3 ms·
How does it work? Does the tool upload code to ChatGPT for analysis? That may not be allowed for some corporate projects.
by petilon 2mo ago
How does it work? Does the tool upload code to ChatGPT for analysis? That may not be allowed for some corporate projects.
- derac 2mo agoAmazon bedrock is an option for gpt models that does not send your data to openai.
- deleted 2mo ago[deleted]
- daishi55 2mo agoYes, I suspect companies that don’t allow ChatGPT will not be able to use the ChatGPT security analysis tool.
- dangelosaurus 2mo agoIn short, this isn't an offline scanner. The CLI runs locally but the code and context needed for analysis are sent to the hosted model (OpenAI). For API, Business, and Enterprise accounts, business data isn't used to train models by default. Retention and other data controls depend on the product and account configuration. If your company doesn't allow source code to leave its environment, you shouldn't run this against that codebase. Local and third-party endpoints aren't officially supported yet, but you can read through the code and your favorite coding agent will allow you to use it with any model of your choice in 30 seconds. More on OpenAI's enterprise data handling: https://openai.com/enterprise-privacy/ https://openai.com/enterprise-privacy/
- raylad 2mo agoAnything you ever do with any non-locally-hosted model always "uploads code" to the inference provider because that's how it works: the model uses tools to inspect the code, the result of the tool use is sent in an API call to provide context (and a prompt for the next turn), and then the response continues the process. This is true and has to be true for any hosted model that works with existing code: it's not specific to this application.