A European retail company with 1,500 engineers built remediation agents on top of Codacy that close their own security issues. We turned what they built into a reference architecture: a 7-stage loop from pulling open findings, through triage and fix, to merge and close.
Codacy
Desenvolvimento de software
Lisbon, Lisboa 22.125 seguidores
Code Quality & Security for AI-Assisted Engineering
Sobre nós
Codacy is the code quality and security platform for AI-assisted engineering teams. AI is now embedded through the engineering workflow, which has made teams faster, but also adds risk to everything they ship. Codacy helps AI-assisted teams ship high-quality, secure code across the full software development lifecycle, starting in the agent and editor, through pull requests in Git, and into containers and runtime security. At each stage we check for quality issues, security vulnerabilities and AI coding risk introduced into the codebase, and help devs and agent fix them effortlessly. A team's standards become automated guardrails that apply across every IDE, AI coding agent, and Pull Request. More than 250,000 developers rely on Codacy to keep quality and security stable as AI changes how software gets built.
- Site
-
https://www.codacy.com
Link externo para Codacy
- Setor
- Desenvolvimento de software
- Tamanho da empresa
- 51-200 funcionários
- Sede
- Lisbon, Lisboa
- Tipo
- Empresa privada
- Fundada em
- 2012
- Especializações
- Software Quality, Continuous Static Analysis, Automated Code Review, Technical Debt Management, Code Reviews, Code Quality, Engineering Performance, CI/CD, GitHub, Bitbucket e GitLab
Funcionários da Codacy
Localidades
-
Principal
Como chegar
Av. Joao Crisostomo 31
6th Floor
Lisbon, Lisboa 1050-125, PT
-
Como chegar
1460 Broadway
New York, NY 10036, US
Atualizações
-
Codacy compartilhou isso
AI is changing the Engineering Manager role. There is more context, more capacity, and more happening in parallel. A bigger part of the job is making sure the team can still focus on what matters, without getting overwhelmed by the sheer amount of information coming at them. I shared some thoughts on this alongside Jorge Braz for this article. https://lnkd.in/eqT-wFEP
-
New in Codacy: affected functions on advisories.
We recently shipped affected functions on advisories. Most of the times, when an insecure dependency is reported, our code is not really using the vulnerable code. Codacy now shows the actual affected functions on advisory-linked findings, plus a ready-made prompt for your coding assistant to search the repo for those calls. Is it used? Could be used? Upgrade. If not, review what it found, then ignore it as "Not exploitable" and move on. Available via the UI, API and CLI. Specially useful via the CLI to put your agent to verify and ignore in bulk. Learn more about it here: https://lnkd.in/e2ADqyvM
-
Most AI code review tools can't safely block a merge today. Some teams are either using a strict but probabilistic bot 🙉 or an advisory one that enforces nothing 🙈. Others pair AI review with deterministic checks that enforce the same result every time. 🦍 We compare 14 tools and show which tools can be trusted to uphold AI code governance in 2026.
-
Codacy compartilhou isso
A CVE on a dependency flags the whole package as vulnerable, even when the flaw sits in a few specific functions your code may never call. Across a long advisory list, everything ends up looking equally urgent. Codacy now shows which functions inside a vulnerable dependency or container image a CVE actually affects. Your team can check usage with a ready-made prompt for your AI coding assistant, then upgrade if the code calls affected functions or ignore the finding if not. Now when auditors or CISOs want to know why a vulnerability is still open, you have a concrete answer: "we checked and it's not exploitable". Now available via the UI, CLI and API: https://lnkd.in/eRSAGUkU
-
-
Codacy compartilhou isso
When a new CVE is published, the usual thing to hear from engineering teams is "does it actually touch our code?" That's because a package having a CVE doesn't mean every part of it is a problem. Usually the flaw lives in a few specific functions. Codacy now shows if there are affected functions on findings linked to an advisory, so triage starts from the part of the package that's implicated, not just the package name. One click copies a prompt for your AI coding assistant to check whether your code calls them. Less time debating whether a CVE matters. More confidence that the ones you escalate deserve it. Now available via the UI, CLI and API: https://lnkd.in/ehRzq_qp
-
-
Codacy compartilhou isso
When your PR comes back red, how many pushes does it take to get it green? Three? Four? And how many of those findings were real? You know at least one wasn't. You rewrote working code anyway, because arguing with the checker costs more than caving to it. In Claude Code: "Review pull request 42 with Codacy." Whole list at once. Fixed on your machine. False positives dismissed with a reason logged, so nobody argues them again. Then the real question: if the agent can do that after the PR, why are you waiting for the PR? Scan before you commit. Open it clean. Walkthrough here: https://lnkd.in/gpkkhk-f
-
Codacy compartilhou isso
Your agent can already check Codacy results on a PR, fix issues, and unblock a quality check. That’s useful. But why wait until the PR exists? When I’m working with agents like Claude Code, I often run /code-review locally before I even open a draft PR. So the natural next step was: what if that same review flow could also run Codacy analysis locally and fix issues before the first push? That’s why we created two Codacy Skills: one that teaches the agent how to set up and run Codacy analysis locally, and another one that teaches it how to use Codacy analysis as part of any code review. The result is a tighter feedback loop: the agent writes the code, runs the same kind of independent analysis your team relies on, reads the findings, and fixes them while everything is still local. Here are the skills: https://lnkd.in/eBTimbr6 And here’s a walkthrough: https://lnkd.in/dTxuUJx2
-
Codacy compartilhou isso
Of all the agent skills we built, this one pays off the most. The Codacy Analysis CLI skill lets your coding agent scan your changes locally and fix the issues it finds before you commit. Agents like Claude Code get specific findings to work through, so you can deal with those issues before they show up in a pull request. That means fewer rounds of pushing a change, waiting for checks, and coming back to fix something you could have caught locally. Here’s how to get started: https://lnkd.in/g4JVhWA6