Skip to content

CodeArmor 2.6 adds policy-as-code architecture rules and GitLab merge request audits

Read the changelog
CodeArmor AI

Changelog

What shipped, release by release

CodeArmor ships every few weeks. Major releases are listed here; security fixes are communicated directly to affected workspaces.

  1. v2.6

    Policy-as-code architecture rules and GitLab audits

    Architecture rules can now be versioned alongside your code, and GitLab merge requests get the same continuous audit as GitHub pull requests.

    • newArchitecture rules v2: declare layer boundaries, allowed dependencies and ownership in codearmor.yml.
    • newGitLab merge request audits with inline discussions and pipeline gating, now generally available.
    • improvedDependency graph builder is 2.1x faster on monorepos above 500k lines.
    • fixedKotlin coroutine flows are no longer reported as unawaited promises.
  2. v2.5

    Private cloud deployments and SCIM

    Run CodeArmor entirely inside your own AWS or GCP account with provisioning managed by our control plane.

    • newPrivate cloud deployment for AWS and GCP, including regional data residency.
    • newSCIM 2.0 provisioning for Okta and Entra ID.
    • improvedAudit log export now streams to Splunk and Datadog in near real time.
  3. v2.4

    Claude Opus 5.5 reasoning engine

    Audits are faster and catch deeper multi-service exploit chains with the upgraded reasoning engine and 200k-token context.

    • improvedMedian audit time down 38 percent across all repository sizes.
    • improvedCross-service data-flow tracing now follows messages through Kafka, SQS and NATS.
    • fixedRemediation PRs no longer reformat untouched files when a repository uses Biome.
  4. v2.3

    Issue tracking and on-call integrations

    Findings flow into the tools your team already triages in.

    • newTwo-way sync with Jira and Linear, including status updates when a remediation PR merges.
    • newPagerDuty and Opsgenie alerts for critical findings on production branches.
    • improvedSlack digests can be scoped per team and per severity.
  5. v2.2

    SOC 2 Type II and audit log export

    Completed our first SOC 2 Type II observation period and shipped the compliance evidence features customers asked for.

    • newSOC 2 Type II report available under NDA from the trust page.
    • newExportable audit logs covering findings, patches, merges and configuration changes.
    • improvedCompliance mapping now covers CWE Top 25 and PCI DSS 4.0 requirement 6.
  6. v2.1

    Go and Rust data-flow tracing

    Full exploit-path tracing for Go and Rust services, plus incremental audits for monorepos.

    • newGo and Rust join TypeScript, Python, Java and Kotlin with complete data-flow tracing.
    • newIncremental audits analyze only the changed dependency subgraph on each pull request.
    • fixedLarge generated protobuf files are skipped instead of consuming the context window.
  7. v2.0

    Autonomous remediation pull requests

    CodeArmor now fixes what it finds. Every patch is executed against generated tests in an isolated sandbox before a pull request is opened.

    • newSandbox-verified remediation PRs with generated unit tests and a plain-language explanation.
    • newSide-by-side vulnerable versus remediated diff view in every finding.
    • improvedFindings include an exploit scenario written in the style of a senior AppSec review.
  8. v1.5

    Dependency graph explorer

    Visualize module boundaries, cycles and layer violations across the whole repository.

    • newInteractive dependency graph with cycle detection and ownership overlays.
    • newArchitecture drift findings for direct infrastructure access from presentation layers.
  9. v1.3

    Business-logic exploit detection

    The first release that goes beyond OWASP patterns to reason about what code is supposed to do.

    • newDetection for race conditions on monetary invariants, IDOR chains and price manipulation.
    • improvedSelf-verification pass writes a failing test before any finding is reported.
  10. v1.1

    GitHub Action with merge gating

    Run audits on every pull request and block merges on severity thresholds.

    • newcodearmor-ai/audit-action with inline review comments.
    • newConfigurable fail-on thresholds per repository.
  11. v1.0

    General availability

    CodeArmor launches with whole-repository security audits for TypeScript, Python and Java.

    • newFull-repository audits with OWASP Top 10 coverage and 200k-token context.
    • newGitHub App installation with organization-wide repository selection.