Security and SAST Remediation Improvements

  • Enabling comprehensive security analysis directly from context within GitHub Checks.
  • CodeRabbit now seamlessly integrates with top SAST tools that create github check annotation comments such as: Codacy, SonarCloud, Code Climate, GitHub Advanced Security, Palo Alto Prisma Cloud, and more!
  • We have added a YouTube Tutorial for a step-by-step guide on using CodeRabbit with Codacy and SonarCloud during pull requests.
  • Improved the Semgrep Documentation.
  • CodeRabbit now automatically detects Semgrep rulesets from default semgrep.yml or semgrep.config.yml files, eliminating the need for manual configuration.