Configuration
Where to change how codafort behaves: repository files, flags and environment variables. None of it lives on a server.
Rules
Rules load in four layers. When two layers define the same rule.id, the higher number wins:
| # | Source | When |
|---|---|---|
| 1 | builtin, the rules that ship with codafort | always |
| 2 | .codafort-rules.yaml at the project root | if present |
| 3 | .codafort-rules/*.yaml | if present |
| 4 | --rules-dir <dir> | when passed |
A custom rule, in YAML, can be regex, ts-query, taint-path (from a source to a sink, with sanitizers) or a composition (all_of/any_of/not/path_glob). codafort rules lists what is loaded.
attest does not load --rules-dir: the rules hash in the counter-signed declaration matches exactly what ran.
Gate
.codafort-gate.yaml declares the conditions for codafort gate and engine analyze --fail-on-quality-gate. Without the file, the default applies: it fails if vulnerabilities, blocker, taint_findings or risk_findings_high is above zero. Resolution order: --config, then the file in the directory, then the default. See CI and the gate.
Suppressions that persist
codafort false-positive SF-3 --reason "input comes from a constant" # mark as FP
codafort risk-accept SF-5 --reason "mitigated at the WAF until Q4" # accept the risk (WontFix)
Both persist across runs and stay recorded in the result: a risk-accept does not fail the gate, but it stays in the report, and the counter-signed declaration carries the result together with what was suppressed.
Session and cache
.codafort/session.json: theSF-nof the lastscan(enablesexplain/fixwithout analysing again)..codafort/cache.redb: incremental cache;engine analyze --incrementalre-analyses only what changed.codafort engine cacheinspects and clears it.
Both are regenerable and should not go into version control.
--taint-k <0|1> sets how precisely data flow is followed across functions (attest uses 0).
Outputs
engine analyze --format <json|sarif|sonarqube|html|graphml|csv|cyclonedx|spdx|finding>. sarif carries codeFlows, the data path that code scanning shows; finding emits the canonical coda-finding/1; cyclonedx and spdx are the SBOM. report --tui and report --web read the local envelope (--web, the served dashboard, is in the Platform plan). The HTML dashboard fetches nothing from the network.
Telemetry
codafort config telemetry status
codafort config telemetry off # permanent
export CODAFORT_TELEMETRY=off # session / CI
codafort scan . --no-telemetry # just this once
codafort scan . --telemetry-dry-run # shows the payload, sends nothing
In CI or without a TTY, the level drops to 0 on its own. Today the collector is not provisioned: the binary attempts the send on every interactive scan and nobody receives it. Telemetry is pseudonymous: a random, fixed install id, with no name or e-mail. The public text is at codafort.com/telemetry.
Licence
codafort license activate <token> # verifies the licence offline
codafort license status # tier and validity
codafort license deactivate # back to Free
Security is never locked: without a licence, scan/explain/fix/vet/gate/MCP work in full. Each plan adds to the previous one. Vibe unlocks review and the quality and risk axes; Pro, the runtime moments (codaprobe, codatrace and codacrash fleet triage); Verified, the counter-signed declaration (attest create/bundle); Platform, multi-repo governance (engine merge, the bulk-scan portfolio) and the served dashboard (report --web). Verifying a declaration (attest verify) is free. See codafort.com/pro.
Environment variables
| Variable | Effect |
|---|---|
CODAFORT_TELEMETRY=off | turns telemetry off for the session |
CODAFORT_ATTEST_KEY · CODAFORT_ATTEST_DELEGATION | air-gapped declaration (sub-key and delegation); see Counter-signed declaration |
CODAFORT_VERSION · CODAFORT_INSTALL · CODAFORT_NO_MODIFY_PATH | installer install.sh only |
CODATRACE_MAX_EVENTS | maximum events the codatrace agent emits (default 10,000) |
SG_DENY_MODULES | codaguard deny-list (codacrash) |