An actionable finding
The engineer receives a location and explanation that can be checked against the implementation, with the available flow evidence and analysis limitations.
Application and platform engineering
Give developers feedback while the repository is still in front of them, then use the same analysis in CI. Code Security helps application and platform teams review source, dependency and configuration changes without making a source upload the prerequisite for a scan.
Illustrative investigation
01 / Input
Where the application receives the value
02 / Transformation
How it is changed, checked or passed onward
03 / Operation
The security-sensitive use the reviewer must inspect
Location
File & line
Assessment
Severity & confidence
Coverage
Method & limits
Conceptual example. Flow evidence is available only for supported analysis paths.
A practical scenario
An engineer updates a handler, adds a package and changes the container definition. Those changes raise different questions: how inputs reach sensitive operations, which dependency versions are selected and whether the supporting configuration is appropriate. Review them together before approving the revision.
The team's working process
Run a representative scan locally and review its coverage with the engineers who maintain the project. Select the relevant source, dependency and secret checks, then decide which findings require a fix or a recorded review before delivery.
Read the affected location, supported trace, confidence and remediation guidance. Run separate inventory or malicious-package checks when the change needs them. Use local reports for immediate work and upload results when the wider team needs to collaborate.
Provision authorised CLI components in CI with a scoped token. Check incomplete-analysis signals as well as the configured threshold. Run the project's tests and retain the relevant findings artifact, keeping credentials and private engine bundles out of shared build output.
The result of the work
The engineer receives a location and explanation that can be checked against the implementation, with the available flow evidence and analysis limitations.
The team can distinguish a complete scan, a failed operation, incomplete coverage and a threshold failure instead of treating every empty output as a pass.
Optional uploads connect findings to assignment, comments and dispositions. The next comparable run can be reviewed against the existing record.
A focused evaluation
Pick a repository with a known issue, a recently fixed change and the delivery configuration the team actually uses. Compare the findings and coverage with that knowledge. Measure whether an engineer can reproduce the result and complete the review in the ordinary pull-request workflow.
Agree the participating team, input scope and expected deliverable before expanding the rollout. The most useful evaluation shows how a real owner investigates and acts on the result.
Practical questions
No. Analysis runs locally. Uploads are explicit and metadata-first; source snippets need the configured permission and operator consent.
The v1.3 MCP workflow supports compatible, configured clients. Host validation and platform limits are documented; keep CI as the release enforcement point.
Team includes scanning and the shared findings workflow for up to 20 CLI-capable developers. Business adds portfolio risk, inventory and organisation policy features.
Code Security · next step
A scoped scan result, an engineering correction where needed, and a repeatable CI decision for the final change.
14-day self-service trial. Card required; cancel before the trial ends to avoid the first charge.