Ingest the SARIF
codna secure . --from-sarif results.sarif. The report needs a full commit SHA and the scanner name and version.
Your scanner reports fifty findings. codna secure proves which are reachable, for zero model tokens, and the GitHub App comments the result on the issue or alert.
The problem
codna secure ingests a SARIF 2.1.0 report from CodeQL, Semgrep, Snyk or Trivy and classifies each finding against the repository's dependency graph. Read-only, no model call. The local engine never claims a finding is exploitable; it says production-reachable, unreachable or unknown.
How Codna fixes it
codna secure . --from-sarif results.sarif. The report needs a full commit SHA and the scanner name and version.
Each finding is classified against the graph for zero model tokens. Labels: production-reachable, unreachable or unknown.
On GitHub, the codna-secure label or a code-scanning alert runs the same read-only classification and comments the result. Remediation, where available, opens one draft pull request per verified finding after nine gates, through a separate writer step that holds the only write token.
codna secure . --from-sarif results.sarif # in CI: thyn-ai/codna-action@v1 with mode: secure
What you get
Classification is deterministic. Nothing is sent to a model.
Any SARIF 2.1.0 report: CodeQL, Semgrep, Snyk, Trivy.
The codna-secure label on an issue, or a code-scanning alert, runs the classification and comments the result.
The proof
Prove it first. codna secure classifies the finding as production-reachable, unreachable or unknown for zero tokens. Then run codna fix with the finding as the issue and let your tests verify the patch.
codna secure proves whether the vulnerable path is reachable from your code. For the upgrade itself, run codna fix with the failing build as the issue and let your tests verify.
Neither. Codna does not scan. It reads your scanner's SARIF and proves reachability, read-only, for zero model tokens.
No. The local engine never claims a finding is exploitable. It classifies reachability so you can prioritise and fix.
Any fix Codna opens reports blast radius and regression risk and passes a risk gate first. Remediation from secure, where available, opens one draft pull request per verified finding after nine gates. Codna never merges.
Classification is read-only and makes no model call. Understanding runs on your machine and spends no tokens. Only the evidence bundle or the diff reaches your model provider, with your key from the OS keychain. Set privacy.egress to fail-closed in codna.yaml and Codna runs your tests only under kernel-level network denial. Secret redaction is always on.
Related