The VelnixTHE VELNIX
0%
Back to projects
AI / Developer tools

CodeDog

AI-assisted security reviews directly in developer pull requests.

< 12s

Scan Time

-92%

False Positives

84%

Remediation Rate

codedog.velnix.studio
pull_request_review_7.ymlSecurity Pass
@@ -42,8 +42,8 @@ function handleInput(req)
- const query = `SELECT * FROM users WHERE id = ${req.body.id}`;
+ const query = `SELECT * FROM users WHERE id = $1`;

CodeDog Security Agent Analysis:

"Identified SQL Injection vulnerability. Direct string interpolation into DB query exposes the system to query spoofing. Refactored query to use parameterized query parameters instead."

Overview

CodeDog bridges the gap between complex static analysis and active developer workflows. By running automated scans on incoming Git diffs and explaining vulnerabilities in plain language, it turns security checks from an engineering bottleneck into a collaborative step.

The Stack

ReactTypeScriptPythonFastAPIOpenAI APIDocker

What We Shipped

Real-time secure LLM parsing engine
GitHub Actions & GitLab webhook receivers
PR comment synchronization pipeline
Interactive vulnerabilities status dashboard

The Challenge

Traditional security scanners output hundreds of false positives, which developers routinely ignore. Generating static reports outside of GitHub or GitLab workflows means vulnerability remediation is delayed until just before shipping, causing major design delays.

Our Solution

We designed and built a secure, real-time LLM-powered review pipeline. Instead of bulk reports, CodeDog acts as a junior reviewer on PRs—analyzing the delta of the code, identifying actual vulnerability paths, and providing direct, copy-pasteable diff corrections in comments.

Keep Exploring

Other Case Studies

View all projects
Previous Case Study • Fintech / Developer tools

FakePE

API sandbox enabling developers to test edge-case payment flows.

Next Case Study • Infrastructure

VedDB

High-performance key-value database designed for operational clarity.