All tutorials
Learn Cordon
28 tutorials covering the scanner as release 0.6.0 ships it: each a single use case to read, run and move on from, with 150 diagrams. Start with your first scan, or go straight to the ecosystem and command reference. Every page and section links to its source on GitHub at v0.6.0.
Every ecosystem it reads
Every language it reads
Start here
By what you want to catch
- 03Malware & known vulnerabilitiesadvisory DB, typosquats, dependency confusion2 diagrams
- 04Reachability, cut noise without hiding anythingcut CVE noise without hiding anything2 diagrams
- 05Provenance & attestation, prove the sourceprove a package was built from its real source2 diagrams
- 06Secrets, credentials and exfiltration61 secret rules, 13 exfiltration rules6 diagrams
- 07CI/CD pipeline attacksattacks on the pipeline, across seven CI systems6 diagrams
- 08Containers, Kubernetes and infrastructure as codeDockerfile, compose, Kubernetes, Terraform6 diagrams
Running it for real
- 09The advisory databasekeep the intel fresh (OSV + signed bundle)2 diagrams
- 10CI & git hooksfail-on gates, SARIF, fail-closed pre-commit2 diagrams
- 11Air-gapped installsoffline bundles, deterministic scans3 diagrams
- 12Vetting a package before you install itanswer "should I install this?" before you do7 diagrams
Going deeper
- 13AST rules & capabilitieshow rules see through obfuscation ([ast-js])3 diagrams
- 14Config, policy & baselinesorg ceilings, adopt-incrementally3 diagrams
- 15Output formatstext | json | sarif | junit | markdown | github0 diagrams
- 16The sandbox -- running what you do not trustthe one component that executes, and its isolation6 diagrams
- 17Source, build systems, binaries and licencesbuild systems, binaries, licences, scan scope6 diagrams
- 18AI agents, MCP servers and skillsevery agent's instruction, MCP and hook files4 diagrams
- 19What changed since the last releasewhat changed since the version you trust2 diagrams
- 20Findings in the editorfindings on the line, in VS Code1 diagram
Across a team
- 21Reviewing a dependency updatewhat an update adds, on every pull request2 diagrams
- 22Code arriving from someone elseclone and pull, scanned before they land4 diagrams
- 23Machines and vendor SBOMsinstalled packages, images, supplier SBOMs2 diagrams
- 24Policy for every repositoryone ceiling, pinned by digest; pins kept current2 diagrams
Reference
- 25Every ecosystemall 28: the files read, the checks, the commands28 diagrams
- 26Every commandevery command and option, from the parser itself45 diagrams
- 27Every AI agent and MCP locationeach agent's files, MCP configs, hooks and rules0 diagrams
- 28Every ruleall 1,384 rules and every Agent Threat Rule0 diagrams
The one thing to remember
Cordon READS. It never runs the code it is scanning, and it never sends anything about your code or dependencies anywhere unless you ask. By default it makes no network request at all; --offline (or CORDON_OFFLINE=1) guarantees it. A scan is safe to point at hostile packages and safe to run in an air-gap.