Google CodeMender tightens checks and recovery for security scans
CodeMender 0.11.0 improves CI validation and interrupted scan recovery while remaining a limited public preview for testing

Google released CodeMender 0.11.0 on September 30, tightening checks and recovery around its AI security scans. The release notes describe changes to configuration, CI validation and interrupted sessions.
CodeMender combines a hosted reasoning system with a local client that reads files, runs commands and works through possible vulnerabilities. Its product documentation says access remains limited to selected customers in public preview, solely for testing and evaluation. Commercial and production use are excluded.
What changed in the scan workflow
Severity values are checked before a scan proceeds, so misspelled CI thresholds are no longer silently ignored. Service location moves from a command flag to an environment variable or configuration file.
Standalone scan, verification and repair sessions survive interruption and can be resumed. Parallel consensus workers are still cancelled. The update improves retries after rate limits and enables branch creation and cleanup within the default sandbox for architecture sessions.
Check the result after resuming
Google’s session guide documents how to inspect task status, resume from the latest checkpoint and export reports in formats including HTML, JSON and SARIF. Findings remain separate from verification and repair status, making the report a useful place to check what actually finished.
Keep the testing environment contained
The configuration guide says the built in sandbox blocks outbound network connections by default. Builds that need to fetch dependencies can therefore fail unless those dependencies are prepared beforehand. Google also cautions that the local sandbox provides less isolation than a full virtual machine, and that Windows sandbox support remains experimental.
Google says the client sends selected code snippets and tool results to the cloud reasoning service. Teams evaluating the product should account for that data flow when choosing which repository to test.
A useful first check is a small repository with a known issue and a working test suite. Confirm that an invalid severity setting is rejected, interrupt a scan, then inspect the resumed result. Keep human review in place before accepting a proposed repair.
For another recent example of reliability work in coding assistants, see our coverage of Claude Code session and tool recovery.
Illustrative archival photograph of a laptop displaying code by Mohammad Rahmani on Unsplash, used under the Unsplash License. It does not depict CodeMender.



