Repository navigation
GuardSpine CodeGuard v1.0.0
AI-aware code governance with cryptographically verifiable evidence bundles.
Features
- Risk Classification (L0-L4): Automatic risk tier assignment based on file patterns and content analysis
-
- Evidence Bundles: Hash-chained JSON bundles for audit trails
-
- Diff Postcard: PR comments showing risk tier, drivers, and findings
-
- Evidence Mappings: Pre-built rule sets for SOC 2, HIPAA, and PCI-DSS audit support
-
- SARIF Integration: Export findings to GitHub Security tab
AI Provider Support
- OpenRouter (100+ models): Claude, GPT-4, Gemini, Llama
-
- Anthropic Direct: Claude API
-
- OpenAI Direct: GPT API
-
- Ollama: Local/on-prem AI for air-gapped environments
Quick Start
- uses: DNYoussef/codeguard-action@v1
- with:
- github_token: ${{ secrets.GITHUB_TOKEN }}
- ```
See [README](https://github.com/DNYoussef/codeguard-action#readme) for full documentation.