Skip to content

description: Every saw command and flag, documented once: scan, fix, discard, audit, guard, hook, auth, db, search, intro, doctor and completion.

saw command reference

Every saw flag is documented here, and only here — the guides link to these pages rather than repeating them. saw <command> -h states what that command is for, lists its flags, and ends with a short examples: block — the same invocations used here, so the terminal and this page agree.

saw <command> [options] [TARGETS...]

Bare saw prints the welcome screen; saw -h lists the commands. stayawake is an identical long alias, for scripts where a three-letter name might clash on PATH.

Command What it does Writes?
scan Hunt for supply-chain worms and report read-only
fix Prepare the cleanup on a security/auto-clean branch that branch only; pushes with --pr
discard Undo saw fix git / GitHub API
audit Machine hygiene, start-up surface, branch protection read-only
guard Install and verify the Strix CI gate check/drift read-only; setup writes a workflow or a PR
hook Scan what a clone or pull just brought in your global git config
auth Credential and capability status; register a GitHub App local config
db Manage the offline advisory database its cache only
search Find the command you want
intro Tour (also the bare-saw welcome)
doctor Self-check: install, credential, capabilities
completion Print a shell-completion script

Three sections apply across commands: remote targeting, report sinks and credentials. Coming from the removed console scripts? See migrating.

Global options

Option Description
-h, --help Help for saw or for any command.
--version Package version and capability inventory.

Flags shared by several commands

Option Where Description
--json scan, auth status, doctor, search Machine-readable output on stdout.
-q, --quiet doctor, search Only the essentials.
-f, --fail audit, guard check Exit non-zero on a warning-level issue. saw scan has no --fail — its exit code is the verdict unconditionally.
--no-stream scan, fix, discard, audit, guard, auth, db Plain instant lines instead of live progress.
-j, --jobs N scan, fix, guard check/setup/drift Work on up to N repositories at once. Default auto (one repo sequential, several use one worker per core); -j 1 forces sequential. On scan it also splits one large repository across workers.

Command aliases

Accepted anywhere the full verb is: scans, sc; auditau; guardgd; searchse; introwelcome; doctord, doc; completioncomp. fix and discard are always spelled out.

Environment variables

Variable Effect
GH_SECURITY_TOKEN, GITHUB_TOKEN, GH_APP_* Credentials — see credentials.
SLACK_WEBHOOK_URL, GITHUB_REPOSITORY Where --alert posts.
STAYAWAKE_REPORTS_DIR Default reports directory; -d overrides it.
STAYAWAKE_NO_STREAM=1 As --no-stream.
SAW_HOOK_DISABLED=1 Skip the clone/pull hook for one command.
SAW_HOOK_TIMEOUT Wall-clock budget for a hook scan (default 60s).
NO_COLOR, CLICOLOR_FORCE Force colour off / on.