Skip to main content

Guardrails CLI for scanning repositories

Project description

Topcoder Guardrails

Enterprise-grade guardrails for GitHub Copilot workflows: a FastAPI backend, GitHub App integration, and CLI that enforce security, policy, and licensing standards with explainable AI + static analysis.

Deployed URL

https://topcoder-production.up.railway.app

Quick start (hosted)

  1. Open the deployed URL.
  2. Go to /settings/ui.
  3. Paste your OpenAI API key and save.
  4. Create or update a PR in a repo where the GitHub App is installed. Guardrails posts comments/checks automatically.

That is all most users need.

What this delivers

  • Hybrid analysis engine: rule-based static checks + AI review with explanations.
  • Copilot awareness: stricter handling for AI-generated code paths.
  • Policy-based enforcement: advisory, warning, blocking, with override label support.
  • License/IP compliance: SPDX/license detection and duplication heuristics.
  • GitHub PR + commit integration: check runs, inline comments, and summaries.
  • Auditability: audit log export, resolution events, and dashboards.
  • Extensible rulepacks: sector-specific YAML rulepacks and repo overrides.

Challenge requirement coverage

  • Secure coding guardrails with OWASP/CWE mappings.
  • Copilot-aware flagging and stricter enforcement for AI-generated code.
  • Configurable coding standards via YAML/JSON repo config.
  • AI-assisted PR review with explanations and suggested fixes (security, performance, maintainability).
  • License/IP checks (restricted licenses + duplication heuristics).
  • Policy-based enforcement modes (advisory, warning, blocking) with override support.
  • PR and commit scanning via GitHub App (check runs + inline comments + summaries).
  • Traceability with audit IDs, export, and resolution events.
  • Async scan flow for large PRs.
  • Pluggable rulepacks per industry (finance, healthcare, public sector, telecom, government) and custom uploads.

Architecture

  • backend/ — FastAPI service, rule engine, AI review, audit logging
  • github-app/ — GitHub App integration (PR + commit scanning)
  • src/guardrails_cli/ — CLI package for local repo scans
  • docs/ — Architecture notes

Security & data handling

  • No source code retention beyond analysis. Audit logs store sanitized output only.
  • Settings storage is encrypted when a key is configured.
  • Data residency can be enforced via repo config + environment variable.

Requirements

CLI

  • Python 3.9+

Configuration (backend)

Core settings:

  • OPENAI_API_KEY (optional) — used when no per-user key exists
  • GUARDRAILS_API_TOKEN (optional) — bearer token required for analysis/scan endpoints when set
  • GUARDRAILS_ADMIN_TOKEN (optional) — bearer token required for admin endpoints (audit export, rulepack upload)
  • SETTINGS_SCOPE (default: global) — global | user | ip
  • SETTINGS_TOKEN (optional) — protects settings endpoints
  • REQUIRE_AI_REVIEW_DEFAULT (default: false)

GitHub App integration

The GitHub App scans PRs and pushes, posts comments/checks, and reads repo overrides from .guardrails/config.yml|yaml|json.

Environment variables:

  • BACKEND_URL (required)
  • BACKEND_TOKEN (optional) — bearer token for secured backend endpoints
  • OVERRIDE_LABEL (optional, default: guardrails-override)
  • MAX_FILES (optional, default: 100)
  • MAX_FILE_BYTES (optional, default: 200000)
  • USE_ASYNC_SCAN (optional, default: false)

CLI usage

Install:

pip install guardrails-cli

Scan:

guardrails scan <repo-path> --user <token>
# Or, from inside your repo:
guardrails scan --user <token>

Before scanning, save your OpenAI API key in the hosted settings UI (/settings/ui). The CLI uses the hosted backend by default.

If the backend enforces API tokens:

guardrails scan <repo-path> --user <token> --api-token <backend-token>

Fix modes:

  • Full fix (AI rewrite + safe fixes): guardrails scan --full-fix --user <token>
  • Safe fix only: guardrails scan --safe-fix --user <token>
  • No fixes: guardrails scan --no-fix --user <token>

Notes:

What users must do

  • Provide their own OpenAI API key via /settings/ui (hosted).
  • Install the CLI only if they want local scans.

CLI settings (optional)

guardrails settings --issue-user-token

API endpoints

  • GET /health
  • GET /
  • GET /dashboard
  • GET /settings
  • POST /settings/token
  • GET /settings/token/current
  • POST /settings/token/assign
  • GET /settings/ui
  • POST /settings/api-key
  • POST /settings/ai-mode
  • POST /settings/autofix-mode
  • POST /settings/override-allowed
  • POST /analyze
  • POST /analyze-batch
  • POST /scan/async
  • GET /scan/status/{job_id}
  • GET /report/summary
  • GET /report/trends
  • GET /rulepacks
  • POST /rulepacks
  • GET /audit/export
  • POST /audit/resolve
  • GET /docs

Testing

pytest
  • GET /report/summary — Audit summary counts

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

guardrails_cli-0.1.22.tar.gz (13.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

guardrails_cli-0.1.22-py3-none-any.whl (12.3 kB view details)

Uploaded Python 3

File details

Details for the file guardrails_cli-0.1.22.tar.gz.

File metadata

  • Download URL: guardrails_cli-0.1.22.tar.gz
  • Upload date:
  • Size: 13.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.14

File hashes

Hashes for guardrails_cli-0.1.22.tar.gz
Algorithm Hash digest
SHA256 35bdc6bb4f24d2b05b7b25e9a1b422c636de78bac6b873c7e1e44a276414b6a3
MD5 9ffda474fdf07b3d7c86edf2b59b1745
BLAKE2b-256 f7b3251b2532b0a7e4af380f2085ed27eabfbd48530dc484a0db7fcd8e80fb20

See more details on using hashes here.

File details

Details for the file guardrails_cli-0.1.22-py3-none-any.whl.

File metadata

File hashes

Hashes for guardrails_cli-0.1.22-py3-none-any.whl
Algorithm Hash digest
SHA256 7ca1e06bf8d290f21f07d4f86478bcb1aaf938f0d51552f8fe8b89bcc06e5e69
MD5 896267b3e1515edd811b8543954dc36a
BLAKE2b-256 e2ec55bcee503b6a1a31209f2ab6ad2f4bd91c1823e2bf7cfbee597021ec9e98

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page