Skip to main content

A library for analyzing code security using LLMs

Project description

CodeCheq

A powerful library for analyzing code security using Large Language Models (LLMs). This tool helps identify potential security vulnerabilities, code smells, and best practice violations in your codebase.

Features

  • 🔍 Evidence-based code analysis using LLMs
  • 🛡️ Security vulnerability detection
  • 📊 Detailed analysis reports
  • 🔄 Support for multiple LLM providers (OpenAI, Anthropic)
  • 📝 Customizable analysis prompts
  • 🎯 Multiple output formats (JSON, HTML, Text)
  • 🚀 Easy-to-use CLI interface
  • 🔒 HIPAA and healthcare compliance analysis

Installation

From PyPI

pip install codecheq

From Source

# Clone the repository
git clone https://github.com/yourusername/codecheq.git
cd codecheq

# Install in editable mode
pip install -e .

Quick Start

Using the Library

from codecheq import CodeAnalyzer

# Initialize the analyzer
analyzer = CodeAnalyzer(provider="openai", model="gpt-4")

# Analyze a file
results = analyzer.analyze_file("path/to/your/file.py")

# Print results
for issue in results.issues:
    print(f"Severity: {issue.severity}")
    print(f"Message: {issue.message}")
    print(f"Location: {issue.location}")
    print(f"Description: {issue.description}")
    print(f"Recommendation: {issue.recommendation}")
    print("---")

Using the CLI

After Installation

If you've installed the package (either from PyPI or in editable mode), you can use the CLI directly:

# Analyze a single file
codecheq file.py

# Analyze a directory
codecheq directory/

# Generate HTML report
codecheq file.py --format html --output report.html

# Use specific model
codecheq file.py --model gpt-4

Without Installation

If you haven't installed the package, you can use the provided scripts:

# Using the Python script
python codecheq.py file.py

# Using the batch file (Windows)
codecheq.bat file.py

# Using the run script
python run_codecheq.py file.py

Configuration

The library can be configured using environment variables or a configuration file:

# Environment variables
export OPENAI_API_KEY="your-api-key"
export ANTHROPIC_API_KEY="your-api-key"
export CODECHEQ_MODEL="gpt-4"

Or create a .env file:

OPENAI_API_KEY=your-api-key
ANTHROPIC_API_KEY=your-api-key
CODECHEQ_MODEL=gpt-4

Advanced Usage

Custom Analysis Prompts

from codecheq import CodeAnalyzer, PromptTemplate

# Create custom prompt
custom_prompt = PromptTemplate(
    template="""Analyze the following code for {analysis_type}:
    {code}
    
    Focus on:
    {focus_areas}
    """,
    variables=["analysis_type", "code", "focus_areas"]
)

# Use custom prompt
analyzer = CodeAnalyzer(prompt=custom_prompt)

Batch Analysis

from codecheq import BatchAnalyzer

# Initialize batch analyzer
batch = BatchAnalyzer()

# Add files to analyze
batch.add_file("file1.py")
batch.add_file("file2.py")
batch.add_directory("src/")

# Run analysis
results = batch.analyze()

# Export results
results.export_html("report.html")

Contributing

Contributions are welcome! Please feel free to submit a Pull Request. For major changes, please open an issue first to discuss what you would like to change.

Development Setup

# Clone the repository
git clone https://github.com/yourusername/codecheq.git
cd codecheq

# Create a virtual environment
python -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate

# Install development dependencies
pip install -e ".[dev]"

# Run tests
pytest

License

This project is licensed under the MIT License - see the LICENSE file for details.

Acknowledgments

  • Thanks to all the contributors who have helped shape this project
  • Inspired by various code analysis tools and security best practices

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

codecheq-0.1.2.tar.gz (15.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

codecheq-0.1.2-py3-none-any.whl (14.7 kB view details)

Uploaded Python 3

File details

Details for the file codecheq-0.1.2.tar.gz.

File metadata

  • Download URL: codecheq-0.1.2.tar.gz
  • Upload date:
  • Size: 15.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.10.0

File hashes

Hashes for codecheq-0.1.2.tar.gz
Algorithm Hash digest
SHA256 38f000903e5b393215356a25608bc99fad4c20fbc6cb27739959e1050cb55940
MD5 f1890a1676ad254254c3136b85edd6db
BLAKE2b-256 38b4c5555bb46d23114e102ac2911d58bbbd8e712e6d9884527173006125a79c

See more details on using hashes here.

File details

Details for the file codecheq-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: codecheq-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 14.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.10.0

File hashes

Hashes for codecheq-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 2aa1cbd35b4df4af713243a4f7c8bf468b557968a353fe0728f04dccdf8a3737
MD5 4e88475b70be53ee54700f7c77c59d24
BLAKE2b-256 740424f26f479bbd38d44392247c40dfffc343993cfa39fdc0c42919ffd73dd6

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page