CyfroCode provides a comprehensive SAST code-security workspace embedded directly within CyfroSec. Designed for developers and security teams alike, it allows you to connect your code repositories, automatically run security scans, and generate actionable remediation patches, all without leaving the platform.
CyfroCode supports 7 programming languages for SAST code-security scanning, plus 5 infrastructure/configuration surfaces, dead-code detection, and Logic Map / Mind Map views for understanding architecture faster.
Programming Languages
| Language | Extensions |
|---|---|
| Python | .py |
| JavaScript | .js |
| TypeScript | .ts |
| Java | .java |
| Go | .go |
| C# | .cs |
| C++ | .cpp |
Infrastructure / Configuration Surfaces
- Container (Dockerfile)
- Terraform (IaC)
- Kubernetes (manifests)
- YAML (generic config)
- CI (GitHub Actions workflows)
In This Section
CyfroCode documentation is split into focused guides so you can jump straight to the task you need:
- Connecting GitHub & Repositories — connect the GitHub App and manage synced repositories.
- Running Scans — queue scans and understand the scan detail tabs.
- Findings & AI Explanations — review findings, filters, and AI explanations.
- Logic Map — explore code relationships as an interactive graph.
- Mind Map — review API endpoints as a tree of cards.
- Code Health & Dead-Code Detection — surface dead code, duplicates, and maintenance signals.
- SBOM — inspect the full dependency inventory.
- Intent Analysis — compare intended architecture against what the scan found.
- Automated Patches — generate, review, and export AI remediation drafts.
