigned to Wiz, Inc., New York, NY (US)
Filed by Wiz, Inc., New York, NY (US)
Filed on Dec. 9, 2024, as Appl. No. 18/974,123.
Int. Cl. G06F 21/57 (2013.01); G06F 8/71 (2018.01)
CPC G06F 21/577 (2013.01) [G06F 8/71 (2013.01); G06F 2221/033 (2013.01)] 11 Claims
OG exemplary drawing
 
1. A method for inspecting private code repositories for cybersecurity issues, comprising:
accessing a private code repository, the private code repository including a plurality of code objects, wherein the private code repository is accessible a cloud computing environment;
generating a pull request including code for an inspector, the inspector configured to detect a cybersecurity object in a code object of the plurality of code objects;
initiating the pull request in the private code repository;
receiving a result from the inspector at an inspection environment, wherein the private code repository is inaccessible to the inspection environment, and wherein the result includes an identifier of the code object and an identifier of a detected cybersecurity object, and wherein the cybersecurity object indicates a cybersecurity issue;
inspecting a resource for another cybersecurity object, wherein the resource is deployed in the cloud computing environment based on the code object;
detecting the cybersecurity issue based on detecting the cybersecurity object and the another cybersecurity object; and
generating a representation of: the code object in a security database based on the received result, the resource, and the detected cybersecurity object, wherein the security database includes a representation of the cloud computing environment.