The Vidoc handle
To talk to Vidoc, mention its handle at the start of your comment. The handle depends on the platform:
The summary comment of Vidoc always shows the correct handle in its last line: “Have questions? Tag @… in a comment”. Use this handle. This page uses
@vidoc in the examples.
Scan commands
Write a new PR comment or thread reply that starts with the handle and contains only the command.
How Vidoc reads a comment that mentions the handle:
Rules for commands:
- Letter case is not important. A period or exclamation mark at the end is permitted.
- Put only the command on one line. Do not put it in a quote or a code block.
- If you edit a comment, Vidoc does not run the command in it. Write a new comment.
- PR reviews and PR comments must be on for the repository.
- You do not need a Vidoc account to send commands.
Who can send commands
Cooldown
Vidoc starts a new scan from a command only if no other scan of this PR started in the last 60 seconds. If a scan started recently, wait one minute and send the command again.Replies from Vidoc
When Vidoc accepts the command, it adds the “eyes” (👀) reaction to your comment. Then Vidoc replies in the thread:
On GitHub, you can also select Run Vidoc on the Vidoc Security Scan check to scan again. This button shows only when status reporting is on. Refer to Status check.
Ask Vidoc a question
You can ask Vidoc a question in a PR comment or in a thread. Mention the handle and write your question:What Vidoc can do when you mention it
- Read the code of the repositories in the Vidoc project, and read Memory.
- List the findings and the reviewed PRs of the Vidoc project.
- Save a memory entry.
- Change the status or the severity of a finding in the Vidoc project, when you ask for it explicitly.

