Use case

Prove and fix scanner findings with Codna

Your scanner reports fifty findings. codna secure proves which are reachable, for zero model tokens, and the GitHub App comments the result on the issue or alert.

The problem

A scanner finding is a claim. Reachability is the proof.

codna secure ingests a SARIF 2.1.0 report from CodeQL, Semgrep, Snyk or Trivy and classifies each finding against the repository's dependency graph. Read-only, no model call. The local engine never claims a finding is exploitable; it says production-reachable, unreachable or unknown.

How Codna fixes it

How Codna secures it

1

Ingest the SARIF

codna secure . --from-sarif results.sarif. The report needs a full commit SHA and the scanner name and version.

2

Prove reachability

Each finding is classified against the graph for zero model tokens. Labels: production-reachable, unreachable or unknown.

3

Act on the result

On GitHub, the codna-secure label or a code-scanning alert runs the same read-only classification and comments the result. Remediation, where available, opens one draft pull request per verified finding after nine gates, through a separate writer step that holds the only write token.

codna secure . --from-sarif results.sarif
# in CI: thyn-ai/codna-action@v1 with mode: secure

What you get

What you get

Zero model tokens

Classification is deterministic. Nothing is sent to a model.

Scanner-agnostic

Any SARIF 2.1.0 report: CodeQL, Semgrep, Snyk, Trivy.

GitHub App triggers

The codna-secure label on an issue, or a code-scanning alert, runs the classification and comments the result.

The proof

Fewer tokens. Faster. Verified.

Codna16K
Cursor81K
Average tokens per fix on 87 matched bug-fix cases: Codna and Cursor.

Frequently asked

Prove it first. codna secure classifies the finding as production-reachable, unreachable or unknown for zero tokens. Then run codna fix with the finding as the issue and let your tests verify the patch.

codna secure proves whether the vulnerable path is reachable from your code. For the upgrade itself, run codna fix with the failing build as the issue and let your tests verify.

Neither. Codna does not scan. It reads your scanner's SARIF and proves reachability, read-only, for zero model tokens.

No. The local engine never claims a finding is exploitable. It classifies reachability so you can prioritise and fix.

Any fix Codna opens reports blast radius and regression risk and passes a risk gate first. Remediation from secure, where available, opens one draft pull request per verified finding after nine gates. Codna never merges.

Classification is read-only and makes no model call. Understanding runs on your machine and spends no tokens. Only the evidence bundle or the diff reaches your model provider, with your key from the OS keychain. Set privacy.egress to fail-closed in codna.yaml and Codna runs your tests only under kernel-level network denial. Secret redaction is always on.

Understand. Fix. Evolve.