Skip to content

Latest commit

 

History

History
211 lines (166 loc) · 10.6 KB

File metadata and controls

211 lines (166 loc) · 10.6 KB

Code Security reference

Supported languages and ecosystems

Dependencies (SCA)

Language Ecosystems and files
JavaScript / TypeScript npm, yarn, pnpm, bun
Python pip, Poetry, Pipenv, uv, Conda
Go Go modules, Go binaries
Rust Cargo, Rust binaries
Java / JVM Maven, Gradle, JAR files, sbt
Ruby Bundler, gemspec
PHP Composer
.NET NuGet, packages.props, .NET Core deps
Swift / Objective-C Swift Package Manager, CocoaPods
Containers OS packages in container images

Development dependencies are included and marked as such. The SBOM is CycloneDX. Maven parent POMs are not resolved, because scans run without access to package registries.

For Go and Rust, dependency findings also say whether the vulnerable code is imported, and for some advisories whether the vulnerable function is called.

Static analysis (SAST)

LimaCharlie's default code rules cover JavaScript and TypeScript, Python, Go, Java, C#, Ruby and Rust, and are mapped to CWE. Rules you write can target any language the engine supports.

Static analysis runs exactly the organization's enabled code rules. The policy's sast_ruleset is deprecated and ignored.

A low-confidence static-analysis finding is recorded as INFO.

Infrastructure as code

Terraform, CloudFormation, Kubernetes manifests, Helm charts and Dockerfiles.

Secrets

Credentials in the working tree, and in the full git history when secrets_history is on. On GitHub, a secret finding also carries GitHub's own verdict on whether the credential is still live, when GitHub has one.

End-of-life runtimes

Python, Node.js, Go, Java, Ruby, PHP and .NET, read from files such as .nvmrc, .python-version, .ruby-version, go.mod, pom.xml, build.gradle and global.json. Also nginx, Debian, Ubuntu and Alpine base images.

AutoFix

npm (including yarn and pnpm projects), pip, Go modules and Maven. See AutoFix pull requests.

Limits

Free tier

Limit Value
Repositories scanned The first 10 by name, per connected source-control organization
Container images scanned The 5 most referenced, per organization

Repositories and images held back by these limits report free_tier_code_repos_cap or free_tier_code_images_cap. The covered set does not rotate, so findings do not appear and disappear between passes.

All plans

Limit Value
Scan duration 30 minutes per repository, including about 20 minutes of scanning
Repository download 4 GiB. A larger repository fails with source_too_large
Container image size 1 GiB compressed
File size read by static analysis 1 MiB (larger files are counted, not read)
Enabled code rules per organization 5,000 rules and 20 MB
Report size 20 MiB compressed
Container images per pass 50
Triggered scans (pushes and rescans) per repository 50 per day
Pull-request writes per connection 500 per day
AutoFix pull requests per connection 20 per day
Pushed document size 20 MiB

When a limit cuts a scan short, the repository reports scan_status: partial and lists the limit in scan_limits. A partial scan never closes findings it did not get to check again. Files skipped by the static-analysis size limit are counted, but do not make the scan partial.

Status and reason codes

Repository scan_status

scan_status scan_status_reason Meaning
scanned The last scan completed.
partial A limit or unavailable engine cut the scan short. The limits are listed in scan_limits, for example sast_no_rules when no code rule is enabled. See When rules cannot run for the static-analysis reasons.
unknown repo_not_scanned Not scanned yet.
unknown repo_archived Archived repositories are not scanned.
unknown free_tier_code_repos_cap Outside the free-tier repository limit.

repo_archived and free_tier_code_repos_cap can also appear on a scanned repository that was scanned before it was archived or held back. Its last results are kept.

SBOM

Reason Meaning
sbom_not_generated_yet No scan has completed yet. Try again later.
no_sbom_for_this_repository The scan found no dependency manifest. This is permanent for repositories without dependencies.
code_lane_not_enabled_in_datacenter Code Security is not available in this data region.

Scan errors on code status

Code Meaning
github_app_missing_contents_permission The GitHub App lacks Contents: Read-only, so nothing could be downloaded.
gitlab_token_missing_read_repository, bitbucket_token_missing_read_repository The connection's token cannot clone repositories.
gitlab_token_inactive The GitLab token is revoked or expired.
source_too_large The repository is over the 4 GiB download limit.
job_timeout The scan ran past its time limit.
fetch_failed The repository could not be downloaded.
mirror_stale The vulnerability database mirror was out of date, so the scan did not run.

Events

Code Security emits these operational events into the organization's event stream. They are off by default. Turn them on with ops_events: true in the emission policy.

Event When
cloudsec.code_scan_completed A repository or image scan finished.
cloudsec.code_scan_failed A repository or image scan failed.
cloudsec.code_pr_check_completed A pull-request check was published.
cloudsec.code_pr_check_failed A pull-request check could not be completed.
cloudsec.code_autofix_opened An AutoFix pull request was opened.
cloudsec.code_autofix_refused An AutoFix request did not produce a pull request.
cloudsec.code_scan_closure_held A scan would have closed a large share of a repository's findings, so closing waits for a second scan.
cloudsec.code_scan_claim_refused One engine's result could not be trusted, so that engine's findings were left unchanged.

Code findings themselves emit the standard cloud_finding.* events, which are on by default. See Events.

API routes

All routes are under https://api.limacharlie.io/v1/cloudsec/{oid}. Reads need cloudsec.get and writes need cloudsec.set. The exceptions: AutoFix and remediation requests and decisions need cloudsec.respond, a runtime check (POST) needs only cloudsec.get, and the map status read (GET /code/iac-map/status) needs cloudsec.set. See the table below. The organization must be subscribed to ext-cloud-security.

Route CLI Purpose
GET /code/repos code repos Repositories with scan status and open-finding counts. Params: q, has_findings, provider, cursor, limit.
GET /code/status code status Run status per connection.
GET /code/capabilities code capabilities What enabled source-control workflow connections can do, and their webhook status. Optional repo.
GET /code/fixes code fixes Open dependency findings grouped by the upgrade that fixes them.
GET /code/sbom code sbom A short-lived download link for one repository's SBOM. Params: repo (required, <owner>/<name> as /code/repos returns it), provider.
GET /code/images, GET /code/images/{digest} image list, image get Container images and one image's detail.
GET /code/image-repos, GET /code/image-repos/facets image repos, image repo-facets Image repositories and their filter counts.
POST /code/scan code rescan Rescan one repository. Body: {repo, ref?, provider?}.
POST /code/autofix code autofix Open an AutoFix pull request as a remediation run. Needs cloudsec.respond. Body: {finding_id, repo?}.
POST /code/ingest code ingest Push SARIF, CycloneDX or a scanner report.
POST /code/pr_check code pr-check Check a pull request. Used by the webhook rules.
POST /code/webhook code webhook Point a GitHub App's webhook at LimaCharlie. See the webhook API.

Image reads accept repeatable lineage_status values: verified, asserted, inferred, ambiguous, unknown. Filtering is server-side; a stale lineage decision counts as unknown immediately. Image-repository facets can request lineage_facet=true for digest-level counts under lineage_statuses; repository placement filters do not narrow those lineage counts. An older server that cannot apply the filter refuses it instead of returning an unfiltered page. See image lineage for what each status proves.

Findings are read with the standard findings routes, filtered by repo.

Evidence, lineage and remediation routes. See Configure evidence, lineage and remediation for the setup, and Unknown, partial and refusal reasons for the codes they return.

Route Permission Purpose
GET /findings/{finding_id}/evidence-chain cloudsec.get The finding's evidence chain. Optional runtime=true.
POST /findings/{finding_id}/runtime-check cloudsec.get Check whether the finding's package was seen running. Reads only.
GET /code/coverage cloudsec.get Coverage lines with their denominators.
GET /code/impact cloudsec.get Live impact of a commit (repo_urn, commit) or a finding (finding_id).
GET /code/provenance, POST /code/provenance cloudsec.get, cloudsec.set List or push build provenance.
POST /code/iac-map, GET /code/iac-map/status cloudsec.set Push a Terraform map, and read its publication status.
POST /findings/{finding_id}/remediations cloudsec.respond Request a remediation run. Body: {action, idempotency_key}.
GET /remediations, GET /remediations/{run_id} cloudsec.get List runs, or read one run with its steps.
POST /remediations/{run_id}/approve, reject, cancel cloudsec.respond Decide a run.

Not available yet

  • Scanning images from container registries. image_sources: ["registries"] is accepted but does nothing yet.
  • GitLab and Bitbucket workflows without the corresponding server capability. Support depends on rollout in your data region. Read code capabilities; scheduled repository scans do not imply webhook, check or AutoFix support.
  • Scanning self-managed GitLab instances. They can be connected for inventory.
  • Bitbucket Data Center (self-hosted).