Documentation
From install to first verified pull request
Most teams connect a repository, add the workflow and merge their first remediation within an hour. This guide covers the full path.
Quickstart
1. Install the GitHub App
From your workspace, choose Connect repository and install the CodeArmor GitHub App on the organization. Select the repositories to audit; you can change this at any time.
2. Add the workflow
Commit the workflow below to run an incremental audit on every pull request. Store your API key as the CODEARMOR_API_KEY repository secret.
.github/workflows/codearmor.ymlyaml1name: CodeArmor Audit2on: [pull_request]34jobs:5 audit:6 runs-on: ubuntu-latest7 permissions:8 contents: read9 pull-requests: write10 steps:11 - uses: actions/checkout@v412 - uses: codearmor-ai/audit-action@v113 with:14 api-key: ${{ secrets.CODEARMOR_API_KEY }}15 fail-on: critical,high16 auto-remediate: true3. Run the first full audit
Open the repository in your workspace and press Scan. The first audit builds the dependency graph and primes the prompt cache, so it takes a few minutes; later audits are incremental.
4. Review and merge remediation PRs
Each verified finding includes an explanation, a side-by-side diff and generated tests that already passed in the sandbox. Review the pull request like any other and merge when satisfied.
Configuration
Policies live in a codearmor.yml file at the repository root. Organization-wide defaults can be set from workspace settings and overridden per repository.
1# codearmor.yml (repository root)2version: 23audit:4 fail-on: [critical, high]5 auto-remediate: true6 ignore:7 - "**/generated/**"8 - "**/*.pb.ts"9architecture:10 layers:11 - name: controllers12 path: "src/controllers/**"13 may-import: [services]14 - name: services15 path: "src/services/**"16 may-import: [repositories, domain]17 - name: repositories18 path: "src/repositories/**"19 may-import: [infra]20notifications:21 slack: "#security-findings"22 pagerduty:23 severity: [critical]| Key | Description |
|---|---|
| audit.fail-on | Severities that fail the CI check. Any of critical, high, medium, low. |
| audit.auto-remediate | Open a verified remediation pull request for each confirmed finding. |
| audit.ignore | Glob patterns excluded from analysis, for example generated code. |
| architecture.layers | Named layers with allowed import targets. Violations become drift findings. |
| notifications | Slack channel, Jira or Linear project and PagerDuty severity routing. |
CLI
The CLI runs the same audit engine from a developer machine or any CI provider. It is useful for pre-commit checks and for providers without a native integration.
# Authenticate once per machinenpx @codearmor/cli login# Audit the current repository and open findings in the terminalnpx @codearmor/cli audit --repo . --fail-on high# Generate a remediation PR for a specific findingnpx @codearmor/cli fix CA-2041 --open-prSupported languages
Detection covers every language in the repository. Data-flow tracing and autonomous remediation are available for the languages below; the rest receive detection and explanation without automatic patches.
| Language | Data-flow tracing | Auto-remediation |
|---|---|---|
| TypeScript / JavaScript | Supported | Supported |
| Python | Supported | Supported |
| Go | Supported | Supported |
| Java / Kotlin | Supported | Supported |
| Rust | Supported | Supported |
| Ruby | Supported | Supported |
| C# / .NET | Supported | Detection only |
| PHP | Supported | Detection only |
| Terraform / HCL | Detection only | Detection only |
API & webhooks
Everything in the workspace is available through the REST API. Webhooks deliver signed events for new findings, opened pull requests and merges so you can build custom routing.
curl https://api.codearmor.site/v1/repositories/acme-corp/payment-gateway/findings \ -H "Authorization: Bearer $CODEARMOR_API_KEY" \ -H "Accept: application/json"Need something that is not covered here? Email admin@codearmor.site and a solutions engineer will help.