Skip to content

CodeArmor 2.6 adds policy-as-code architecture rules and GitLab merge request audits

Read the changelog
CodeArmor AI

Documentation

From install to first verified pull request

Most teams connect a repository, add the workflow and merge their first remediation within an hour. This guide covers the full path.

Quickstart

  1. 1. Install the GitHub App

    From your workspace, choose Connect repository and install the CodeArmor GitHub App on the organization. Select the repositories to audit; you can change this at any time.

  2. 2. Add the workflow

    Commit the workflow below to run an incremental audit on every pull request. Store your API key as the CODEARMOR_API_KEY repository secret.

    .github/workflows/codearmor.ymlyaml
    1name: CodeArmor Audit
    2on: [pull_request]
    3
    4jobs:
    5 audit:
    6 runs-on: ubuntu-latest
    7 permissions:
    8 contents: read
    9 pull-requests: write
    10 steps:
    11 - uses: actions/checkout@v4
    12 - uses: codearmor-ai/audit-action@v1
    13 with:
    14 api-key: ${{ secrets.CODEARMOR_API_KEY }}
    15 fail-on: critical,high
    16 auto-remediate: true
  3. 3. Run the first full audit

    Open the repository in your workspace and press Scan. The first audit builds the dependency graph and primes the prompt cache, so it takes a few minutes; later audits are incremental.

  4. 4. Review and merge remediation PRs

    Each verified finding includes an explanation, a side-by-side diff and generated tests that already passed in the sandbox. Review the pull request like any other and merge when satisfied.

Configuration

Policies live in a codearmor.yml file at the repository root. Organization-wide defaults can be set from workspace settings and overridden per repository.

codearmor.ymlyaml
1# codearmor.yml (repository root)
2version: 2
3audit:
4 fail-on: [critical, high]
5 auto-remediate: true
6 ignore:
7 - "**/generated/**"
8 - "**/*.pb.ts"
9architecture:
10 layers:
11 - name: controllers
12 path: "src/controllers/**"
13 may-import: [services]
14 - name: services
15 path: "src/services/**"
16 may-import: [repositories, domain]
17 - name: repositories
18 path: "src/repositories/**"
19 may-import: [infra]
20notifications:
21 slack: "#security-findings"
22 pagerduty:
23 severity: [critical]
KeyDescription
audit.fail-onSeverities that fail the CI check. Any of critical, high, medium, low.
audit.auto-remediateOpen a verified remediation pull request for each confirmed finding.
audit.ignoreGlob patterns excluded from analysis, for example generated code.
architecture.layersNamed layers with allowed import targets. Violations become drift findings.
notificationsSlack channel, Jira or Linear project and PagerDuty severity routing.

CLI

The CLI runs the same audit engine from a developer machine or any CI provider. It is useful for pre-commit checks and for providers without a native integration.

terminalyaml
# Authenticate once per machine
npx @codearmor/cli login
# Audit the current repository and open findings in the terminal
npx @codearmor/cli audit --repo . --fail-on high
# Generate a remediation PR for a specific finding
npx @codearmor/cli fix CA-2041 --open-pr

Supported languages

Detection covers every language in the repository. Data-flow tracing and autonomous remediation are available for the languages below; the rest receive detection and explanation without automatic patches.

LanguageData-flow tracingAuto-remediation
TypeScript / JavaScriptSupportedSupported
PythonSupportedSupported
GoSupportedSupported
Java / KotlinSupportedSupported
RustSupportedSupported
RubySupportedSupported
C# / .NETSupportedDetection only
PHPSupportedDetection only
Terraform / HCLDetection onlyDetection only

API & webhooks

Everything in the workspace is available through the REST API. Webhooks deliver signed events for new findings, opened pull requests and merges so you can build custom routing.

terminalyaml
curl https://api.codearmor.site/v1/repositories/acme-corp/payment-gateway/findings \
-H "Authorization: Bearer $CODEARMOR_API_KEY" \
-H "Accept: application/json"

Need something that is not covered here? Email admin@codearmor.site and a solutions engineer will help.