Skip to content

Latest commit

 

History

295 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

The Wolf

The Wolf

Deterministic security and code-quality scanning that helps every repository get better.

by AlphaBravo

Version Scanners Self-hosted AI API License


Measure code. Improve it. Prove it got better.

The Wolf unifies 53 best-in-class security and quality scanners behind a single console, API, and CLI, then runs them as reproducible, version-pinned evidence against every repository in your fleet. Whether code was written by a developer, generated with AI, or changed by an automated fix, Wolf makes it answer to deterministic scanners, quality gates, baselines, and targeted rescans before you trust it. No per-seat licensing. No code leaving your perimeter. No forty tools to install and babysit. Just Docker, and a platform that runs entirely on your terms.


Why teams choose The Wolf

Every team wants code to get safer, cleaner, and easier to ship, but improvement is hard to prove without repeatable checks. Human-written code, AI-assisted code, and automated fixes all need deterministic scanners, reproducible evidence, and policy gates that do not depend on confidence or guesswork. At the same time, security tooling sprawl is still the problem: every team ends up juggling a dozen scanners, each with its own CLI, output format, container, update cadence, and dashboard — and none of them tell you which of the 4,000 findings to fix first, or prove that a change actually made the code better.

The Wolf collapses that sprawl into one platform:

The old way With The Wolf
Code improvement judged manually or inconsistently Deterministic scanner evidence for every change
12 scanners, 12 CLIs, 12 dashboards One console, one API, one CLI
"Install bandit, gosec, eslint, trivy..." on every box Zero host install — every tool runs in an isolated container
A wall of 4,000 undifferentiated findings Composite severity scoring + AI prioritization
AI fixes you still have to trust manually Scan, fix, targeted rescan before the PR
Per-repo tools that can't see the forest Fleet posture across 100+ repos on any host
SaaS that ingests your source Self-hosted — your data never leaves
Per-developer seat pricing No seat tax

The platform at a glance

Unified Scanning

53 scanners, one deterministic engine. SAST, SCA, secrets, containers, IaC, DAST, SBOM, license, privacy/PII, K8s, and more — running in parallel, version-pinned, and fully reproducible.

Fleet Management

See and steer everything. Manage 100+ repos across local, GitHub, and remote SSH hosts from a single fleet dashboard — posture, trends, top risks, and what needs attention today.

AI Remediation

Find, fix, and prove. AI enriches findings and opens fix PRs, while deterministic rescans and regression guardrails decide whether the change actually improved the code.

Governance & Policy

Ship with confidence. Quality gates that block CI, baselines that surface only what's new, audit-logged suppressions, and SARIF in and out of every system you already run.

Built for Platforms

Automate all of it. A complete REST API with live OpenAPI docs, a CLI that mirrors it 1:1, scoped tokens, SSE streaming, SQLite or PostgreSQL — self-hosted and air-gap friendly.

Source Anywhere

Scan it wherever it lives. Local checkouts, public and private GitHub, generic git, or code sitting on remote SSH hosts — no agents to deploy, bulk-imported in seconds.


Capabilities

One platform, every scanner

The Wolf orchestrates 53 industry-standard tools across every major category — and it doesn't ask you to install a single one. Each tool runs in its own short-lived, locked-down container; the only thing on your host is Docker. That gives teams a deterministic improvement loop: scan code consistently, fix what matters, and rescan the exact evidence before merging. It works for traditional development, AI-assisted development, and autonomous remediation.

  • Comprehensive coverage — SAST, software composition analysis (SCA), secret detection, container & image hardening, infrastructure-as-code, Kubernetes, policy-as-code, DAST, SBOM generation, license compliance, privacy/PII data-flow, dependency freshness, repository hygiene, and per-language linting for Python, Go, JavaScript/TypeScript, Java, Kotlin, Ruby, PHP, Rust, C/C++, Swift, and more.
  • Parallel by design — every applicable tool runs concurrently with configurable concurrency, so a full multi-tool scan finishes in the time of your slowest scanner, not the sum of all of them.
  • Reproducible & auditable — every tool is version-pinned. Identical scans on two hosts produce identical findings. Reproducibility you can put in front of an auditor.
  • Hardened isolation — scanned code runs unprivileged, on a read-only mount, with a read-only root filesystem and no inbound network. Your scanners never become your attack surface.
  • Smart deduplication & scoring — findings from overlapping tools are merged, fingerprinted, and ranked by a composite severity score (tool severity × code location × AI context), so the critical handful rises to the top of the noise.

Fleet management & posture

Built for the reality of modern engineering orgs: dozens or hundreds of services, spread across laptops, build hosts, and Git providers.

  • The Fleet dashboard — open findings by severity with week-over-week trend, your most vulnerable shared components ("14 repos still depend on log4j 1.2"), a prioritized needs-attention list (failing gates, stale scans, new criticals), and a live inventory by source, collection, and language.
  • Org-wide visibility — administrators see the whole fleet; other users stay owner-scoped. There is no global fleet_mode toggle.
  • Bulk onboarding — import an entire GitHub organization in one flow, or point at an SSH host and auto-discover every git repository on it. Go from zero to a fully-mapped fleet in minutes.
  • Collections — group repositories by team, environment, or tier; scan them as a batch and track cross-repo metrics and posture per collection.
  • Branch-aware trends — track findings per branch over time and prove your security posture is improving.

AI-assisted remediation

Most tools tell you what's wrong. The Wolf fixes it.

  • Finding enrichment — every finding can be enriched with an AI-authored, ready-to-hand-off remediation prompt: what's wrong, why it matters, and exactly how to fix it.
  • Automated fix engine — point it at a finding or a whole scan and it generates the patch and opens the pull request, driven by your choice of agent (Claude Code, Codex, or a custom engine).
  • Autonomous remediation loops — run scan, fix, rescan cycles that iterate until clean, governed by per-finding budgets, wall-clock and cost ceilings, and regression guardrails so a fix never makes things worse.
  • AI triage — automatically separate real issues from false positives before they ever reach a human queue.
  • Your model, your keys, your call — pluggable providers (Anthropic, OpenAI), and AI is off by default — a single master switch, opt-in when you're ready, with full cost and token accounting.

Governance, compliance & policy

The controls that turn scanning into a program.

  • Quality gates — declarative, scoped policies that fail a build on severity counts, new findings, or category thresholds. One CLI exit code wires The Wolf into any CI system.
  • Baselines & diff — pin a known-good scan as a baseline and surface only what's new, resurfaced, or fixed — so developers see their regressions, not the backlog.
  • Durable suppressions — audit-logged, expiring, scoped hide rules (by fingerprint, rule, category, or path) plus .wolfignore support — accepted risk that's tracked, not lost.
  • SARIF in and out — import findings from any external scanner and export any scan as SARIF for your dashboards, code-scanning views, and compliance pipelines.
  • Complete audit trail — every mutating action — who, what token, which resource, what result — is recorded for security review of both human and AI-driven activity.

Built for platform & security teams

  • A complete REST API — every capability is an endpoint, documented with live, interactive OpenAPI/Swagger docs served right from the product (fully offline). If a human can do it in the UI, a pipeline can do it through the API.
  • A CLI that mirrors the API 1:1 — wolf <resource> <verb> for everything, with table output for humans and JSON for machines, kubeconfig-style contexts for multiple environments, and CI-friendly exit codes.
  • Scoped, revocable credentials — least-privilege API tokens with verb:resource scopes and configurable expiry, alongside session-based UI auth — role-appropriate access for every actor.
  • Run it your way — single-binary or Docker, SQLite for a team or PostgreSQL for the enterprise, on your servers, in your cloud, or fully air-gapped.
  • Live everything — real-time scan, fix, and loop progress streamed over SSE to the console and the CLI.
  • Managed scanner images — consume tested scanner images from GHCR by default, detect available updates in the console, and pre-pull the full configured set before scans run.

Scan code wherever it lives

  • Local paths — point at any checkout on the host.
  • GitHub, public and private — token-authenticated, with whole-org bulk import.
  • Generic git — any HTTPS or SSH git remote.
  • Remote SSH hosts — scan code sitting on other machines with no agent to install: The Wolf archives the working tree over SSH and scans it locally.

What you get

  • Faster mean-time-to-remediate — prioritized findings plus AI that opens the fix PR.
  • One pane of glass — fleet-wide posture instead of a dozen disconnected dashboards.
  • Lower tooling cost — replace a stack of point products and per-seat SaaS with one self-hosted platform.
  • Audit-ready evidence — reproducible scans, a classified audit log, and SARIF exports out of the box.
  • Secure by default — role-based access, two-factor auth, scoped API keys, and HTTPS via the bundled proxy.
  • No vendor lock-in — your data, your infrastructure, standard formats, open scanners.

Get started in 60 seconds

The only prerequisite is Docker. No scanners to install — they're pulled or built on demand.

# Launch the platform (API + web console)
docker compose up -d

# Open the console
open http://localhost:8778

# (optional) Pre-pull every scanner image
docker compose exec wolf wolf pull scanners

# Health-check the environment
docker compose exec wolf wolf doctor

# Scan a repository
docker compose exec wolf wolf scan --repo /repos/myproject

Prefer the API or CI? Everything the console does is one call away:

# Authenticate once, then drive the whole platform from the CLI.
# Mint a scoped key in the console (Account > API Keys) or:  wolf auth token create --name ci --scope read-write
wolf config set-context prod --server https://wolf.internal --token wolf_...
# (interactive alternative — prompts for a 2FA code when enabled)
#   wolf auth login --server https://wolf.internal --email you@example.com

wolf repo create --name acme --type github --path acme/payments
SCAN=$(wolf scan create --repo <repo-id> --profile fast -o json | jq -r .data.id)
wolf scan watch "$SCAN"                       # live progress
wolf scan gate "$SCAN" --fail-exit-code       # exit 5 on policy fail
wolf sarif export "$SCAN" > findings.sarif    # feed your dashboards
wolf init                                     # first-run local layout
wolf backup -o ./wolf-backup.tar              # control-plane backup
wolf mcp                                      # stdio MCP; server needs WOLF_MCP_ENABLED=1

Interactive API docs ship with the product at /api/v1/docs (Swagger UI) and /api/v1/docs/redoc — no internet required. Disconnected installs: docs/disconnected.md. CLI map: docs/cli.md. For durable remote scans from CI or another service—including one-shot Git/SSH sources, credentials, idempotency, SSE replay, workers, and Kubernetes native Jobs—see docs/remote-scanning-api.md. For scanner image operations—including GHCR image channels, pre-pulling, registry mirrors, air-gapped installs, and advanced custom builds—see scanners/README.md and docs/scanner-custom-builds.md.


The scanner catalog

53 scanners. One console. Every tool is either pulled from its maintainer's official image, bundled in The Wolf's slim default image, or available in an opt-in heavyweight bucket — all orchestrated identically.

Cross-language & security

Category Tool Source What it does
SAST Semgrep Official image Pattern + semantic static analysis across every language
SAST CodeQL Heavyweight bucket GitHub's semantic SAST engine
SCA Trivy Official image Filesystem, container & IaC vulnerability scanning
SCA Grype + Syft Official image SBOM-driven vulnerability matching
SCA OSV-Scanner Official image Multi-ecosystem scanning on Google's OSV database
Dependency freshness Renovate Official image Flags outdated & vulnerable deps across 15+ ecosystems
IaC KICS Official image ~3k rules across Terraform, K8s, CloudFormation, Ansible, Helm
IaC Checkov Official image Terraform / Helm / K8s / CloudFormation security
Policy-as-code Conftest Official image OPA/Rego policy evaluation over any config
Kubernetes Kubescape · Kube-linter · Pluto Official image Security, compliance & deprecated-API detection
Secrets Gitleaks · TruffleHog · detect-secrets Official image / bundled History + working-tree secret detection, with live verification
Containers Hadolint · Dockle Official image Dockerfile linting & CIS image hardening
Infrastructure TFLint Official image Provider-aware Terraform linting
DAST Nuclei Official image Template-based HTTP/DNS/TCP vulnerability scanning
Privacy / PII Bearer Official image GDPR/HIPAA/PCI data-flow analysis
Repo hygiene OpenSSF Scorecard Official image Supply-chain security posture scoring
SBOM Syft Official image Software bill-of-materials generation
Docs / API Spectral · Vale Official image OpenAPI/AsyncAPI linting & prose style
Shell / SQL / Config ShellCheck · SQLFluff · yamllint · markdownlint Bundled Language-specific linting

Per-language depth

Language Tools
Python Bandit · Ruff · Mypy · pip-audit · Radon · Vulture
Go Gosec · Staticcheck · Govulncheck · GoKart
JavaScript / TypeScript ESLint · npm-audit
Java / Kotlin detekt · PMD · Infer
Ruby Brakeman · RuboCop
PHP PHPStan
Rust Clippy
C / C++ Cppcheck · Infer
Swift SwiftLint

The Wolf also maps source to tests across 13 languages for coverage-aware scoring, and adds new tools with a single plugin file. The full annotated manifest lives in scanners/tools.yaml and scanners/TOOLS.md.


Autonomous remediation

The Wolf can go past finding a problem to proposing the fix — autonomously, but on a short leash. The autonomous fix engine takes a single finding, has an AI coding agent write a patch, proves the patch is good, and hands you a review-ready branch and diff. It never trusts the agent's word for it. Architecture and rationale: docs/superpowers/specs/2026-06-15-autonomous-fix-engine-design.md.

Off by default. The entire surface is gated behind one master setting, autofix_enabled (default false). With it off, the execute path returns 403 autofix_disabled, the worker processes nothing, and the UI surface is dark. Flip it on in Settings > General or with wolf settings set autofix_enabled true.

Verified, branch-only, then optional push. The worker operates in an isolated worktree/clone on a fresh fix branch, commits each kept fix, rescans the branch, can pause for a human between loops, and can push that branch for review. It never pushes main/master or the repo default branch.

The verify gate (why you can trust it)

The load-bearing principle is never use an engine's self-report to decide success — every fix is judged by the diff on disk and a verification gate, not by what the agent claims it did. A proposed fix is rolled back unless it clears every step:

  1. Files actually changed — an empty or no-op diff fails.
  2. It still builds — a language-aware build (go build ./..., tsc --noEmit, ...), parse-only at minimum.
  3. The finding is gone — a targeted rescan re-runs only that finding's scanner/rule against the changed file and confirms it no longer fires.
  4. No regressions — the rescan introduces no new findings.
  5. Optional tests — a configured test command, if you supply one.

Anything that fails is rolled back and the orchestrator escalates (more context, then the next engine) up to a bounded max_attempts, all under per-finding, wall-clock, and cost budgets. A finding that can't be fixed cleanly is recorded as unfixable — not silently "done".

The worker

The server runs no agents. It enqueues durable jobs onto a fix_jobs queue; a separable wolf fixer worker atomically claims them, runs the orchestration inside an engine container, streams logs + status back over SSE, and updates the job. Run one or many — the atomic claim guarantees two workers never double-claim a job, and a heartbeat + stale-reclaim recovers jobs from a crashed worker.

wolf fixer            # long-running worker: claim, fix, repeat
wolf fixer --once     # claim exactly one job, then exit (k8s Job-per-task)

The engine containers

The worker runs inside one of three independently versioned engine containers, built and pushed through the same scanner-image build subsystem as the scanner images (see internal/scannerbuild FixerVariants and fixer/). All share a base with git, gh/glab, and the language build tools the verify gate needs (go, node/tsc):

Image Engine Auth
wolf-fixer-engines Combined Debian worker: Claude + Codex + OpenCode any of the CLI logins or provider keys
wolf-fixer-claude Anthropic Claude Code CLI claude login or an anthropic_key / ANTHROPIC_API_KEY
wolf-fixer-codex OpenAI Codex CLI codex login or an openai_key / OPENAI_API_KEY
wolf-fixer-opencode OpenCode CLI (opencode-ai@1.18.16) opencode auth login or Anthropic/OpenAI keys
wolf-fixer-api API engine via internal/ai — CLI-free anthropic_key or openai_key

Compose and Helm default to ghcr.io/alphabravo-oss/wolf-fixer-engines, the combined Debian worker. The single-engine images stay independently versioned in the locked scanner/fixer release; wolf-fixer-engines is published alongside them so the worker can scale on its own.

The engine chain prefers an available, authenticated CLI (OAuth session or API key) and falls back to the API engine. The API engine returns a unified diff that wolf applies with git apply. OpenCode is a first-class engine; the dedicated image is optional (build fixer/Dockerfile.opencode against the locked fixer base). A repo-shipped opencode.json is stripped from the worktree before the run.

Auth-then-ready flow

The CLI variants need a one-time interactive login; the API variant is the zero-auth fallback for environments where you can't provision a CLI session.

# 1. Start the worker container with a volume for the agent session.
# Resolve the approved release once and use its immutable digest here.
export WOLF_FIXER_IMAGE='ghcr.io/alphabravo-oss/wolf-fixer-engines@sha256:<approved-digest>'
docker run -d --name wolf-fixer \
  -v wolf-fixer-session:/home/wolf \
  -e WOLF_API_URL=https://wolf.internal \
  "$WOLF_FIXER_IMAGE"

# 2. Log in once. The session is written under $HOME and reused.
wolf fixer login claude      # or: docker exec -it wolf-fixer wolf fixer login claude
wolf fixer login codex
wolf fixer login opencode
wolf fixer status            # confirm OAuth / API-key readiness

# 3. Pick model + effort in Settings → Fixer (or per job). Then queue a fix.

Kubernetes shape

Two supported shapes — persist the agent session on a PVC mounted at /home/wolf (covers Claude, Codex, and OpenCode session files):

  • Deployment + PVC — a long-running worker (or a few) that loop on the queue. Authenticate once with kubectl exec -it deploy/wolf-fixer -- wolf fixer login claude; the PVC keeps the session across rollouts.
  • Job-per-task — wolf fixer --once as a Kubernetes Job that claims one job and exits, scaled by the queue depth. Pair the CLI variants with the same session PVC, or use wolf-fixer-api (no session needed) for fully ephemeral runs.

Enterprise & deployment

The Wolf is designed to live inside your perimeter and your governance model.

Deployment Single Go binary or Docker Compose. Runs on your servers, your cloud, or fully air-gapped.
Data store SQLite for a team; PostgreSQL for scale and high availability.
Access control Role-based (admin / user) with per-user data isolation, two-factor auth (TOTP, optionally mandatory org-wide), console sessions, and scoped, revocable API keys (verb:resource + admin). See docs/authentication.md.
Audit A classified, security-aware audit log — semantic event type, category, severity, actor, source IP, and result — searchable and filterable. See docs/audit.md.
HTTPS Run behind the bundled Caddy reverse proxy — automatic Let's Encrypt or bring-your-own cert — with an optional hardened Docker-socket proxy. See docs/deployment.md.
Secrets Encrypted at rest with a master key; GitHub, SSH, AI-provider, and registry credentials managed in-product.
Air-gapped / mirrored Pre-load images and run with pull_policy=Never, point Docker Hub-hosted upstream scanners at a public cache such as mirror.gcr.io, or disable upstream images entirely and run everything from images you build and host yourself.
Supply chain Version-pinned scanner images published through CI to GHCR, with local digest checks and optional advanced custom builds for private registries.
Data residency Self-hosted by design — source code and findings never leave your infrastructure.

The scanner backend is a three-tier image strategy — official upstream images where maintainers publish them, a slim Wolf-built image for the long tail of per-language tools, and opt-in heavyweight buckets (JVM, Rust, CodeQL) pulled only when needed — so a typical Python + JavaScript shop runs on well under a gigabyte of images.

For the full operations reference — air-gapped installs, network allowlists, registry mirroring, scanner DB caching, and the WOLF_SCANNERS_* knobs — see scanners/README.md and docs/.


Architecture

cmd/wolf/        CLI + server entrypoint
internal/
  api/           HTTP API, OpenAPI docs, SSE streaming, auth & audit middleware
  ai/            Pluggable AI providers (Anthropic, OpenAI)
  auth/          Sessions, scoped API tokens, RBAC
  db/            SQLite + PostgreSQL persistence
  fix/  loop/    AI fix engine, autonomous remediation loops + fix worker/orchestrator
  finding/       Identity, diff, baselines, quality gates, suppressions, SARIF
  scan/          Detection, orchestration, scoring, reporting
  scannerbuild/  Server-side scanner & fixer image build & publish
  setup/scanners/ Container backend
plugins/         49 tool plugins, by language/category
scanners/        Wolf-built scanner images + manifests
fixer/           Autonomous-fix engine container images (claude / codex / api)
ui/              Vite + React 19 + Tailwind 4 console

A single Go binary serves the API, the web console, and the embedded documentation; the only runtime dependency is Docker for the scanner containers.


License

Source available. Intended product license is Business Source License 1.1 with a four-year Change Date to Apache License 2.0. Counsel must supply LICENSE before a public BSL release. See LICENSE_POLICY.md and NOTICE. Copyright © AlphaBravo, Inc. All rights reserved.

Community evaluation is capped at 5 repositories, 3 users, and 1 concurrent scan worker. Set WOLF_COMMUNITY_LIMITS=0 to lift it; a signed Enterprise license also lifts it.

The Wolf — built by AlphaBravo.

About

No description, website, or topics provided.

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages