Application and platform engineering

Make security review part of the change that ships.

Give developers feedback while the repository is still in front of them, then use the same analysis in CI. Code Security helps application and platform teams review source, dependency and configuration changes without making a source upload the prerequisite for a scan.

Inside a supported flow finding

Illustrative investigation

A request value reaches a database operation

  1. 01 / Input

    Where the application receives the value

  2. 02 / Transformation

    How it is changed, checked or passed onward

  3. 03 / Operation

    The security-sensitive use the reviewer must inspect

Location
File & line

Assessment
Severity & confidence

Coverage
Method & limits

Conceptual example. Flow evidence is available only for supported analysis paths.

A practical scenario

A pull request changes an API and its deployment configuration

An engineer updates a handler, adds a package and changes the container definition. Those changes raise different questions: how inputs reach sensitive operations, which dependency versions are selected and whether the supporting configuration is appropriate. Review them together before approving the revision.

Bring to the review
The repository, supported manifests and lockfiles, infrastructure files, and the revision being reviewed.
Work towards
A scoped scan result, an engineering correction where needed, and a repeatable CI decision for the final change.

The team's working process

From a developer's first scan to the release gate

  1. Establish the checks for this repository

    Run a representative scan locally and review its coverage with the engineers who maintain the project. Select the relevant source, dependency and secret checks, then decide which findings require a fix or a recorded review before delivery.

  2. Keep investigation close to the code

    Read the affected location, supported trace, confidence and remediation guidance. Run separate inventory or malicious-package checks when the change needs them. Use local reports for immediate work and upload results when the wider team needs to collaborate.

  3. Apply the policy to the final revision

    Provision authorised CLI components in CI with a scoped token. Check incomplete-analysis signals as well as the configured threshold. Run the project's tests and retain the relevant findings artifact, keeping credentials and private engine bundles out of shared build output.

The result of the work

A useful handover between engineering and security.

An actionable finding

The engineer receives a location and explanation that can be checked against the implementation, with the available flow evidence and analysis limitations.

A repeatable pipeline result

The team can distinguish a complete scan, a failed operation, incomplete coverage and a threshold failure instead of treating every empty output as a pass.

A review record

Optional uploads connect findings to assignment, comments and dispositions. The next comparable run can be reviewed against the existing record.

A focused evaluation

Test the workflow with evidence your team already understands.

Pick a repository with a known issue, a recently fixed change and the delivery configuration the team actually uses. Compare the findings and coverage with that knowledge. Measure whether an engineer can reproduce the result and complete the review in the ordinary pull-request workflow.

Agree the participating team, input scope and expected deliverable before expanding the rollout. The most useful evaluation shows how a real owner investigates and acts on the result.

Practical questions

Planning for application and platform engineering.

Do developers need to send the repository to Magdox?

No. Analysis runs locally. Uploads are explicit and metadata-first; source snippets need the configured permission and operator consent.

Can a coding assistant run the checks too?

The v1.3 MCP workflow supports compatible, configured clients. Host validation and platform limits are documented; keep CI as the release enforcement point.

Which plan is the starting point?

Team includes scanning and the shared findings workflow for up to 20 CLI-capable developers. Business adds portfolio risk, inventory and organisation policy features.

Code Security · next step

Start with one application and its repositories.

A scoped scan result, an engineering correction where needed, and a repeatable CI decision for the final change.

14-day self-service trial. Card required; cancel before the trial ends to avoid the first charge.