Security Scanning

Codity provides comprehensive security scanning capabilities to help identify vulnerabilities and dependency issues in your codebase before they reach production.

Overview

Codity's security scanning includes two main components:

  • Security Vulnerability Scanning: Detects security vulnerabilities in your code
  • Package Dependency Scanning: Identifies vulnerable or outdated dependencies
  • License Compliance Scanning: Identifies license risks and copyleft compliance issues in dependencies

All scans run automatically on every pull request or merge request, providing immediate feedback to developers.

Security Vulnerability Scanning

Security vulnerability scanning analyzes your code for common security issues and weaknesses that could be exploited by attackers.

What It Detects

Code-Level Vulnerabilities:

  • SQL Injection vulnerabilities
  • Cross-Site Scripting (XSS) attacks
  • Command Injection flaws
  • Path Traversal vulnerabilities
  • Insecure Deserialization
  • Authentication and Authorization issues
  • Insecure Cryptography usage
  • Hard-coded credentials and secrets
  • Insecure Random Number Generation
  • XML External Entity (XXE) attacks

Security Misconfigurations:

  • Insecure CORS configurations
  • Missing security headers
  • Insecure cookie settings
  • Open redirects
  • Improper error handling that exposes sensitive data
  • Debug mode enabled in production code

OWASP Top 10 Coverage: Codity's scanning covers all OWASP Top 10 vulnerabilities, including:

  • Broken Access Control
  • Cryptographic Failures
  • Injection attacks
  • Insecure Design patterns
  • Security Misconfiguration
  • Vulnerable and Outdated Components
  • Identification and Authentication Failures
  • Software and Data Integrity Failures
  • Security Logging and Monitoring Failures
  • Server-Side Request Forgery (SSRF)

Severity Levels

Vulnerabilities are classified by severity to help prioritize fixes:

  • Critical: Immediate action required - exploitable vulnerabilities that could lead to complete system compromise
  • High: Should be fixed soon - serious vulnerabilities that could significantly impact security
  • Medium: Should be addressed - moderate security issues that could be exploited under certain conditions
  • Low: Consider fixing - minor security concerns or best practice violations
  • Info: Informational - security recommendations and hardening suggestions

How It Works

  1. Automatic Detection: Scans run automatically on every PR/MR
  2. Inline Comments: Vulnerabilities are reported as inline comments on specific lines of code
  3. Detailed Explanations: Each finding includes:
    • Description of the vulnerability
    • Why it's a security risk
    • Potential impact
    • Recommended fix with code examples
    • References to security standards (CWE, OWASP)
  4. Context-Aware: Understands code context to minimize false positives
  5. Multi-Language Support: Works with Python, JavaScript/TypeScript, Java, Kotlin, Scala, Go, Ruby, PHP, C#, Rust, Apex, and Visualforce

Supported Languages

Language File Types Scanned
Python .py
JavaScript .js, .jsx, .mjs, .cjs
TypeScript .ts, .tsx
Java .java
Kotlin .kt
Scala .scala
Go .go
Ruby .rb
PHP .php
C# .cs
Rust .rs
Apex .cls, .trigger
Visualforce .page, .component

Findings in other file types are still reported when they appear in a reviewed diff; the languages above are the ones Codity resolves cross-file context for, so they get the deepest analysis.

Effectiveness

High Detection Rate:

  • Comprehensive pattern-based detection covering major vulnerability classes
  • 100% coverage of OWASP Top 10 categories
  • Regular updates to detection patterns
  • Incorporates latest security research

Low False Positive Rate:

  • Advanced pattern matching reduces false positives
  • Context-aware analysis understands code flow
  • Configurable rules to match your security standards

Early Detection:

  • Catches vulnerabilities before code review
  • Prevents security issues from reaching production
  • Reduces cost of fixing vulnerabilities (earlier is cheaper)
  • Enables shift-left security practices

Package Dependency Scanning

Package dependency scanning identifies security vulnerabilities in third-party libraries and packages used by your project. It reads your manifests and lock files directly, so it works whether or not your CI runs an audit step.

What It Detects

Vulnerable Dependencies:

  • Known CVE (Common Vulnerabilities and Exposures)
  • Security advisories from package registries
  • Exploitable vulnerabilities in dependencies
  • Transitive dependency vulnerabilities (dependencies of dependencies)

Outdated Dependencies:

  • Dependencies with available security patches
  • End-of-life or unmaintained packages
  • Deprecated packages with security concerns

Supported Languages and Package Managers

Language Package Manager Manifests and Lock Files
JavaScript / TypeScript npm, Yarn, pnpm package-lock.json, yarn.lock, pnpm-lock.yaml, package.json
Python pip, Poetry, Pipenv poetry.lock, Pipfile.lock, requirements.txt
Ruby Bundler Gemfile.lock
Java Maven, Gradle pom.xml, build.gradle
Kotlin Gradle build.gradle, build.gradle.kts
Scala sbt build.sbt
Go Go modules go.mod, go.sum
PHP Composer composer.lock, composer.json
C# / .NET NuGet packages.lock.json, *.csproj, packages.config, Directory.Packages.props
Rust Cargo Cargo.lock, Cargo.toml
Swift Swift Package Manager Package.resolved
Dart / Flutter pub pubspec.lock
Elixir Hex mix.lock

How It Works

  1. Manifest Discovery: Walks the repository for the files listed above, including nested projects in a monorepo
  2. Dependency Resolution: Parses each file into a pinned set of packages and versions, separating direct from transitive and production from development dependencies
  3. Vulnerability Matching: Queries the OSV database per ecosystem — npm, PyPI, RubyGems, Maven, Go, Packagist, NuGet, crates.io, SwiftURL, Pub, and Hex
  4. Impact Assessment: Evaluates severity and exploitability
  5. Fix Recommendations: Suggests specific version upgrades to resolve issues
  6. Pull Request Comments: Reports findings directly on the PR/MR

CI log parsing (supplementary). Where your pipeline already runs an audit step, Codity also reads its output to pick up findings the manifests alone would not show. This path covers npm audit, yarn audit, pip-audit, Maven, Gradle, bundler-audit and Go, and it supplements the manifest scan rather than replacing it.

Vulnerability Database Sources

Codity's dependency scanning uses data from:

  • National Vulnerability Database (NVD)
  • GitHub Security Advisories
  • npm Security Advisories
  • PyPI Security Advisories
  • RubySec Advisory Database
  • RustSec Advisory Database
  • OSV (Open Source Vulnerabilities)

Business Benefits

Cost Savings:

  • 10-100x cheaper to fix vulnerabilities early vs. production
  • Reduced security incident costs
  • Faster security review process

Time Savings:

  • Automated scanning replaces manual security reviews
  • Immediate feedback (no waiting for security team)
  • Faster development cycles
  • Reduced back-and-forth on security issues

Risk Reduction:

  • Lower probability of breaches
  • Reduced legal liability
  • Better security reputation

Developer Experience

Seamless Integration:

  • Works with existing workflows
  • No additional tools to learn
  • Clear, actionable feedback
  • Fix suggestions with code examples

Learning and Growth:

  • Developers learn secure coding patterns
  • Immediate feedback loop
  • References to security standards (CWE, OWASP)
  • Builds security awareness

License Compliance Scanning

License compliance scanning analyzes your project's dependencies to identify license risks, copyleft obligations, and compliance issues.

How to Trigger

Comment /license-scan on any PR/MR to trigger a license compliance scan.

Supported Platforms:

  • GitHub
  • GitLab
  • Azure DevOps
  • Bitbucket

What It Detects

License Risk Classification:

  • High Risk: Strong copyleft licenses (GPL-2.0, GPL-3.0, AGPL-3.0, SSPL-1.0, OSL) and proprietary/commercial licenses
  • Medium Risk: Weak copyleft licenses (LGPL, MPL, EPL, EUPL, CDDL, CPL)
  • Low Risk: Permissive licenses (MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC, Unlicense, CC0-1.0, Zlib, PostgreSQL, Python-2.0, and others)
  • Unknown: Licenses that cannot be identified

Copyleft Detection:

  • Identifies strong copyleft licenses (GPL, AGPL, OSL, SSPL) that require derivative works to use the same license
  • Identifies weak copyleft licenses (LGPL, MPL, EPL, EUPL, CDDL) that have limited copyleft scope
  • Detects FOSS exceptions (classpath-exception, gcc-exception) that reduce copyleft restrictions

OSI Approval Status:

  • Reports whether each license is OSI (Open Source Initiative) approved

Supported Languages and Lock Files

Language Files Used
JavaScript / TypeScript package-lock.json, yarn.lock, package.json
Python poetry.lock, Pipfile.lock, requirements.txt
Ruby Gemfile.lock
Java / Kotlin pom.xml, build.gradle
Go go.mod
PHP composer.lock, composer.json
C# / .NET packages.lock.json, *.csproj, packages.config, Directory.Packages.props

License scanning covers a narrower set than dependency scanning: Rust, Swift, Dart, Elixir and Scala are scanned for vulnerabilities but not yet for license compliance.

Scan Results

Each scan result includes:

  • Total packages scanned
  • Risk breakdown (high, medium, low, unknown counts)
  • Copyleft package count
  • Compliance status
  • Per-package details: package name, version, license ID, SPDX ID, risk level, copyleft status, and OSI approval

Salesforce

Salesforce projects get additional checks on every pull request, as part of the normal security scan.

What Runs on Every Pull Request

  • PMD rules for Apex and Visualforce
  • Curated rules for Lightning Web Components and Aura
  • Vulnerable JavaScript libraries in static resources
  • An Apex-aware security review covering CRUD/FLS, sharing, @AuraEnabled and @RestResource entry points, and guest-user context

Metadata Checks

Changes to Salesforce metadata are checked as well:

  • Permission sets and profiles, and guest-user exposure
  • Org-wide defaults and sharing rules
  • CSP and remote sites
  • Named credentials, connected apps, SAML, org security settings and certificates
  • destructiveChanges, Flows, and Agentforce agents and prompt templates

Permission, sharing and settings rules report only changes that loosen security. Settings that were already in place are not reported.

Guest Reachability

Codity flags concrete paths from a guest profile to an Apex class declared without sharing.

Deep Apex Analysis on Request

Comment on a pull request:

/security-scan --deep-apex

This adds Salesforce Graph Engine data-flow (taint) analysis. Its results are merged with those of the fast scan that runs on every pull request.

Supported Platforms:

  • GitHub
  • GitLab
  • Azure DevOps
  • Bitbucket

In the PR Comment

Salesforce findings get their own grouped section in the PR comment, including in Concise Mode.

Customizing Security Rules

Commit a .codity/security-rules.yaml (or .codity/security-rules.yml) file to the repository to tune what the security scan reports:

disabled_rules:
  - ApexCRUDViolation
severity_overrides:
  ApexSOQLInjection: critical
path_ignores:
  - "*Test.cls"
  - "test/fixtures/*"
Key What it does
disabled_rules Drops findings by rule ID.
severity_overrides Maps a rule ID to critical, high, medium or low.
path_ignores Ignores paths that match shell-style globs (fnmatch).

Rule IDs match case-insensitively and punctuation is ignored, so PMD names (ApexCRUDViolation) and ESLint-style names (@lwc/lwc/no-inner-html) both work as written.

The file applies to pull request security scans, including the scan that runs automatically after a review. There is no dashboard setting for it yet.

Additional Resources