CyfroCode

CyfroCode

Connect GitHub, queue scans, review findings by severity, generate AI patches, and export fixes as pull requests.

CyfroCode provides a comprehensive SAST code-security workspace embedded directly within CyfroSec. Designed for developers and security teams alike, it allows you to connect your code repositories, automatically run security scans, and generate actionable remediation patches, all without leaving the platform.

CyfroCode supports 7 programming languages for SAST code-security scanning, plus 5 infrastructure/configuration surfaces, dead-code detection, and Logic Map / Mind Map views for understanding architecture faster.

CyfroCode overview showing security posture, risk score, severity mix, and a 14-day findings trendThe CyfroCode overview: posture headline, risk score, severity mix, and a stacked findings trend across repositories.

Programming Languages

LanguageExtensions
Python.py
JavaScript.js
TypeScript.ts
Java.java
Go.go
C#.cs
C++.cpp, .cc, .hpp

Infrastructure / Configuration Surfaces

  1. Container (Dockerfile)
  2. Terraform (IaC)
  3. Kubernetes (manifests)
  4. YAML (generic config)
  5. CI (GitHub Actions workflows)

In This Section

The CyfroCode guide is split into focused pages so you can jump straight to the task at hand:

  1. Connecting GitHub & Repositories — install the GitHub App and manage your synced repositories.
  2. Running Scans & Scan Tabs — queue scans and understand the scan detail tabs.
  3. Findings & AI Patches — triage findings, read AI explanations, and generate remediation patches.
  4. Logic Map & Mind Map — explore code relationships and API endpoint trees.
  5. Code Health, SBOM & Intent — review dead code, dependency inventory, and architecture intent.