Security Scanning
Codity provides comprehensive security scanning capabilities to help identify vulnerabilities and dependency issues in your codebase before they reach production.
Overview
Codity's security scanning includes two main components:
- Security Vulnerability Scanning: Detects security vulnerabilities in your code
- Package Dependency Scanning: Identifies vulnerable or outdated dependencies
- License Compliance Scanning: Identifies license risks and copyleft compliance issues in dependencies
All scans run automatically on every pull request or merge request, providing immediate feedback to developers.
Security Vulnerability Scanning
Security vulnerability scanning analyzes your code for common security issues and weaknesses that could be exploited by attackers.
What It Detects
Code-Level Vulnerabilities:
- SQL Injection vulnerabilities
- Cross-Site Scripting (XSS) attacks
- Command Injection flaws
- Path Traversal vulnerabilities
- Insecure Deserialization
- Authentication and Authorization issues
- Insecure Cryptography usage
- Hard-coded credentials and secrets
- Insecure Random Number Generation
- XML External Entity (XXE) attacks
Security Misconfigurations:
- Insecure CORS configurations
- Missing security headers
- Insecure cookie settings
- Open redirects
- Improper error handling that exposes sensitive data
- Debug mode enabled in production code
OWASP Top 10 Coverage: Codity's scanning covers all OWASP Top 10 vulnerabilities, including:
- Broken Access Control
- Cryptographic Failures
- Injection attacks
- Insecure Design patterns
- Security Misconfiguration
- Vulnerable and Outdated Components
- Identification and Authentication Failures
- Software and Data Integrity Failures
- Security Logging and Monitoring Failures
- Server-Side Request Forgery (SSRF)
Severity Levels
Vulnerabilities are classified by severity to help prioritize fixes:
- Critical: Immediate action required - exploitable vulnerabilities that could lead to complete system compromise
- High: Should be fixed soon - serious vulnerabilities that could significantly impact security
- Medium: Should be addressed - moderate security issues that could be exploited under certain conditions
- Low: Consider fixing - minor security concerns or best practice violations
- Info: Informational - security recommendations and hardening suggestions
How It Works
- Automatic Detection: Scans run automatically on every PR/MR
- Inline Comments: Vulnerabilities are reported as inline comments on specific lines of code
- Detailed Explanations: Each finding includes:
- Description of the vulnerability
- Why it's a security risk
- Potential impact
- Recommended fix with code examples
- References to security standards (CWE, OWASP)
- Context-Aware: Understands code context to minimize false positives
- Multi-Language Support: Works with Python, JavaScript/TypeScript, Java, Kotlin, Scala, Go, Ruby, PHP, C#, Rust, Apex, and Visualforce
Supported Languages
| Language | File Types Scanned |
|---|---|
| Python | .py |
| JavaScript | .js, .jsx, .mjs, .cjs |
| TypeScript | .ts, .tsx |
| Java | .java |
| Kotlin | .kt |
| Scala | .scala |
| Go | .go |
| Ruby | .rb |
| PHP | .php |
| C# | .cs |
| Rust | .rs |
| Apex | .cls, .trigger |
| Visualforce | .page, .component |
Findings in other file types are still reported when they appear in a reviewed diff; the languages above are the ones Codity resolves cross-file context for, so they get the deepest analysis.
Effectiveness
High Detection Rate:
- Comprehensive pattern-based detection covering major vulnerability classes
- 100% coverage of OWASP Top 10 categories
- Regular updates to detection patterns
- Incorporates latest security research
Low False Positive Rate:
- Advanced pattern matching reduces false positives
- Context-aware analysis understands code flow
- Configurable rules to match your security standards
Early Detection:
- Catches vulnerabilities before code review
- Prevents security issues from reaching production
- Reduces cost of fixing vulnerabilities (earlier is cheaper)
- Enables shift-left security practices
Package Dependency Scanning
Package dependency scanning identifies security vulnerabilities in third-party libraries and packages used by your project. It reads your manifests and lock files directly, so it works whether or not your CI runs an audit step.
What It Detects
Vulnerable Dependencies:
- Known CVE (Common Vulnerabilities and Exposures)
- Security advisories from package registries
- Exploitable vulnerabilities in dependencies
- Transitive dependency vulnerabilities (dependencies of dependencies)
Outdated Dependencies:
- Dependencies with available security patches
- End-of-life or unmaintained packages
- Deprecated packages with security concerns
Supported Languages and Package Managers
| Language | Package Manager | Manifests and Lock Files |
|---|---|---|
| JavaScript / TypeScript | npm, Yarn, pnpm | package-lock.json, yarn.lock, pnpm-lock.yaml, package.json |
| Python | pip, Poetry, Pipenv | poetry.lock, Pipfile.lock, requirements.txt |
| Ruby | Bundler | Gemfile.lock |
| Java | Maven, Gradle | pom.xml, build.gradle |
| Kotlin | Gradle | build.gradle, build.gradle.kts |
| Scala | sbt | build.sbt |
| Go | Go modules | go.mod, go.sum |
| PHP | Composer | composer.lock, composer.json |
| C# / .NET | NuGet | packages.lock.json, *.csproj, packages.config, Directory.Packages.props |
| Rust | Cargo | Cargo.lock, Cargo.toml |
| Swift | Swift Package Manager | Package.resolved |
| Dart / Flutter | pub | pubspec.lock |
| Elixir | Hex | mix.lock |
How It Works
- Manifest Discovery: Walks the repository for the files listed above, including nested projects in a monorepo
- Dependency Resolution: Parses each file into a pinned set of packages and versions, separating direct from transitive and production from development dependencies
- Vulnerability Matching: Queries the OSV database per ecosystem — npm, PyPI, RubyGems, Maven, Go, Packagist, NuGet, crates.io, SwiftURL, Pub, and Hex
- Impact Assessment: Evaluates severity and exploitability
- Fix Recommendations: Suggests specific version upgrades to resolve issues
- Pull Request Comments: Reports findings directly on the PR/MR
CI log parsing (supplementary). Where your pipeline already runs an audit
step, Codity also reads its output to pick up findings the manifests alone
would not show. This path covers npm audit, yarn audit, pip-audit, Maven,
Gradle, bundler-audit and Go, and it supplements the manifest scan rather than
replacing it.
Vulnerability Database Sources
Codity's dependency scanning uses data from:
- National Vulnerability Database (NVD)
- GitHub Security Advisories
- npm Security Advisories
- PyPI Security Advisories
- RubySec Advisory Database
- RustSec Advisory Database
- OSV (Open Source Vulnerabilities)
Business Benefits
Cost Savings:
- 10-100x cheaper to fix vulnerabilities early vs. production
- Reduced security incident costs
- Faster security review process
Time Savings:
- Automated scanning replaces manual security reviews
- Immediate feedback (no waiting for security team)
- Faster development cycles
- Reduced back-and-forth on security issues
Risk Reduction:
- Lower probability of breaches
- Reduced legal liability
- Better security reputation
Developer Experience
Seamless Integration:
- Works with existing workflows
- No additional tools to learn
- Clear, actionable feedback
- Fix suggestions with code examples
Learning and Growth:
- Developers learn secure coding patterns
- Immediate feedback loop
- References to security standards (CWE, OWASP)
- Builds security awareness
License Compliance Scanning
License compliance scanning analyzes your project's dependencies to identify license risks, copyleft obligations, and compliance issues.
How to Trigger
Comment /license-scan on any PR/MR to trigger a license compliance scan.
Supported Platforms:
- GitHub
- GitLab
- Azure DevOps
- Bitbucket
What It Detects
License Risk Classification:
- High Risk: Strong copyleft licenses (GPL-2.0, GPL-3.0, AGPL-3.0, SSPL-1.0, OSL) and proprietary/commercial licenses
- Medium Risk: Weak copyleft licenses (LGPL, MPL, EPL, EUPL, CDDL, CPL)
- Low Risk: Permissive licenses (MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC, Unlicense, CC0-1.0, Zlib, PostgreSQL, Python-2.0, and others)
- Unknown: Licenses that cannot be identified
Copyleft Detection:
- Identifies strong copyleft licenses (GPL, AGPL, OSL, SSPL) that require derivative works to use the same license
- Identifies weak copyleft licenses (LGPL, MPL, EPL, EUPL, CDDL) that have limited copyleft scope
- Detects FOSS exceptions (classpath-exception, gcc-exception) that reduce copyleft restrictions
OSI Approval Status:
- Reports whether each license is OSI (Open Source Initiative) approved
Supported Languages and Lock Files
| Language | Files Used |
|---|---|
| JavaScript / TypeScript | package-lock.json, yarn.lock, package.json |
| Python | poetry.lock, Pipfile.lock, requirements.txt |
| Ruby | Gemfile.lock |
| Java / Kotlin | pom.xml, build.gradle |
| Go | go.mod |
| PHP | composer.lock, composer.json |
| C# / .NET | packages.lock.json, *.csproj, packages.config, Directory.Packages.props |
License scanning covers a narrower set than dependency scanning: Rust, Swift, Dart, Elixir and Scala are scanned for vulnerabilities but not yet for license compliance.
Scan Results
Each scan result includes:
- Total packages scanned
- Risk breakdown (high, medium, low, unknown counts)
- Copyleft package count
- Compliance status
- Per-package details: package name, version, license ID, SPDX ID, risk level, copyleft status, and OSI approval
Salesforce
Salesforce projects get additional checks on every pull request, as part of the normal security scan.
What Runs on Every Pull Request
- PMD rules for Apex and Visualforce
- Curated rules for Lightning Web Components and Aura
- Vulnerable JavaScript libraries in static resources
- An Apex-aware security review covering CRUD/FLS, sharing,
@AuraEnabledand@RestResourceentry points, and guest-user context
Metadata Checks
Changes to Salesforce metadata are checked as well:
- Permission sets and profiles, and guest-user exposure
- Org-wide defaults and sharing rules
- CSP and remote sites
- Named credentials, connected apps, SAML, org security settings and certificates
destructiveChanges, Flows, and Agentforce agents and prompt templates
Permission, sharing and settings rules report only changes that loosen security. Settings that were already in place are not reported.
Guest Reachability
Codity flags concrete paths from a guest profile to an Apex class declared without sharing.
Deep Apex Analysis on Request
Comment on a pull request:
/security-scan --deep-apex
This adds Salesforce Graph Engine data-flow (taint) analysis. Its results are merged with those of the fast scan that runs on every pull request.
Supported Platforms:
- GitHub
- GitLab
- Azure DevOps
- Bitbucket
In the PR Comment
Salesforce findings get their own grouped section in the PR comment, including in Concise Mode.
Customizing Security Rules
Commit a .codity/security-rules.yaml (or .codity/security-rules.yml) file to the repository to tune what the security scan reports:
disabled_rules:
- ApexCRUDViolation
severity_overrides:
ApexSOQLInjection: critical
path_ignores:
- "*Test.cls"
- "test/fixtures/*"
| Key | What it does |
|---|---|
disabled_rules |
Drops findings by rule ID. |
severity_overrides |
Maps a rule ID to critical, high, medium or low. |
path_ignores |
Ignores paths that match shell-style globs (fnmatch). |
Rule IDs match case-insensitively and punctuation is ignored, so PMD names (ApexCRUDViolation) and ESLint-style names (@lwc/lwc/no-inner-html) both work as written.
The file applies to pull request security scans, including the scan that runs automatically after a review. There is no dashboard setting for it yet.
Additional Resources
- OWASP Top 10: https://owasp.org/www-project-top-ten/
- CWE Database: https://cwe.mitre.org/
- CVE Database: https://cve.mitre.org/
- NIST NVD: https://nvd.nist.gov/

