Skip to main content

CodeGuard

CodeGuard (codeguard) is a command-line tool for macOS that checks Swift projects read-only. It reads configuration, paths and Git changes, calls external check tools and writes the result as a text, JSON or SARIF report. It never modifies the project itself.

This help describes codeguard 0.3.5.

What CodeGuard checks​

A check run consists of phases. Which of them run depends on the command, the configuration and the project.

PhaseWhat happensTool
securityPath rules (allowed scope, protected files) and content rules (e.g. fatalError, try!, as!, secrets, passwords in logs)CodeGuard itself
platformStatic check of app and framework targets: privacy manifest, purpose strings, App Transport Security, entitlementsCodeGuard itself
formatFormat checkswift-format
swiftlintLint with the project's .swiftlint.ymlswiftlint
swiftlint_metricsManaged metric rules (line length, complexity …) from the CodeGuard configurationswiftlint
compileBuild for every detected and available Apple platformswift build or xcodebuild
testsTests natively on macOS and on disposable simulatorsswift test or xcodebuild test

For details, see Checks and rules.

What CodeGuard guarantees​

  • No writes to the project. The only things written are a requested report (--output), the device-local trust store with its audit log and, for simulator tests, disposable simulators. Xcode builds run on a copy of the project.
  • No network. Builds run offline. Swift packages with remote dependencies therefore can't be built at the moment (exit 3, see FAQ).
  • No project code without approval. swift build, swift test and xcodebuild run project code (manifest, plugins, build settings, tests). They only start with a trust ticket or, in CI, in an attested, isolated environment.
  • Tools only from verified paths. External tools are resolved via xcode-select/xcrun or below trusted directories, never via PATH.
  • The exit code is a contract. It is the same in all output formats and can be evaluated in scripts and pipelines.

Platforms​

CodeGuard builds for macOS, iOS/iPadOS, watchOS, tvOS and visionOS, against the simulator SDKs plus native macOS. There is no device build, no Mac Catalyst, no DriverKit and no Linux.

How this help is organized​