Skip to content
Draft
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ rss_href: /feed_rss_created.xml

# Adding GolangCI-Lint as new supported tool – January 2026

**GolangCI-Lint (client-side):** Run GolangCI-Lint locally on your Go projects and upload the results to Codacy for analysis and reporting.

## GolangCI-Lint (Client-side Go tool)

Expand Down
2 changes: 2 additions & 0 deletions docs/release-notes/cloud/cloud-2026-01.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@

📢 [Visit the Codacy roadmap](https://roadmap.codacy.com) and <span class="skip-vale">let us know</span> your feedback on both new and planned product updates!

**GolangCI-Lint integration:** We've built a new GolangCI-Lint wrapper that runs over 100 linters in a single pass, extending how much of your Go code Codacy can check in one analysis. Also this month: a dedicated VS Code setup section and a step-by-step walkthrough guide new users through configuring the extension.

Check failure on line 16 in docs/release-notes/cloud/cloud-2026-01.md

View workflow job for this annotation

GitHub Actions / vale

[vale] reported by reviewdog 🐶 [Vale.Spelling] Did you really mean 'walkthrough'? Raw Output: {"message": "[Vale.Spelling] Did you really mean 'walkthrough'?", "location": {"path": "docs/release-notes/cloud/cloud-2026-01.md", "range": {"start": {"line": 16, "column": 256}}}, "severity": "ERROR"}

## Product enhancements

**New Features**
Expand Down
2 changes: 2 additions & 0 deletions docs/release-notes/cloud/cloud-2026-02-migrating-semgrep.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@

# Semgrep to Opengrep migration – February 2026

**Semgrep to Opengrep:** Following licensing changes to Semgrep, Codacy switched to Opengrep as a 1:1 replacement, preserving all existing patterns, issue history, and configuration.

Check failure on line 9 in docs/release-notes/cloud/cloud-2026-02-migrating-semgrep.md

View workflow job for this annotation

GitHub Actions / vale

[vale] reported by reviewdog 🐶 [Vale.Spelling] Did you really mean 'Semgrep'? Raw Output: {"message": "[Vale.Spelling] Did you really mean 'Semgrep'?", "location": {"path": "docs/release-notes/cloud/cloud-2026-02-migrating-semgrep.md", "range": {"start": {"line": 9, "column": 57}}}, "severity": "ERROR"}

As we previously discussed on our [blog](https://blog.codacy.com/opengrep-vs-semgrep), there have been licensing changes to Semgrep, and Opengrep has emerged as an open-source fork of the Semgrep engine. To ensure your continued access to the existing patterns we have switched to Opengrep.

This change has been performed as a 1:1 replacement, preserving all existing patterns, issue history, and configuration. Going forward, we'll also be able to keep delivering custom Codacy rules to protect you against emerging threats, such as [hidden Unicode character vulnerabilities in rules files](https://blog.codacy.com/vulnerability-in-rules-files-with-hidden-unicode-characters).
2 changes: 2 additions & 0 deletions docs/release-notes/cloud/cloud-2026-02.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@

📢 [Visit the Codacy roadmap](https://roadmap.codacy.com) and <span class="skip-vale">let us know</span> your feedback on both new and planned product updates!

**Migration from Semgrep to Opengrep:** Following licensing changes to Semgrep, we've moved to Opengrep, an open-source fork of the same engine, so your existing code patterns and workflows keep working without interruption. Also this month: a new Organization Overview Dashboard surfaces health, security, grade, complexity, duplication, and coverage metrics across your organization, alongside a fix to pattern filtering and a new text search for SRM findings.

Check failure on line 16 in docs/release-notes/cloud/cloud-2026-02.md

View workflow job for this annotation

GitHub Actions / vale

[vale] reported by reviewdog 🐶 [Vale.Spelling] Did you really mean 'Semgrep'? Raw Output: {"message": "[Vale.Spelling] Did you really mean 'Semgrep'?", "location": {"path": "docs/release-notes/cloud/cloud-2026-02.md", "range": {"start": {"line": 16, "column": 72}}}, "severity": "ERROR"}

## Product enhancements

- **Migration from Semgrep to Opengrep**: In response to recent licensing changes affecting Semgrep, we have transitioned to Opengrep, an open-source fork of the Semgrep engine. This update ensures uninterrupted access to your existing code patterns and continued support for your workflows. (CF-2184)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,8 @@

We are making two changes to the GitHub integration settings over the coming weeks. Both are handled automatically - you don't need to take any action.

**GitHub integration changes:** AI-enhanced comments (Beta) are being replaced by the AI Reviewer on March 17, 2026, and the Coverage summary setting is being folded into the Pull request review comment — both migrations happen automatically.

Check failure on line 12 in docs/release-notes/cloud/cloud-2026-03-github-integration-settings-changes.md

View workflow job for this annotation

GitHub Actions / vale

[vale] reported by reviewdog 🐶 [Microsoft.Dashes] Remove the spaces around ' — '. Raw Output: {"message": "[Microsoft.Dashes] Remove the spaces around ' — '.", "location": {"path": "docs/release-notes/cloud/cloud-2026-03-github-integration-settings-changes.md", "range": {"start": {"line": 12, "column": 203}}}, "severity": "ERROR"}

- [**AI-enhanced comments (Beta) being deprecated for GitHub**](#ai-enhanced-comments) — AI-enhanced comments are being replaced by the [AI Reviewer](../../codacy-ai/codacy-ai.md#pr-reviewer) on March 17, 2026.
- [**Coverage summary moving to Pull request review**](#coverage-summary) — the Coverage summary setting is being removed; coverage data will soon be included in the Pull request review comment.

Expand Down
2 changes: 2 additions & 0 deletions docs/release-notes/cloud/cloud-2026-03.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@

📢 [Visit the Codacy roadmap](https://roadmap.codacy.com) and <span class="skip-vale">let us know</span> your feedback on both new and planned product updates!

**AI security and privacy safeguards:** The AI reviewer and false positive detection now automatically mask secrets or credentials accidentally pushed in code, before that code reaches AI models. Also this month: a `review.md` file lets you tune the AI Reviewer's output with your own conventions, a manual "Run review" button gives you control over when it runs, and the AI Reviewer now flags gaps in test coverage with a ready-to-use prompt for your coding agent.

Check warning on line 16 in docs/release-notes/cloud/cloud-2026-03.md

View workflow job for this annotation

GitHub Actions / vale

[vale] reported by reviewdog 🐶 [Microsoft.Adverbs] Consider removing 'accidentally'. Raw Output: {"message": "[Microsoft.Adverbs] Consider removing 'accidentally'.", "location": {"path": "docs/release-notes/cloud/cloud-2026-03.md", "range": {"start": {"line": 16, "column": 132}}}, "severity": "WARNING"}

## Product enhancements

- **AI Security & Privacy Safeguards:** The AI reviewer and false positive detection now automatically mask any secrets or credentials accidentally pushed in code. This ensures that sensitive data is protected before it is processed by AI models, adding an extra layer of security to your workflow. (CF-2337)
Expand Down
2 changes: 2 additions & 0 deletions docs/release-notes/cloud/cloud-2026-04.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@ These release notes are for the Codacy Cloud updates during April 2026.

📢 [Visit the Codacy roadmap](https://roadmap.codacy.com) and <span class="skip-vale">let us know</span> your feedback on both new and planned product updates!

**Context-aware feedback loops:** The AI Reviewer (GitHub only) now factors in earlier comments across a pull request's lifetime, so later reviews build on the conversation instead of repeating themselves. Also this month: the new Pull Request Summary Experience replaces the legacy coverage summary settings, language filtering on the Issues page now isolates results correctly, and a fix restores Prospector's handling of custom configuration files.

## Product enhancements

- **Context-Aware Feedback Loops:** The AI Reviewer (GitHub only) now factors in previous comments throughout the life of a Pull Request. By learning from the conversation history, it delivers more relevant feedback and significantly reduces noise with every subsequent review. (CF-2377)
Expand Down
2 changes: 2 additions & 0 deletions docs/release-notes/cloud/cloud-2026-05.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@

📢 [Visit the Codacy roadmap](https://roadmap.codacy.com) and <span class="skip-vale">let us know</span> your feedback on both new and planned product updates!

**Draft PR AI review control:** The PR reviewer no longer runs automatically on draft pull requests — trigger it manually from the summary page when you want a review. Also this month: AI suggestions in GitHub are deprecated in favor of the PR reviewer, AI Inventory access moves to Business Tier accounts, and YAML analysis now covers `.env`, `.env.production`, `.env.prod`, and `.env.staging` files.

Check failure on line 16 in docs/release-notes/cloud/cloud-2026-05.md

View workflow job for this annotation

GitHub Actions / vale

[vale] reported by reviewdog 🐶 [Microsoft.Dashes] Remove the spaces around ' — '. Raw Output: {"message": "[Microsoft.Dashes] Remove the spaces around ' — '.", "location": {"path": "docs/release-notes/cloud/cloud-2026-05.md", "range": {"start": {"line": 16, "column": 100}}}, "severity": "ERROR"}

## Product enhancements

- **Draft PR AI Review Control:** The PR reviewer no longer runs automatically for draft PRs. Please trigger it manually using the button on the summary if you want a review. (CF-2354)
Expand Down
2 changes: 2 additions & 0 deletions docs/release-notes/cloud/cloud-2026-06.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@ These release notes are for the Codacy Cloud updates during June 2026.

📢 [Visit the Codacy roadmap](https://roadmap.codacy.com) and <span class="skip-vale">let us know</span> your feedback on both new and planned product updates!

**Import chain visibility for vulnerable dependencies:** Codacy now shows the dependency chain behind a vulnerability, so you can see how it was introduced into your project rather than just that it exists. Also this month: the CI/CD setup option for container scanning is easier to find, and Guardrails now supports proxy configurations for restricted network environments.

### Features
- **Import chain visibility for vulnerable dependencies (OD-105):** We added clearer dependency chain visibility so users can better understand how vulnerable dependencies are introduced into their projects.
- **Better visibility for CI/CD setup in container scanning (OD-124):** We made the CI/CD setup option more prominent in container scanning so teams can find and enable it more easily.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ rss_href: /feed_rss_created.xml

# Adding PHP CS Fixer as new supported tool – July 2026

**PHP CS Fixer and Checkov configuration files:** PHP CS Fixer joins Codacy's supported tools for PHP style violations, and Checkov analysis can now be configured with a `.checkov.yaml` or `.checkov.yml` file in your repository.

## PHP CS Fixer

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,8 @@

We’ve upgraded how Shellcheck works on Codacy! While you previously had to configure Shellcheck analysis directly through the Codacy UI, you can now manage your settings using a configuration file.

**Shellcheck configuration files:** You can now manage Shellcheck settings with a `.shellcheckrc` file in your repository instead of configuring analysis directly through the Codacy UI.

Check failure on line 10 in docs/release-notes/cloud/cloud-2026-07-adding-shellcheck-config-file.md

View workflow job for this annotation

GitHub Actions / vale

[vale] reported by reviewdog 🐶 [Vale.Terms] Use 'ShellCheck' instead of 'Shellcheck'. Raw Output: {"message": "[Vale.Terms] Use 'ShellCheck' instead of 'Shellcheck'.", "location": {"path": "docs/release-notes/cloud/cloud-2026-07-adding-shellcheck-config-file.md", "range": {"start": {"line": 10, "column": 56}}}, "severity": "ERROR"}

Codacy will automatically apply your rules during analysis once you set it up.
Here is how to get started:

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,8 @@

We know how important your current workflows and rule configurations are. However, to successfully complete this upgrade, we have encountered hard compatibility constraints with several older, unmaintained coding standard packages. To move forward, we must officially remove support for these legacy packages and their associated rules.

**PHP_CodeSniffer upgrade:** PHP_CodeSniffer is upgrading to its latest version, which drops support for several unmaintained coding standard packages, including the WordPress-VIP, Magento, and PHPCS Security Audit rule sets.

Check failure on line 12 in docs/release-notes/cloud/cloud-2026-07-remove-codesniffer-packages.md

View workflow job for this annotation

GitHub Actions / vale

[vale] reported by reviewdog 🐶 [Vale.Spelling] Did you really mean 'Magento'? Raw Output: {"message": "[Vale.Spelling] Did you really mean 'Magento'?", "location": {"path": "docs/release-notes/cloud/cloud-2026-07-remove-codesniffer-packages.md", "range": {"start": {"line": 12, "column": 182}}}, "severity": "ERROR"}

## Packages Being Removed

The following packages are incompatible with the latest PHP_CodeSniffer version or are no longer maintained, and will be dropped in this release:
Expand Down
2 changes: 2 additions & 0 deletions docs/release-notes/cloud/cloud-2026-07.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,8 @@

📢 [Visit the Codacy roadmap](https://roadmap.codacy.com) and <span class="skip-vale">let us know</span> your feedback on both new and planned product updates!

**Folder-level metrics:** You can now browse a repository by folder and see quality metrics — issues, complexity, coverage, and duplication — scoped to each directory, with folder navigation, search, and branch-keyed overviews. Also this month: security findings now surface the affected entrypoint functions for a vulnerable dependency, a new filter bar on the Pull Requests page lets you search by title and branch, and PHP CS Fixer joins the supported tools.

Check failure on line 15 in docs/release-notes/cloud/cloud-2026-07.md

View workflow job for this annotation

GitHub Actions / vale

[vale] reported by reviewdog 🐶 [Microsoft.Dashes] Remove the spaces around ' — '. Raw Output: {"message": "[Microsoft.Dashes] Remove the spaces around ' — '.", "location": {"path": "docs/release-notes/cloud/cloud-2026-07.md", "range": {"start": {"line": 15, "column": 140}}}, "severity": "ERROR"}

Check failure on line 15 in docs/release-notes/cloud/cloud-2026-07.md

View workflow job for this annotation

GitHub Actions / vale

[vale] reported by reviewdog 🐶 [Microsoft.Dashes] Remove the spaces around ' — '. Raw Output: {"message": "[Microsoft.Dashes] Remove the spaces around ' — '.", "location": {"path": "docs/release-notes/cloud/cloud-2026-07.md", "range": {"start": {"line": 15, "column": 92}}}, "severity": "ERROR"}

### Features
- **Folder-Level Metrics:** Users can now browse their repositories by folder and view quality metrics-issues, complexity, coverage, and duplication - scoped to each directory. Folder navigation, search, and branch-keyed overviews are all included. (OD-179, OD-180, OD-181, OD-183, OD-264)

Expand Down
2 changes: 2 additions & 0 deletions docs/release-notes/cloud/cloud-2026-08.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,8 @@ These release notes are for the Codacy Cloud updates during August 2026.

📢 [Visit the Codacy roadmap](https://roadmap.codacy.com) and <span class="skip-vale">let us know</span> your feedback on both new and planned product updates!

**Repository tokens for API v3:** Scoped repository tokens are now fully supported end-to-end — create, list, delete (single and bulk), and expiration — across all features of the product, with mandatory token lifetimes enforced in both the API and the SPA. Also this month: new search and branch-scope filters land on the Pull Requests page, and a Dart adapter closes a parity gap for Dart projects in the Analysis CLI.

### Features
- **Repository (Project) Tokens for API v3:** Full rollout of scoped repository tokens — creation, listing, deletion (single & bulk), and expiration is now supported end-to-end across all features of our product.

Expand Down
2 changes: 2 additions & 0 deletions docs/release-notes/cloud/cloud-2026-09-adding-oxlint.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,8 @@ rss_href: /feed_rss_created.xml

We're excited to announce support for [Oxlint](https://github.com/oxc-project/oxc), a fast Rust-based linter for JavaScript and TypeScript from the Oxc project. With this addition, Codacy can now automatically analyze your JavaScript and TypeScript projects for correctness, style, and best-practice issues (among other categories), reporting them directly in your dashboard.

**Oxlint support:** Codacy can now analyze your JavaScript and TypeScript projects with Oxlint, a fast Rust-based linter from the Oxc project, and report results directly in your dashboard.

**Why it matters:**

* Oxlint is built for speed, running significantly faster than traditional JS/TS linters.
Expand Down
Loading
Loading