Getting started: install, scan, explain, fix

codafort analyses your code on your machine, with no network, in 16 languages. This guide takes you from install to the first fix in five minutes.

1. Install

Pick a path; all of them install the same binary.

Pre-launch: codafort is not available to install yet. Join the waitlist →

# macOS · Linux — detects the platform, checks SHA-256 (and minisign when available)
curl --proto '=https' --tlsv1.2 -fsSL https://codafort.dev/install.sh | sh

# npm — the native binary ships inside your platform's package
npm i -g codafort        # or, without installing: npx codafort scan .

# Homebrew
brew install codafort/tap/codafort

Windows (PowerShell), with the same verification:

irm https://codafort.dev/install.ps1 | iex

Or download the signed .zip from Download and check it by hand (see Supply chain). On Linux the binary needs glibc 2.28+ (Ubuntu 20.04, Debian 11, RHEL 8 or newer).

2. Scan

cd my-project
codafort scan .

scan uses the security-first profile: it shows the 10 most important findings, each with a session ID SF-n, the file:line and one plain-language sentence about what can go wrong. Only confirmed findings show up.

The session lives in .codafort/session.json. It is what lets you run explain and fix without analysing again.

3. Explain

codafort explain SF-1

Shows the rule, the CWE/OWASP and the data path: from where the untrusted input is born (source) to where it becomes risk (sink), step by step, even when it crosses functions and files.

4. Fix

codafort fix SF-1 --preview   # shows the diff, writes nothing
codafort fix SF-1             # applies the unit fix

fix writes the correction to the file and is free for the whole security axis. Run codafort scan . again and SF-1 is gone.

5. See the full report

codafort report          # summary
codafort report --tui    # navigable in the terminal

The static HTML is free with codafort engine analyze --source . --format html --output report.html. The served dashboard (report --web) is part of the Platform plan.

Next steps

What it does not do

It does not upload your code, does not fetch dependencies from the cloud, and needs no JVM and no external git. It also does not prove the absence of vulnerabilities: recall is published per language at codafort.com/benchmark.