Connect it your way.
From one laptop to every repository in your company. Your code stays where it is; only results reach Cordon.
Developersopen source
The CLIThe whole scanner, offline if you want it.
pipx install cordon-scannercordon-scanner scan .
Developersopen source
Pre-commit guardReads the staged files, so nothing slips in at commit time.
cordon-scanner guard installDevelopersopen source
Clone and pull, checkedCode from a teammate or the internet is scanned from git's objects before it is checked out or merged. With --global, every plain git clone, checkout and pull is checked too, and undone if blocked.
cordon-scanner clone <url>cordon-scanner pullcordon-scanner guard install --global
EveryoneCordon Cloud
Sign in from the terminalApprove the sign-in in the console, with a second factor; scans from a laptop then upload as the person who ran them.
cordon-scanner logincordon-scanner scan . --upload
Platform adminsCordon Cloud
Code host

GitHub App, GitLab group or Bitbucket workspace, cloud or self-managed. Every repository listed in one step, with findings as pull-request comments.
Setup > Connect your code hostDevOpsCordon Cloud
CI pipelines




Ready templates for GitHub Actions, GitLab, Bitbucket, Azure Pipelines, Jenkins, CircleCI and Buildkite. Each signs in with the CI's own OIDC identity, so no secret is stored, and GitHub, GitLab, CircleCI and Buildkite sign the results for the exact commit.
uses: Threx-code/cordon/action@<sha>with: { upload: true }
Reviewersopen source
Dependency review
On a pull request: every package the update adds, upgrades or downgrades, the advisories it brings in or fixes, and with --online what each new release contains, posted as a comment.
cordon-scanner review --base origin/main# Action: dependency-review: true
Developersopen source
In the editor
The VS Code extension scans on save and marks findings in place, from the same engine and rules as CI. Publisher ID: threx-code.cordon; accept no other.
code --install-extension threx-code.cordon# or the signed .vsix from github.com/Threx-code/cordon/releases
EnterprisesCordon Cloud
Cordon RunnerScans every repository from inside your network. Only results leave.
docker run \ -e CORDON_RUNNER_TOKEN \ ghcr.io/threx-code/cordon-runner:<version> \ runner --allow-host github.com
IT, through MDMCordon Cloud
LaptopsEvery AI tool and MCP server developers added. See exactly what is sent first.
cordon-scanner agent inventorycordon-scanner agent report
Platform teamsCordon Cloud
Package firewall





Run it next to your builds, in front of Artifactory or Nexus, and point npm, pip, Maven, Go, NuGet, RubyGems or Cargo at it; malware is refused at install.
npm config set registry \ https://firewall.acme.internal/npm/
Security engineersopen source
Container images
Layer by layer, from a saved image: OS packages, runtimes, language packages and the application. Nothing runs.
cordon-scanner scan image.tarSecurity engineersopen source
MachinesA laptop or CI runner's installed packages: the distribution's, and Python, npm, Ruby, Cargo, Go and Homebrew installs outside any project. Read from metadata; no package manager is run.
cordon-scanner scan --host / --home "$HOME"Procurement and securityopen source
A vendor's SBOMCycloneDX or SPDX, checked against the same intel as your own code, with the vulnerabilities the vendor listed kept beside the ones Cordon finds.
cordon-scanner scan vendor.cdx.jsonPlatform teamsCordon Cloud
Deploy gate
A deploy step asks Cordon before release and refuses any image without a passing, signed scan, so what was never scanned never ships.
Setup > Deploy gateWatch it connect
Sign in, guard a commit, gate CI, read an image.
134x38
cordonzsh payments-apiintel bundle, 5drulepack b44fbcabexecuted 0
Where alerts go
To the team that owns the code.
Routes send each finding to its owner, in the tool they already use. A ticket closes itself when a complete scan proves the fix.