Skip to main content

ContrastContrast Code

ContrastContrast Code is an AI-powered orchestration engine that integrates static analysis tools into the ContrastContrast platform. It scans your repositories for security vulnerabilities using Static Application Security Testing (SAST) and Software Composition Analysis (SCA) then enriches those findings with AI triage and runtime context from instrumentation sensors in Contrast Security. The result is a prioritized, correlated view of risk from code to production without adding new agents or sensors to your existing pipeline.

ContrastContrast Code runs as part of your GitHub CI/CD pipeline with the NorthstarNorthstar GitHub app and a GitHub Action. When a scan completes, findings are captured in the ContrastContrast platform as Observations. They are scored into Issues alongside any runtime data from Contrast Assess (IAST) and Contrast Application Detection and ResponseContrast ADR(アプリケーションにおける検知と対応) (ADR). You can also view repository-to-application linkage in the Explorer, which shows which repositories map to which running applications.

ContrastContrast Code is available as part of the ContrastContrast Platform SKU and is licensed per active committer, which is an account that commits code to a monitored repository within any consecutive 30-day period.

注記

Monorepos are not fully supported in application models at this time.

AI Triage

AI Triage is an automated analysis step that runs on SAST findings before they are ingested into the ContrastContrast Platform. Rather than surfacing every raw static finding directly to your security team, AI Triage examines each result in context and classifies it as a likely true positive or false positive.

For each finding AI Triage produces three pieces of information:

  • Classification: Whether the finding is likely a true positive or a false positive

  • Justification: The reasoning behind the classification

  • Work performed: A description of what the AI agent analyzed to reach its conclusion

This information appears in the detailed view for each Observation in the platform. Issues resulting from false-positive findings are automatically moved to a Closed state by default.

AI Triage applies only to SAST findings. AI Triage will analyze for 10 minutes by default, although the duration is configurable.

Supported languages

Contrast Code supports the following languages. Additional language support for SAST and/or SCA will be added over time.

Table key:

green dotサポート対象

-- このテクノロジでは該当なし

注記

For assistance, contact Contrast support.

Language

Static SCA

SAST

Android

--

green dot

Apex

--

green dot

Bash

--

green dot

C

--

green dot

C++

--

green dot

.NET/C#

green dot

green dot

Dart

green dot

green dot

Dockerfile

--

green dot

Elixir

green dot

green dot

Go

green dot

green dot

HTML

--

green dot

Java

green dot

green dot

JavaScript

green dot

green dot

JSON

--

green dot

JSP

--

green dot

Julia

green dot

--

Kotlin

--

green dot

OCaml

--

green dot

PHP

green dot

green dot

Python

green dot

green dot

R

green dot

--

Ruby

green dot

green dot

Rust

green dot

green dot

Scala

--

green dot

Shell

--

green dot

Solidity

--

green dot

Swift

green dot

green dot

Terraform

--

green dot

TypeScript

green dot

green dot

XML

--

--

YAML

--

green dot

Get started

To onboard your repositories to Contrast Code, install the NorthstarNorthstar GitHub app.