Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and suppression baselines.
Author:
- Debasis Mohanty ([email protected])
- Twitter / X: @coffeensecurity
- www.coffeeandsecurity.com
Daksh SCRA (Source Code Review Assist) is built to enhance the efficiency of the source code review process, providing a well-structured and organised approach for code reviewers.
Rather than indiscriminately flagging everything as a potential issue, Daksh SCRA promotes thoughtful analysis, urging the investigation and confirmation of potential problems. This approach mitigates the scramble to tag every potential concern as a bug, cutting back on the confusion and wasted time spent on false positives.
Daksh SCRA was initially introduced during a source code review training session at Black Hat USA 2022 (August 6-9), where it was subtly presented to a specific audience. Its official public debut took place at Black Hat USA 2023 in Las Vegas.
rdl_ref and executed by the core/rdl_engine.py pipeline - supports file-aware gates, boolean expressions, project observations, and exported logic metadata in reports.Active enhancements are ongoing. Multiple new features and improvements are planned for upcoming releases.
Feel free to contribute towards updating or adding new rules and future development.
If you find any bugs, report them to [email protected].
Detailed documentation: https://dakshlabs.com/#docs
There are two ways to run Daksh SCRA - pick whichever fits your workflow:
| Best for | Jump to | |
|---|---|---|
| π Web UI (Docker) | The easiest way to get started - one command, a browser dashboard, live scan progress, and a report/artifact browser. Recommended for most users. | Web UI (Docker) |
| π» CLI (Python) | Scripting, CI pipelines, or running scans without Docker. | CLI Setup |
Both paths run the exact same scanning engine - the Web UI is a browser front end over the same CLI, so results are identical either way.
The fastest way to run Daksh SCRA is through its browser-based Web UI, launched with the host-aware Docker startup helper. It gives you a scan launcher, a live console feed, and a browsable history of past reports. The startup helper needs Python 3 (standard library only); the application and its dependencies run in Docker.
The Docker setup runs the Web UI and the CLI as independent services built from the same image, so you can use either (or both) from the same container.
After downloading Daksh SCRA from GitHub, extract the ZIP archive first.
Open a terminal (PowerShell or Command Prompt on Windows) inside the extracted
project folder containing docker-compose.yml and dakshscra.py.
Run all startup and Docker Compose commands below from that folder.
If your terminal opens elsewhere, change into the extracted folder first:
cd "path/to/extracted/DakshSCRA-folder"
Replace the example path with your actual download location and folder name.
If you cloned the repository instead, run cd DakshSCRA from its parent folder.
The startup helper recognizes Windows, WSL, Linux and macOS, then mounts the host root, available Windows drives and common folders read-only before starting the containers. Run it on the computer running Docker.
Linux, macOS or WSL (foreground):
python3 tools/start_webui.py
Windows PowerShell or Command Prompt (foreground):
py tools/start_webui.py
Add --detach for background mode, or --dry-run to inspect detected paths.
Existing .env path overrides are respected. Accounts, scans and the runtime
volume are preserved when containers are recreated.
Docker Desktop may require permission to share the selected host paths. If it rejects a mount, allow that location in Docker Desktop and rerun the helper. A remote browser sees the Docker host's folders, not its own computer's drives. Automatic detection requires a local Docker engine; run the helper on the engine host when using a remote Docker context.
For manually configured mounts, docker compose up --build -d api web remains
available. Its baseline mounts the repository at /scan-targets and
${DAKSH_HOST_MOUNT:-/} at /host/root. Use the helper for Windows drive discovery
and common-folder shortcuts; plain Compose cannot detect the client OS.
Then open http://localhost:8080.
To use a different port:
DAKSH_PORT=9090 python3 tools/start_webui.py
Stop the stack with:
docker compose down
The Web UI requires an account. On first startup, an initial admin account is created from DAKSH_ADMIN_USERNAME / DAKSH_ADMIN_PASSWORD (set these in .env); if DAKSH_ADMIN_PASSWORD is left unset, a random password is generated and printed once to the API's startup log - save it, since it cannot be recovered afterward.
You'll be required to set your own password (and, optionally, username) the first time you log in. An admin account can create further accounts via the POST /api/v1/auth/users API endpoint (no dedicated UI for this yet). See .env.example for the full list of authentication-related settings (session lifetime, cookie security, CORS).
Under the hood, the CLI remains the source of truth - it does all the scanning and generates every HTML / PDF / JSON output. The Web UI runs one active job at a time and snapshots each completed job's outputs into runtime/webui/jobs/<job-id>/artifacts/ so past reports stay accessible.
You don't need a local Python environment to use the CLI either - it's available as its own Compose service, built from the same image:
docker compose run --rm cli -h
docker compose run --rm cli -r auto -t /scan-targets/path/to/source
reports/ and runtime/ volumesKey mount points: