Amazon CodeGuru Security¶
Description¶
On November 20, 2025, AWS will discontinue support for Amazon CodeGuru Security. After November 20, 2025, you will no longer be able to access the /codeguru/security console, service resources, or documentation. For more information, see https://docs.aws.amazon.com/codeguru/latest/security-ug/end-of-support.html.
This section provides documentation for the Amazon CodeGuru Security API operations. CodeGuru Security is a service that uses program analysis and machine learning to detect security policy violations and vulnerabilities, and recommends ways to address these security risks.
By proactively detecting and providing recommendations for addressing security risks, CodeGuru Security improves the overall security of your application code. For more information about CodeGuru Security, see the Amazon CodeGuru Security User Guide.
Usage¶
Arguments¶
-
configOptional configuration of credentials, endpoint, and/or region.
- credentials:
- creds:
- access_key_id: AWS access key ID
- secret_access_key: AWS secret access key
- session_token: AWS temporary session token
- profile: The name of a profile to use. If not given, then the default profile is used.
- anonymous: Set anonymous credentials.
- creds:
- endpoint: The complete URL to use for the constructed client.
- region: The AWS Region used in instantiating the client.
- close_connection: Immediately close all HTTP connections.
- timeout: The time in seconds till a timeout exception is thrown when attempting to make a connection. The default is 60 seconds.
- s3_force_path_style: Set this to
trueto force the request to use path-style addressing, i.e.http://s3.amazonaws.com/BUCKET/KEY. - sts_regional_endpoint: Set sts regional endpoint resolver to regional or legacy https://docs.aws.amazon.com/sdkref/latest/guide/feature-sts-regionalized-endpoints.html
- use_dual_stack: Set this to
trueto use the dualstack (IPv4 and IPv6) endpoint for a service, where available, falling back to the regular endpoint when it isn't. Defaults to theAWS_USE_DUALSTACK_ENDPOINTenvironment variable when unset.
- credentials:
-
credentialsOptional credentials shorthand for the config parameter
- creds:
- access_key_id: AWS access key ID
- secret_access_key: AWS secret access key
- session_token: AWS temporary session token
- profile: The name of a profile to use. If not given, then the default profile is used.
- anonymous: Set anonymous credentials.
- creds:
-
endpointOptional shorthand for complete URL to use for the constructed client.
-
regionOptional shorthand for AWS Region used in instantiating the client.
Value¶
A client for the service. You can call the service's operations using syntax like svc$operation(...), where svc is the name you've assigned to the client. The available operations are listed in the Operations section.
Service syntax¶
svc <- codegurusecurity(
config = list(
credentials = list(
creds = list(
access_key_id = "string",
secret_access_key = "string",
session_token = "string"
),
profile = "string",
anonymous = "logical"
),
endpoint = "string",
region = "string",
close_connection = "logical",
timeout = "numeric",
s3_force_path_style = "logical",
sts_regional_endpoint = "string",
use_dual_stack = "logical"
),
credentials = list(
creds = list(
access_key_id = "string",
secret_access_key = "string",
session_token = "string"
),
profile = "string",
anonymous = "logical"
),
endpoint = "string",
region = "string"
)
Operations¶
batch_get_findings |
Returns a list of requested findings from standard scans |
|---|---|
create_scan |
Use to create a scan using code uploaded to an Amazon S3 bucket |
create_upload_url |
Generates a pre-signed URL, request headers used to upload a code resource, and code artifact identifier for the uploaded resource |
get_account_configuration |
Use to get the encryption configuration for an account |
get_findings |
Returns a list of all findings generated by a particular scan |
get_metrics_summary |
Returns a summary of metrics for an account from a specified date, including number of open findings, the categories with most findings, the scans with most open findings, and scans with most open critical findings |
get_scan |
Returns details about a scan, including whether or not a scan has completed |
list_findings_metrics |
Returns metrics about all findings in an account within a specified time range |
list_scans |
Returns a list of all scans in an account |
list_tags_for_resource |
Returns a list of all tags associated with a scan |
tag_resource |
Use to add one or more tags to an existing scan |
untag_resource |
Use to remove one or more tags from an existing scan |
update_account_configuration |
Use to update the encryption configuration for an account |