Safeship

Documentation

Using Safeship

Everything you need to scan a repository, read the results, and fix what matters.

Introduction

Safeship is a security co-pilot for developers — especially people building with AI who aren't security experts. Connect a GitHub repository and Safeship scans it for leaked secrets, insecure code, and vulnerable dependencies, then explains every finding in plain English with a suggested fix.

It performs static analysis only: it reads your code, it never attacks anything, and it never changes your code without opening a pull request you review.

Getting started

  1. Sign in with GitHub. Safeship requests access to read your repositories and to open pull requests for the one-click fixes.
  2. Pick a repository. On the Repositories tab, choose any repo — public or private — and press Scan.
  3. Wait a moment. Your repo is cloned into a temporary sandbox, and four open-source engines run over it: Gitleaks (secrets), Semgrep (insecure code), OSV (vulnerable dependencies), and Trivy (infrastructure misconfigurations in Terraform, Kubernetes, and Dockerfiles).
  4. Read the report. Findings are grouped and ranked; open any one for a plain-English explanation and a fix.

Understanding your report

Each scan produces a report with a few signals:

  • Safety score (0–100).A quick overall signal computed from the findings' severity — higher is safer. Each finding counts a little less than the one before it, so a repository with a long backlog still shows progress as you work through it, and an open critical keeps the score low however few findings there are.
  • Severity. critical / high / medium / low — the technical seriousness reported by the engine.
  • Priority.fix now / should fix / minor — Safeship's plain-language read on real-world urgency.
  • Grouping. View findings by priority, by area (backend / frontend / data / config), or by the engine that found them, and search to focus.

A finding looks like this:

safeship · report64/100
High Fix now

Hardcoded API key committed to config.ts

config.tsgitleaks

What it means

A secret key is committed to your repository — anyone who can read the code can use it to access your service. Rotate the key and load it from an environment variable instead.

Suggested fix
- const key = "sk_live_9f2c8a1b…";
+ const key = process.env.API_KEY;

Fixing issues

Open any finding to see What it means and a Suggested fix, both written for non-experts.

  • Fix with AI. For a fixable file, Safeship generates the change and opens a pull request on a new branch. You review and merge — it never pushes to your default branch.
  • Batch fix. Select several findings and open a single pull request that addresses them together.

Advisor

Beyond scanning, the Advisor reviews how your project is built:

  • Schema. Reads your database schema and migrations, suggests improvements, and draws an entity-relationship diagram of your tables and relationships. Supports Prisma, SQL, and Rails.
  • Stack. Reviews your technology choices and flags risks or better fits.
  • Optimize. Points out performance and structure improvements.

For schema reviews you can Apply the recommendations as a reviewable pull request — editing the schema file for Prisma/SQL, or adding a new migration for Rails.

Assistant

The Assistant is a chat for security and coding questions. Ask about a specific finding, a concept ("what is SQL injection?"), or your own code. Replies stream in as they're written, and your conversations are saved so you can pick them back up.

Bring your own model

By default every feature uses Safeship's built-in model. In Settings → AI model you can add your own OpenAI-compatible models — OpenAI, Groq, OpenRouter, or any compatible endpoint — then choose which model each feature uses.

Point everything at one model, or use a different model per feature (explanations, advisor, assistant, fixes) to manage cost and rate limits. Your API key is stored encrypted, never shown again, and used only for your requests.

Privacy & safety

  • Static analysis only — no port scans, no live traffic, no exploitation.
  • Your code is scanned in a temporary sandbox and never stored.
  • Secrets are redacted before anything is sent to the AI.
  • Safeship only writes through pull requests you review and merge — never to your default branch.

What Safeship keeps

  • Saved to your account: your scans and their findings, Advisor reviews, and Assistant conversations — so you can revisit them.
  • Not kept:your source code. It's scanned in a temporary sandbox and discarded afterward.
  • If you add your own AI model, the API key is stored encrypted and used only for your requests.

Troubleshooting

  • A scan is stuck or failed. Scans run in the background; one that loses its runner is marked failed automatically — just start it again. Very large repositories take longer.
  • No findings. Often good news. It can also mean the repo has no files the engines recognize — Safeship reports only what Gitleaks, Semgrep, OSV, and Trivy detect.
  • Explanations or fixes are slow. The AI is generating them; each explanation is cached after the first time. Bring your own faster model in Settings if you like.
  • "Save & test" fails for a model. Check the base URL, model name, and API key — the message shown is the provider's own error.
  • A fix was skipped.Some files can't be auto-fixed (for example, dependency lockfiles). Apply the suggested fix manually in those cases.
  • GitHub permission errors.Sign out and back in to refresh Safeship's access to your repositories.

FAQ

Is it really free?

Yes — Safeship runs on open-source engines and free infrastructure, with no paid API and no credit card. If you prefer a premium model, you can plug in your own API key.

What can it scan?

Any GitHub repository you can access, public or private, across most popular languages.

Do you need write access to my repo?

Only to open pull requests for fixes you choose to apply. Scanning itself only reads.

Will it change my code?

Only if you ask. Every change arrives as a pull request on a new branch for you to review — nothing is pushed to your default branch.