Amazon CodeGuru Security logo

Amazon CodeGuru Security

Amazon CodeGuru Security is a static application security testing (SAST) service that uses machine learning to detect security vulnerabilities in your code. It identifies vulnerabilities such as injection flaws, data exposure risks, and infrastructure-as-code misconfigurations, and provides actionable remediation guidance to help developers fix security issues quickly.

1 APIs 1 Capabilities 5 Features
AmazonAWSSecuritySASTCode AnalysisDevSecOpsDeveloper Tools

APIs

Amazon CodeGuru Security API

The Amazon CodeGuru Security REST API.

Capabilities

Amazon CodeGuru Security Application Security Scanning

Unified workflow for security and DevOps teams to create security scans, retrieve findings, track vulnerabilities by severity, and manage remediation using Amazon CodeGuru Secur...

Run with Naftiko

Features

Static Application Security Testing

Analyze source code for security vulnerabilities without running the application using machine learning-powered SAST.

Multi-Language Support

Detect security issues in Java, Python, JavaScript, TypeScript, C, C++, C#, Go, Ruby, and Kotlin code.

Infrastructure-as-Code Scanning

Detect security misconfigurations in CloudFormation, Terraform, CDK, and other IaC templates.

Severity Classification

Classify findings by severity (Critical, High, Medium, Low, Informational) to help prioritize remediation.

Remediation Guidance

Provide detailed remediation recommendations including suggested code fixes for each identified vulnerability.

Use Cases

DevSecOps Integration

Integrate security scanning into CI/CD pipelines to detect vulnerabilities before code reaches production.

Security Audit and Compliance

Run security scans on existing codebases to identify and remediate vulnerabilities for compliance audits.

IaC Security Validation

Scan infrastructure-as-code templates for security misconfigurations before provisioning cloud resources.

Integrations

AWS CodeBuild

Run security scans as part of CodeBuild build projects for CI/CD integration.

GitHub Actions

Add CodeGuru Security scanning to GitHub Actions workflows.

AWS Security Hub

Send security findings to Security Hub for centralized security management.

Amazon S3

Store and retrieve code bundles for security scanning from S3.

Semantic Vocabularies

Amazon Codeguru Security Context

49 classes · 70 properties

JSON-LD

API Governance Rules

Amazon CodeGuru Security API Rules

10 rules · 5 errors 4 warnings 1 info

SPECTRAL

Resources

🚀
GettingStarted
GettingStarted
💰
Pricing
Pricing
🌐
Console
Console
🌐
Portal
Portal
🔗
Documentation
Documentation
📜
TermsOfService
TermsOfService
📜
PrivacyPolicy
PrivacyPolicy
🟢
StatusPage
StatusPage
📰
Blog
Blog
📝
SignUp
SignUp
👥
GitHubOrganization
GitHubOrganization
🔗
SpectralRules
SpectralRules
🔗
Vocabulary
Vocabulary
🔗
NaftikoCapability
NaftikoCapability
🔗
JSONLD
JSONLD