Skip to main content

A library for analyzing code security using LLMs

Project description

CodeCheq

A powerful library for analyzing code security using Large Language Models (LLMs). This tool helps identify potential security vulnerabilities, code smells, and best practice violations in your codebase.

Features

  • 🔍 Evidence-based code analysis using LLMs
  • 🛡️ Security vulnerability detection
  • 📊 Detailed analysis reports
  • 🔄 Support for multiple LLM providers (OpenAI, Anthropic)
  • 📝 Customizable analysis prompts
  • 🎯 Multiple output formats (JSON, HTML, Text)
  • 🚀 Easy-to-use CLI interface
  • 🔒 HIPAA and healthcare compliance analysis

Installation

From PyPI

pip install codecheq

From Source

# Clone the repository
git clone https://github.com/CalBearKen/aioniq_codecheq.git
cd codecheq

# Install in editable mode
pip install -e .

Quick Start

Using the Library

from codecheq import CodeAnalyzer

# Initialize the analyzer
analyzer = CodeAnalyzer(provider="openai", model="gpt-4")

# Analyze a file
results = analyzer.analyze_file("path/to/your/file.py")

# Print results
for issue in results.issues:
    print(f"Severity: {issue.severity}")
    print(f"Message: {issue.message}")
    print(f"Location: {issue.location}")
    print(f"Description: {issue.description}")
    print(f"Recommendation: {issue.recommendation}")
    print("---")

Using the CLI

After Installation

If you've installed the package (either from PyPI or in editable mode), you can use the CLI directly:

# Analyze a single file
codecheq file.py

# Analyze a directory
codecheq directory/

# Generate HTML report
codecheq file.py --format html --output report.html

# Use specific model
codecheq file.py --model gpt-4

Without Installation

If you haven't installed the package, you can use the provided scripts:

# Using the Python script
python codecheq.py file.py

# Using the batch file (Windows)
codecheq.bat file.py

# Using the run script
python run_codecheq.py file.py

Configuration

The library can be configured using environment variables or a configuration file:

# Environment variables
export OPENAI_API_KEY="your-api-key"
export ANTHROPIC_API_KEY="your-api-key"
export CODECHEQ_MODEL="gpt-4"

Or create a .env file:

OPENAI_API_KEY=your-api-key
ANTHROPIC_API_KEY=your-api-key
CODECHEQ_MODEL=gpt-4

Advanced Usage

Custom Analysis Prompts

from codecheq import CodeAnalyzer, PromptTemplate

# Create custom prompt
custom_prompt = PromptTemplate(
    template="""Analyze the following code for {analysis_type}:
    {code}
    
    Focus on:
    {focus_areas}
    """,
    variables=["analysis_type", "code", "focus_areas"]
)

# Use custom prompt
analyzer = CodeAnalyzer(prompt=custom_prompt)

Batch Analysis

from codecheq import BatchAnalyzer

# Initialize batch analyzer
batch = BatchAnalyzer()

# Add files to analyze
batch.add_file("file1.py")
batch.add_file("file2.py")
batch.add_directory("src/")

# Run analysis
results = batch.analyze()

# Export results
results.export_html("report.html")

Contributing

Contributions are welcome! Please feel free to submit a Pull Request. For major changes, please open an issue first to discuss what you would like to change.

Development Setup

# Clone the repository
git clone https://github.com/yourusername/codecheq.git
cd codecheq

# Create a virtual environment
python -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate

# Install development dependencies
pip install -e ".[dev]"

# Run tests
pytest

License

This project is licensed under the Apache License - see the LICENSE file for details.

Acknowledgments

  • Thanks to all the contributors who have helped shape this project
  • Inspired by various code analysis tools and security best practices

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

codecheq-0.1.6.tar.gz (19.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

codecheq-0.1.6-py3-none-any.whl (19.3 kB view details)

Uploaded Python 3

File details

Details for the file codecheq-0.1.6.tar.gz.

File metadata

  • Download URL: codecheq-0.1.6.tar.gz
  • Upload date:
  • Size: 19.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.10.0

File hashes

Hashes for codecheq-0.1.6.tar.gz
Algorithm Hash digest
SHA256 492405738531804cda4e875da1d93a25a4d90c2a087d1119daed91e98e00ff79
MD5 70a7c1f6c168ddcf7ed2335704890d43
BLAKE2b-256 1fd9f3b7ac8ffc6e162d8b5bf3c1dd76010390649601fc5ec0d493287c9b50f9

See more details on using hashes here.

File details

Details for the file codecheq-0.1.6-py3-none-any.whl.

File metadata

  • Download URL: codecheq-0.1.6-py3-none-any.whl
  • Upload date:
  • Size: 19.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.10.0

File hashes

Hashes for codecheq-0.1.6-py3-none-any.whl
Algorithm Hash digest
SHA256 9dfdc670ade1c95f38e9fbb3b0bdc722796b3caebe311a267a4f690a6ead9d39
MD5 cebd5d242336f5394326fe2d7dbc100d
BLAKE2b-256 a6f8b11ff1390f24619d60d05c85437aa6accc44e8f68489e44380c6a13445f8

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page