User Guides
- CodeGraph quick reference One-page map of current CLI and OpenCode entry points. The page explains the purpose, usage steps, and result checks.
- CodeGraph command-line guide Supported source-checkout CLI entry points, scope rules, and automation boundaries. The page explains the purpose, usage steps, and result checks.
- Typed scenario invocation Invoke a CodeGraph analysis scenario through the exported role-bound Python request contract. See the examples and checks before applying it.
- Import a project into CodeGraph Import local or remote source, verify the job, and select explicit project scope. The page explains the purpose, usage steps, and result checks.
- Review a bounded code change Run the current unified review CLI and interpret its quality and security evidence. The page explains the purpose, usage steps, and result checks.
- Code review hooks for Codex and Claude Code Configure and verify the distributed CodeGraph hook runtimes for Codex and Claude Code, including lifecycle events and blocking boundaries.
- Pilot benchmark Reproducible comparison of 5-10 customer pilot tasks against an agreed baseline. The page explains the purpose, usage steps, and result checks.
- Production monitoring Operator runbook for CodeGraph Prometheus metrics, dashboards, alerts, and receiver-safe deployment. See the examples and checks before applying it.
- Troubleshoot CodeGraph safely Read-only diagnostics, reviewed repair plans, and support evidence. The page explains the purpose, usage steps, and result checks.
- Dogfood operations Current CLI workflow for inspecting CodeGraph CPG freshness, commit analysis, quality trends and guided recovery.
- Analyze security data flows Use broad audit evidence and targeted source-to-sink taint analysis safely. The page explains the purpose, usage steps, and result checks.
- CodeGraph LSP server Configure CPG-backed diagnostics, hover, CodeLens and quick fixes in an LSP client. The page explains the purpose, usage steps, and result checks.
- OpenCode quick start with CodeGraph Launch the current OpenCode integration and use its supported command set. The page explains the purpose, usage steps, and result checks.
- Scenario catalog Task-oriented index of the active public CodeGraph scenario guides, with safe selection and evidence boundaries.
- Scenario 01: Onboard to an unfamiliar codebase Build an evidence-based map of an unfamiliar workspace with CodeGraph. The page explains the purpose, usage steps, and result checks.
- Scenario 02: Run a bounded security audit Run a bounded, evidence-based audit without overstating its authority. The page explains the purpose, usage steps, and result checks.
- Security audit autofix previews Generate reviewable security patch previews without modifying source files. The page explains the purpose, usage steps, and result checks.
- Scenario 03: Create source-backed documentation Produce source-backed documentation through the typed documentation scenario. The page explains the purpose, usage steps, and result checks.
- Scenario 04: Develop a bounded feature Investigate and implement a bounded feature through an evidence-backed task carrier. The page explains the purpose, usage steps, and result checks.
- Scenario 05: Refactoring with impact evidence A reproducible CodeGraph workflow for scoping, implementing, and verifying a bounded refactoring. See the examples and checks before applying it.
- Scenario 06: Investigate a performance problem Turn static performance hypotheses into reproducible before-and-after measurements. The page explains the purpose, usage steps, and result checks.
- Scenario 07: Find and prioritize test gaps Inspect available coverage evidence and prioritize test gaps without inventing runtime data. See the examples and checks before applying it.
- Scenario 08: Assemble compliance evidence Map a bounded compliance claim to separate, reproducible evidence sources. The page explains the purpose, usage steps, and result checks.
- Scenario 09: Review a bounded change Review a bounded revision with portable CodeGraph evidence and explicit lane boundaries. See the examples and checks before applying it.
- Scenario 10: Cross-repository impact Review dependencies, duplication, and consolidation risks across repositories without confusing analysis with approval.
- Scenario 11: Architecture analysis Collect revision-bound dependency and layer evidence for an accountable architecture review. See the examples and checks before applying it.
- Scenario 12: Technical-debt planning Turn bounded technical-debt evidence into a reviewed repayment proposal. The page explains the purpose, usage steps, and result checks.
- Scenario 13: Mass-refactoring plan Analyze a broad symbol or API migration and produce a bounded, reviewable plan without editing source. See the examples and checks before applying it.
- Scenario 14: Security-incident investigation Trace security-incident impact while keeping investigation separate from containment, remediation, postmortem, and closure.
- Scenario 15: Debugging investigation Find source locations and static call evidence relevant to a bounded debugging hypothesis. See the examples and checks before applying it.
- Scenario 16: Entry points and attack surface Build a source-bound hypothesis about externally reachable code and trust boundaries. See the examples and checks before applying it.
- Scenario 18: Code-optimization analysis Generate bounded optimization suggestions without claiming approval, application, or undo. See the examples and checks before applying it.
- Scenario 19: Standards check Import explicit coding rules, run a bounded check, and preserve operational evidence without claiming compliance approval.
- Scenario 20: Dependency analysis Inventory project dependencies and collect bounded vulnerability, license, SBOM, and health evidence without overstating feed coverage.
- Architecture control in CodeGraph Define an architecture model, evaluate rules on the CPG, and adopt release gates safely. See the examples and checks before applying it.
- Run a CPG-backed project audit Choose an audit depth, read the evidence-aware Q1-Q12 result, and investigate recurring defect findings without accepting a false green result.
- Dashboard score methodology How CodeGraph calculates audit, compliance, release, SCA, quality, and the composite Health Score. See the examples and checks before applying it.
- Dashboard operations Operational checks and recovery actions for dashboard data, history, saved views, and notifications. See the examples and checks before applying it.
- Dashboard user guide Task-oriented navigation, filters, freshness, and safe actions in the CodeGraph dashboard. See the examples and checks before applying it.
- Digital employees for investment and construction control The roles of DASHA, CARA, and VERA, how they work together, and their usage boundaries. See the examples and checks before applying it.
- Working with DASHA, CARA, and VERA Run the industry preset, interpret its results, and recover from a blocked workflow. The page explains the purpose, usage steps, and result checks.
- Structural pattern search and controlled rewrite Run explicit-scope GoCPG pattern searches and scans, then gate any source rewrite through preview, approval, backup, and verification.
- Operational release gate Run, inspect and administer the CodeGraph operational release gate without confusing it with governed SDLC closure.
- Generate an SBOM and audit dependencies Separate software inventory from vulnerability evidence and policy thresholds. The page explains the purpose, usage steps, and result checks.
- Assess software supply-chain risk Check provenance, integrity, trust, and typosquatting beyond SCA inventory. The page explains the purpose, usage steps, and result checks.
- Build and maintain a STRIDE threat model Generate, review, update, and visualize a source-bound threat model. The page explains the purpose, usage steps, and result checks.
- Composite analysis workflows Combine Scenario 18 or 19 findings through the supported CLI or governed MCP route without treating suggestions as applied edits.