A library for analyzing code security using LLMs
Project description
CodeCheq
A powerful library for analyzing code security using Large Language Models (LLMs). This tool helps identify potential security vulnerabilities, code smells, and best practice violations in your codebase.
Features
- 🔍 Evidence-based code analysis using LLMs
- 🛡️ Security vulnerability detection
- 📊 Detailed analysis reports
- 🔄 Support for multiple LLM providers (OpenAI, Anthropic)
- 📝 Customizable analysis prompts
- 🎯 Multiple output formats (JSON, HTML, Text)
- 🚀 Easy-to-use CLI interface
- 🔒 HIPAA and healthcare compliance analysis
Installation
From PyPI
pip install codecheq
From Source
# Clone the repository
git clone https://github.com/CalBearKen/aioniq_codecheq.git
cd codecheq
# Install in editable mode
pip install -e .
Quick Start
Using the Library
from codecheq import CodeAnalyzer
# Initialize the analyzer
analyzer = CodeAnalyzer(provider="openai", model="gpt-4")
# Analyze a file
results = analyzer.analyze_file("path/to/your/file.py")
# Print results
for issue in results.issues:
print(f"Severity: {issue.severity}")
print(f"Message: {issue.message}")
print(f"Location: {issue.location}")
print(f"Description: {issue.description}")
print(f"Recommendation: {issue.recommendation}")
print("---")
Using the CLI
After Installation
If you've installed the package (either from PyPI or in editable mode), you can use the CLI directly:
# Analyze a single file
codecheq file.py
# Analyze a directory
codecheq directory/
# Generate HTML report
codecheq file.py --format html --output report.html
# Use specific model
codecheq file.py --model gpt-4
Without Installation
If you haven't installed the package, you can use the provided scripts:
# Using the Python script
python codecheq.py file.py
# Using the batch file (Windows)
codecheq.bat file.py
# Using the run script
python run_codecheq.py file.py
Configuration
The library can be configured using environment variables or a configuration file:
# Environment variables
export OPENAI_API_KEY="your-api-key"
export ANTHROPIC_API_KEY="your-api-key"
export CODECHEQ_MODEL="gpt-4"
Or create a .env file:
OPENAI_API_KEY=your-api-key
ANTHROPIC_API_KEY=your-api-key
CODECHEQ_MODEL=gpt-4
Advanced Usage
Custom Analysis Prompts
from codecheq import CodeAnalyzer, PromptTemplate
# Create custom prompt
custom_prompt = PromptTemplate(
template="""Analyze the following code for {analysis_type}:
{code}
Focus on:
{focus_areas}
""",
variables=["analysis_type", "code", "focus_areas"]
)
# Use custom prompt
analyzer = CodeAnalyzer(prompt=custom_prompt)
Batch Analysis
from codecheq import BatchAnalyzer
# Initialize batch analyzer
batch = BatchAnalyzer()
# Add files to analyze
batch.add_file("file1.py")
batch.add_file("file2.py")
batch.add_directory("src/")
# Run analysis
results = batch.analyze()
# Export results
results.export_html("report.html")
Contributing
Contributions are welcome! Please feel free to submit a Pull Request. For major changes, please open an issue first to discuss what you would like to change.
Development Setup
# Clone the repository
git clone https://github.com/yourusername/codecheq.git
cd codecheq
# Create a virtual environment
python -m venv venv
source venv/bin/activate # On Windows: venv\Scripts\activate
# Install development dependencies
pip install -e ".[dev]"
# Run tests
pytest
License
This project is licensed under the Apache License - see the LICENSE file for details.
Acknowledgments
- Thanks to all the contributors who have helped shape this project
- Inspired by various code analysis tools and security best practices
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file codecheq-0.1.5.tar.gz.
File metadata
- Download URL: codecheq-0.1.5.tar.gz
- Upload date:
- Size: 19.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.10.0
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1227d0f6ea3ad16513e690bd443baf8e6a53111663dc5897bd2f07ea18a26ec2
|
|
| MD5 |
185eaedfca7c53f6c0eac2fee7b62070
|
|
| BLAKE2b-256 |
02f3ae4b33ea378c560bb3e98c5c81fee448c4a9a6f5197decb1638dfc85fb70
|
File details
Details for the file codecheq-0.1.5-py3-none-any.whl.
File metadata
- Download URL: codecheq-0.1.5-py3-none-any.whl
- Upload date:
- Size: 19.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.10.0
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ba3f5e000ad57edc89d557509f906d5ceff64ed751e4ece5524d054326a2c636
|
|
| MD5 |
dea41f5008a455cf5bc76c2f827c445c
|
|
| BLAKE2b-256 |
d00b5dcce9b218d97dee4037ae04f00d012056a873769fd9f9be6bde29184bf6
|