CodeGuard
CodeGuard (codeguard) is a command-line tool for macOS that checks Swift projects read-only. It reads configuration, paths and Git changes, calls external check tools and writes the result as a text, JSON or SARIF report. It never modifies the project itself.
This help describes codeguard 0.3.5.
What CodeGuard checks
A check run consists of phases. Which of them run depends on the command, the configuration and the project.
| Phase | What happens | Tool |
|---|---|---|
security | Path rules (allowed scope, protected files) and content rules (e.g. fatalError, try!, as!, secrets, passwords in logs) | CodeGuard itself |
platform | Static check of app and framework targets: privacy manifest, purpose strings, App Transport Security, entitlements | CodeGuard itself |
format | Format check | swift-format |
swiftlint | Lint with the project's .swiftlint.yml | swiftlint |
swiftlint_metrics | Managed metric rules (line length, complexity …) from the CodeGuard configuration | swiftlint |
compile | Build for every detected and available Apple platform | swift build or xcodebuild |
tests | Tests natively on macOS and on disposable simulators | swift test or xcodebuild test |
For details, see Checks and rules.
What CodeGuard guarantees
- No writes to the project. The only things written are a requested report (
--output), the device-local trust store with its audit log and, for simulator tests, disposable simulators. Xcode builds run on a copy of the project. - No network. Builds run offline. Swift packages with remote dependencies therefore can't be built at the moment (exit 3, see FAQ).
- No project code without approval.
swift build,swift testandxcodebuildrun project code (manifest, plugins, build settings, tests). They only start with a trust ticket or, in CI, in an attested, isolated environment. - Tools only from verified paths. External tools are resolved via
xcode-select/xcrunor below trusted directories, never viaPATH. - The exit code is a contract. It is the same in all output formats and can be evaluated in scripts and pipelines.
Platforms
CodeGuard builds for macOS, iOS/iPadOS, watchOS, tvOS and visionOS, against the simulator SDKs plus native macOS. There is no device build, no Mac Catalyst, no DriverKit and no Linux.
How this help is organized
- Getting started: requirements, installation, first run
- Commands and options: all commands, global options and exit codes
- Checks and rules: every phase and every rule ID
- Project configuration:
.codeguard.ymlwith all keys - Organization policy:
policy.ymlfor administrators - Configuration examples: macOS, iOS, tvOS, watchOS and Swift packages
- Trust and security: project trust, audit log, simulators
- Manual use: CodeGuard in day-to-day work on your development machine
- CI with GitHub Actions and CI with GitLab
- Reading reports: text, JSON and SARIF with real examples
- FAQ: typical errors and how to fix them