Aster does
- Read only the repositories you choose
- Read a pinned snapshot, in memory
- Show the file, line and evidence for each finding
- Show the maximum credit cost before a fix runs
- Open a draft pull request after you confirm
HOW IT WORKS
Connect GitHub, read the evidence, and decide what ships. Every step below is one you can see, and the important ones wait for you.
THE JOURNEY
Steps one to five are your free audit. Fixes come with paid plans, and nothing reaches your repository until you confirm it.
Install the Aster Code Audit App. It asks for Contents: read and Metadata: read. Nothing more.
Only the repositories you share with the App appear. Revoke access in GitHub whenever you like.
Aster pins one commit and reads up to 80 text files and 2 MiB into memory. Nothing is cloned, installed or executed.
What is read, exactlyStatic checks for risky patterns, credential patterns, client and server boundaries, and syntax. You can leave the page while it works.
Each finding points to a file and a line, with the evidence and a next step in plain language. Every finding is included on the free audit.
Anatomy of a findingPick a supported model for each fix. The maximum credit cost is shown before anything runs, and the code goes only to the provider you chose.
Supported modelsAster proposes a focused change. You read the full diff and its validation status, then decide.
Publishing uses the separately authorized Aster Fixes App. It opens a draft. Nothing is merged automatically.
You review and merge on GitHub. A new audit of the merged code is what confirms the change, not the merge itself.
Step demos are illustrations with an example repository. Your results will differ.
ANATOMY OF A FINDING
app/api/search.ts · line 9
8 const term = req.query.q9 return db.$queryRawUnsafe("… '" + term + "'")
A value from the request is added straight into a SQL string.
Use a parameterized query so the value can’t change the query.
High, Medium or Low tells you where to start. It is a review priority; Aster does not reproduce runtime exploits.
The exact place in the pinned commit, so you can open it straight in your editor.
The lines that matched, in context. Secret-like values are redacted from findings.
One plain sentence about the pattern, written for the person who has to fix it.
A suggested action. On paid plans, you can turn it into a proposed fix to review.
CLEAR BOUNDARIES
Permissions, retention and limits in full: Trust & scope
QUESTIONS
Yes. Connect GitHub, choose the repositories shared with the Aster App, and run your first read-only source audit. Paid memberships add AI-assisted fixes.
No. You can leave the dashboard while an audit runs and come back to its progress or the saved report.
You can, and you should use the review tools you already have. Aster adds a repeatable workflow: source checks, clear evidence, proposed changes and a visible validation status.
No. The audit connection is read-only. To publish a fix, you separately authorize Aster Fixes on selected repositories and confirm the change. It creates a new branch and a draft pull request; nothing is merged automatically.
No. Any automated review has limits. Reports explain scope and skipped files, and critical systems may still need specialist review.
Your first repository audit is free. Pro is $49 a month, or $294 billed yearly. Team is $99 a month, or $594 billed yearly. Compare plans
Connect GitHub, choose a repository, and read what comes back. Your first audit is free.