Skip to content

SecureCode AI 1.0.0

Choose a tag to compare

@shorinversion shorinversion released this 29 Sep 18:32
· 8 commits to main since this release
5a954f8

First release: a local multi-agent security audit prototype (Auditor + Architect) covering the full course assignment.

Try it

python deploy/docker/quickstart.py --demo                   # Docker only
python deploy/docker/quickstart.py --demo --provider local  # uv + Ollama (Qwen 2.5 Coder 7B Q4_K_M)

Highlights

  • Auditor → Architect demo completes on local Qwen Q4_K_M and on DeepSeek: CWE-89 found, parameterized-query patch validated in an ephemeral copy, OWASP Top 10 report (security-report.md/.html).
  • Tools: AST/CST for Python, JS/TS and Go, hardcoded secrets, vulnerable dependencies via OSV, 30+ CWE scanners, patch validation; unified Evidence contract.
  • Executed notebook notebooks/securecode_demo.ipynb.
  • 600-case CVEfixes benchmark: hybrid (scanners + DeepSeek) held-out recall 32.8% vs Semgrep 32.5% — on par, superiority not shown; deterministic recall 25.7% after fixing tree-sitter node comparisons.
  • CI: ruff, mypy (Linux + Windows), 3292 tests, secret and dependency policy.

See the attached final report and benchmark PDF, and CHANGELOG for details and limitations.