The guardian angel for your codebase.

Find, validate, and fix vulnerabilities in code as it is written.

Get updates

One finding, from scan to fix.

deva scan .NEW / full scanCRITICAL  ledgerlens/views.py:87  ID: f_40f0dd7825c680fd34d51d04  deva.cwe-345.pickle-on-request-body | CWE-345  pickle.loads called directly on a request body / network input  without a signature check. Either replace pickle with JSON, or  verify a separate HMAC over the bytes before unpickling. deva validate f_40f0dd7825c680fd34d51d04 --llmvalidate-finding: 1/1 f_40f0dd7825c680fd34d51d04Verdict: Likely validConfidence: 99%Explanation:  The reachable import endpoint passes raw request bytes directly to  pickle.loads, with no signature verification shown. Deployment  exposure is not established. deva suggest-fix f_40f0dd7825c680fd34d51d04 --llmsuggest-fix: 1/1 f_40f0dd7825c680fd34d51d04Verdict: Fix suggestedConfidence: 94%Proposed diff (read-only):  --- a/ledgerlens/views.py  +++ b/ledgerlens/views.py  @@ -82,7 +82,7 @@   @bp.post("/report/import")   def import_report():  -    import pickle  +    import json       from flask import jsonify   -    report = pickle.loads(request.data)  +    report = json.loads(request.data)       return jsonify({"received": report})  Review redacted source lines before applying this proposed diff.

Excerpt of a real run of the Deva CLI on LedgerLens, our demo app. Paths shortened.

We're building Deva now.

Get Deva CLI and the Deva Extension for VS Code now. Join our mailing list to get more updates.