Application Security

Code Manager

Integrates with GitHub, Azure DevOps, and Bitbucket to perform continuous security assessment of your codebase — detecting vulnerabilities and risky patterns in real time without ever storing your source code.

Code Manager

DevSecOps — security built into your pipeline

What it does

Key capabilities

Repository Integration

Native integration with GitHub, Azure DevOps, and Bitbucket — connect your repos without any code changes.

Real-Time Vulnerability Detection

Identifies security flaws, dependency vulnerabilities, and risky coding patterns as code is pushed.

Zero Code Retention

Source code is never stored — analysis is performed in-memory and results are discarded after assessment.

Pipeline Integration

Plug security assessment directly into your CI/CD pipeline to block risky code before it reaches production.

Dependency Scanning

Scans third-party libraries and packages for known CVEs so vulnerable dependencies are caught early.

Remediation Guidance

Every finding comes with specific remediation advice and code-level guidance to accelerate fixing.

Highlights

Why Code Manager?

  • GitHub, Azure DevOps, and Bitbucket supported
  • Zero source code retention — privacy by design
  • Catches vulnerabilities in dependencies before deployment
  • CI/CD pipeline integration to gate releases
  • Shifts security left without slowing development
Included in OneView

Code Manager is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210
FAQs

Frequently asked questions

Code Manager integrates natively with GitHub (cloud and Enterprise Server), Azure DevOps, and Atlassian Bitbucket. Repository connection requires read-only API credentials — no code changes, webhooks, or agent installations in your CI/CD pipeline are needed to begin security assessment.

No. Code Manager is built on a zero retention principle — source code is fetched, analysed in-memory, and discarded after assessment. No copy of your source code is written to storage at any point. Only the security findings — file name, line reference, vulnerability type, and remediation guidance — are stored in your Hakware tenant.

Code Manager parses dependency manifests — package.json, requirements.txt, pom.xml, Gemfile.lock, and others — and cross-references all declared packages against the NIST NVD CVE database and known advisory feeds. Vulnerable packages are flagged with severity, affected version range, and the fixed version that resolves the issue.

Code Manager can be triggered automatically as part of your CI/CD pipeline via API. When integrated with a pull request workflow, it assesses the changed code before merge and can return findings to the pipeline as a gate — blocking PRs with critical vulnerabilities from merging to main without analyst review and approval.

See Code Manager in action

Request a personalised demo and we'll show you exactly how Code Manager works within your environment.