AI coding agents by language

DevFlow documents 7 stacks: 6 with a dependency scanner, 2 container images, and one set of test limits shared by all.

Languages

When scans run

Each audit runs when a task finishes and again on recurring vulnerability polls, stops after 300 seconds by default, and never blocks a gate. For Python, Rust, .NET and the JVM, detection walks a bounded tree and skips .git, node_modules and build output; Go and Node look only at the repo root.

Images

6 of the 7 stacks run in devflow/agent-universal:stable, which ships Go, Node, Python, Rust, the .NET SDK and a JDK with Maven. Flutter repos get a separate SDK build, pinned to the release in .fvmrc when that version has been built.

Shared limits

Every gate runs only the commands you configure, in a non-root container capped by default at 4 CPUs, 4 GB of memory (6 GB with swap) and 512 processes. Agents write only inside the task worktree.

FAQ

Which stacks have no dependency scanner?

Flutter: DevFlow has no scanner for it yet. The other 6 each have one, run when a task finishes and on recurring polls.

Can a repo use its own image?

Yes. A workspace owner can confirm another image per repo in Workspace Settings, as long as its registry passes the image allowlist.

Do all stacks share the same test limits?

Yes. The caps below apply to every gate, whatever the language; an owner can change them only server-wide.