ModelRefs / Security Scanning — Canonical Workflow

Security Scanning — Canonical Workflow

Security Scanning: provisional AI workflow implementation reference with candidate models, providers, tools, and architecture.

Overview

AI-assisted SAST that explains, prioritises and proposes patches for vulnerabilities in PR context. Security Scanning is a provisional implementation reference with candidate models, providers, tools, benchmarks and deployment patterns to validate on the target workload. Engineered for developer tooling pipelines with reproducible evaluation harnesses, CI/CD integration, and per-commit model versioning. Self-hosted cluster deployment provides full network isolation and GPU scheduling control. Evaluation results are persisted to a metrics store and surfaced in PR review dashboards.

Implementation profile

Categorycoding-models
Implementation maturityproduction
Evidence statusincomplete
Primary use casescoding-copilot, reasoning
Deployment optionsmanaged-api, hybrid
Architecturesserverless-api, managed-container, self-hosted-cluster

Candidate models with published references

Coverage means the model is a candidate worth evaluating for this workflow, not a ranking or a recommendation. Models whose reference pages are still in review are omitted.

Benchmarks relevant to this workflow

miracl, mkqa, mldr, swe-bench, aider-polyglot, gpqa, aime-2025, tau-bench, browsecomp-long-context, longfact-concepts, terminal-bench, mmmu, mmlu-pro, livecodebench.

Relevance is a coverage signal from the canonical registry. Each benchmark only describes its own protocol and date, so confirm the harness matches your workload before treating a score as evidence.

Continue your research

Use these connected ModelRefs sections to compare alternatives, inspect implementation paths, and review the evidence and governance boundaries relevant to Security Scanning — Canonical Workflow.