Sign inSign up

mohdmusheer/codeshield-ai

By mohdmusheer

β€’Updated about 2 months ago

CodeShield AI is a state-of-the-art, enterprise-quality codebase security analyzer.

Image
Networking
Security
Machine learning & AI
0

2.4K

mohdmusheer/codeshield-ai repository overview

⁠CodeShield AI πŸ›‘οΈ

CI Pipeline Security Scan Apache 2.0 License Docker Support

CodeShield AI is a state-of-the-art, enterprise-quality codebase security analyzer. It automates remote repository cloning, dependency mapping, code structural analysis, and leverages Groq's Large Language Models (LLMs) alongside static scanners to detect, score, and automatically remediate vulnerabilities.


β πŸ› οΈ Architecture

               β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
               β”‚              Web Dashboard / CLI              β”‚
               β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                      β”‚
                                      β–Ό
               β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
               β”‚           FastAPI Web API Endpoints           β”‚
               β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                      β”‚
                                      β–Ό
               β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
               β”‚      ScanStateManager (Disk Persistence)      β”‚
               β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                      β”‚
                                      β–Ό
               β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
               β”‚     PipelineManager (Background Worker)       β”‚
               β””β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”˜
                 β”‚                  β”‚                      β”‚
                 β–Ό                  β–Ό                      β–Ό
        β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
        β”‚  GitHub/GitLab β”‚ β”‚ Code Chunker & β”‚ β”‚ Static Regex & β”‚
        β”‚ Cloner Service β”‚ β”‚ Compatible     β”‚ β”‚ LLM Semantic   β”‚
        β”‚                β”‚ β”‚ Merger (Groq)  β”‚ β”‚ Scanner        β”‚
        β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

β πŸš€ Key Features

  • Multi-Source Code Loading: Scan remote public GitHub/GitLab repositories, local directories, or ZIP archive uploads with drag-and-drop.
  • Smart Chunk Grouping: Groups compatible code segments by file into unified prompts (up to 15,000 characters) to optimize Groq LLM context windows, bypass HTTP 429 rate limits, and run scans in under 10 seconds.
  • Disk-Backed State Machine: Remembers scan progress across server restarts and connection interruptions.
  • Interactive Code Modals: Provides full code highlighting alongside side-by-side vulnerable vs. remediated code views.
  • Unified Diff Patches: Generates drop-in .diff patches and pre-formated AI prompt logs (fix_prompt.json, .md, .txt) to fix codebase security flaws.
  • Multi-Format Reports: Downloader supports SARIF, CSV, JSON, Markdown, HTML, and Mock PDF formats.

⁠🐳 Docker Deployment

Launch the full container stack (including mounted volumes for logs and reports):

# Provide your GROQ API Key in the shell environment or in .env
export GROQ_API_KEY="your_groq_api_key"

# Build and start services
docker-compose up --build -d

Access the application at http://localhost:8000.

⁠2. Manual Docker Build

Build and run the container locally in detached mode (-d), specifying your GROQ_API_KEY and GROQ_MODEL configuration:

# Build the Docker image
docker build -t codeshield-ai .

# Run the container in detached mode
docker run -d -p 8000:8000 -e GROQ_API_KEY="your_groq_api_key_here" -e GROQ_MODEL="llama-3.3-70b-versatile" codeshield-ai
⁠3. Pull Published Release Image

CodeShield AI automatically publishes container builds to GitHub Container Registry (GHCR) on tagged releases. Pull and run the official image:

# Pull the latest image
docker pull ghcr.io/mohd-musheer/codeshield-ai:latest

# Run the container in detached mode
docker run -d -p 8000:8000 -e GROQ_API_KEY="your_groq_api_key_here" -e GROQ_MODEL="llama-3.3-70b-versatile" ghcr.io/mohd-musheer/codeshield-ai:latest

β πŸ’» Local Installation (Development)

  1. Clone the Repository:

    git clone https://github.com/mohd-musheer/CodeShield-AI.git
    cd CodeShield-AI
    
  2. Configure Environment Settings: Copy .env.example to .env:

    cp .env.example .env
    

    Edit .env and paste your GROQ_API_KEY.

  3. Start the Production Service: Run the quick-start script:

    • Linux / macOS:
      chmod +x start.sh
      ./start.sh
      
    • Windows (PowerShell):
      .\start.ps1
      

β πŸ“˜ API Documentation

CodeShield AI exposes REST endpoints for integration:

MethodEndpointDescription
POST/repository/analyzeTriggers background codebase security scans.
POST/repository/uploadUploads a ZIP codebase archive for parsing.
POST/repository/cancel/{scan_id}Aborts a running scan and cleans up disk cache.
GET/scan/status/{scan_id}Retrieves active progress metrics and current stage.
GET/repository/reportDownloads report in json, html, markdown, sarif, csv, pdf, patch_diff, or fix_prompt.
GET/healthServer status and API liveness metrics.

⁠⚑ Performance Benchmarks

Project SizeTotal ChunksMerged Groq CallsTotal Scan Duration
Small (1-50 Files)3-1012-4 seconds
Medium (50-200 Files)30-803-56-9 seconds
Large (200+ Files)200+12-1515-20 seconds

β πŸ—ΊοΈ Roadmap

  • Support private repositories via SSH Keys and Git Credential Helper.
  • Add native Semgrep rules integration alongside Groq semantic scans.
  • Implement multi-tenant users management and workspace segregation.
  • Provide slack and webhook notification alerts on completed scans.

β πŸ“œ License

Distributed under the Apache 2.0 License. See LICENSE⁠ for details.

Tag summary

Content type

Image

Digest

sha256:840d89057…

Size

89.8 MB

Last updated

about 2 months ago

docker pull mohdmusheer/codeshield-ai