step-security/ai-codewise

step-security/ai-codewise

AI-Powered Code Reviews for Best Practices & Security Issues Across Languages

GitHubGitHub Repository

21 stars

Docker

Docker Action

Score updated 2 days ago

GitHub Actions security score

step-security/ai-codewise

Score

8/10

License

Apache License 2.0

Maintained

Maintained by StepSecurity

Vulnerabilities

21 existing vulnerabilities detected

Docker vulnerabilities

docker://ghcr.io/step-security/ai-codewise:v1.0.0

0 existing vulnerability detected

Branch protection

branch protection is not maximal on development and all release branches

Manual code review

Upstream changes are reviewed before merging

Secure publishing

Reproducible builds with SBOM and provenance

Signed commits

All commits are signed

Automated security tools

Findings from tools are triaged and fixed before each change

Popular

Used by StepSecurity enterprise customers

Security Policy

security policy file detected

Networking Behavior of step-security/ai-codewise

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
api.github.comGitHubGitHub
int.api.stepsecurity.ioUnknown