Configuration

Where to change how codafort behaves: repository files, flags and environment variables. None of it lives on a server.

Rules

Rules load in four layers. When two layers define the same rule.id, the higher number wins:

#SourceWhen
1builtin, the rules that ship with codafortalways
2.codafort-rules.yaml at the project rootif present
3.codafort-rules/*.yamlif present
4--rules-dir <dir>when passed

A custom rule, in YAML, can be regex, ts-query, taint-path (from a source to a sink, with sanitizers) or a composition (all_of/any_of/not/path_glob). codafort rules lists what is loaded.

attest does not load --rules-dir: the rules hash in the counter-signed declaration matches exactly what ran.

Gate

.codafort-gate.yaml declares the conditions for codafort gate and engine analyze --fail-on-quality-gate. Without the file, the default applies: it fails if vulnerabilities, blocker, taint_findings or risk_findings_high is above zero. Resolution order: --config, then the file in the directory, then the default. See CI and the gate.

Suppressions that persist

codafort false-positive SF-3 --reason "input comes from a constant"   # mark as FP
codafort risk-accept SF-5 --reason "mitigated at the WAF until Q4"    # accept the risk (WontFix)

Both persist across runs and stay recorded in the result: a risk-accept does not fail the gate, but it stays in the report, and the counter-signed declaration carries the result together with what was suppressed.

Session and cache

  • .codafort/session.json: the SF-n of the last scan (enables explain/fix without analysing again).
  • .codafort/cache.redb: incremental cache; engine analyze --incremental re-analyses only what changed. codafort engine cache inspects and clears it.

Both are regenerable and should not go into version control.

--taint-k <0|1> sets how precisely data flow is followed across functions (attest uses 0).

Outputs

engine analyze --format <json|sarif|sonarqube|html|graphml|csv|cyclonedx|spdx|finding>. sarif carries codeFlows, the data path that code scanning shows; finding emits the canonical coda-finding/1; cyclonedx and spdx are the SBOM. report --tui and report --web read the local envelope (--web, the served dashboard, is in the Platform plan). The HTML dashboard fetches nothing from the network.

Telemetry

codafort config telemetry status
codafort config telemetry off        # permanent
export CODAFORT_TELEMETRY=off         # session / CI
codafort scan . --no-telemetry        # just this once
codafort scan . --telemetry-dry-run   # shows the payload, sends nothing

In CI or without a TTY, the level drops to 0 on its own. Today the collector is not provisioned: the binary attempts the send on every interactive scan and nobody receives it. Telemetry is pseudonymous: a random, fixed install id, with no name or e-mail. The public text is at codafort.com/telemetry.

Licence

codafort license activate <token>   # verifies the licence offline
codafort license status             # tier and validity
codafort license deactivate         # back to Free

Security is never locked: without a licence, scan/explain/fix/vet/gate/MCP work in full. Each plan adds to the previous one. Vibe unlocks review and the quality and risk axes; Pro, the runtime moments (codaprobe, codatrace and codacrash fleet triage); Verified, the counter-signed declaration (attest create/bundle); Platform, multi-repo governance (engine merge, the bulk-scan portfolio) and the served dashboard (report --web). Verifying a declaration (attest verify) is free. See codafort.com/pro.

Environment variables

VariableEffect
CODAFORT_TELEMETRY=offturns telemetry off for the session
CODAFORT_ATTEST_KEY · CODAFORT_ATTEST_DELEGATIONair-gapped declaration (sub-key and delegation); see Counter-signed declaration
CODAFORT_VERSION · CODAFORT_INSTALL · CODAFORT_NO_MODIFY_PATHinstaller install.sh only
CODATRACE_MAX_EVENTSmaximum events the codatrace agent emits (default 10,000)
SG_DENY_MODULEScodaguard deny-list (codacrash)