All tutorials

Your first scan

Cordon 0.6.05 sections · 2 diagramsView this tutorial on GitHub
  pip install cordon-scanner  cordon-scanner scan .

That is the whole thing. No config, no network, no setup.

Your first scan, figure 1
   cordon-scanner scan .
        │
        ▼
   ┌─────────────┐   walk the tree      ┌──────────────┐
   │  your repo  │ ───────────────────▶ │  identify    │  what is this? which
   │  (a dir,    │                      │  the target  │  languages, manifests,
   │   file or   │                      └──────┬───────┘   lockfiles, CI files?
   │   archive)  │                             ▼
   └─────────────┘                      ┌──────────────┐
                                        │   detectors  │  run every applicable check
                                        └──────┬───────┘
                                               ▼
                                        ┌──────────────┐
                                        │   findings   │  sorted, de-duplicated
                                        └──────┬───────┘
                                               ▼
                                        ┌──────────────┐
                                        │    report    │  to your terminal
                                        └──────────────┘
Your first scan, figure 2
   .  CRITICAL   package "left-pad" decodes a payload and executes it   MALWARE.DROPPER.001
      │          │                                                       │
   severity   what it found (plain language)                         rule id (stable)

   Run again with -v for the evidence, the score, and the fix.
   0  clean          nothing met the failure policy   1  findings        something met --fail-on   2  scanner error   cordon itself broke   (never your code's fault)   3  config error    bad config/policy/override   4  incomplete      scan was degraded and --fail-on-incomplete was set   if cordon-scanner scan . ; then echo ok ; fi     # any non-zero fails safe
   cordon-scanner scan .  --include "src/**"          only these paths   cordon-scanner scan .  --exclude "vendor/**"        skip these (repeatable)   cordon-scanner scan .  --tracked                    only files git tracks   cordon-scanner scan .  --git-diff origin/main       only what changed vs a ref
   --severity   LEVEL     report at/above  info|low|medium|high|critical   --fail-on    LEVEL     break the build  at/above this severity   --quiet   /  --verbose  less / more (the evidence and score derivation)

Next: 02 · How detection works, to understand why a finding fired.