Todas las etiquetas
Etiqueta del catálogo

#sarif

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

27 registros
Con la etiqueta «sarif»Ordenado por índice de salud
PyPI · npm
80Buenoíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
PyPI
73Buenoíndice de salud
Cranot/roam-code
Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 238 commands, 224 MCP tools, change-safety gates, audit evidence, zero API keys.
Python★ 498↓ 5430/mes15 jul 2026
Apache-2.015 jul 2026 · métricas 1.13.0
npm
72Buenoíndice de salud
microsoft/axe-sarif-converter
An axe-core reporter that outputs axe scan results in SARIF format (http://sarifweb.azurewebsites.net/)
TypeScript★ 38↓ 76.1K/mes21 jul 2026
MIT21 jul 2026 · métricas 1.13.0
npm · PyPI
71Buenoíndice de salud
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 14.1K/mes14 jul 2026
AGPL-3.014 jul 2026 · métricas 1.13.0
Go · PyPI
71Buenoíndice de salud
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
PyPI
68Moderadoíndice de salud
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1928/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
PyPI
68Moderadoíndice de salud
justinchuby/lintrunner-adapters
Adapters and tools for lintrunner
Python★ 6↓ 940.1K/mes21 jul 2026
Licencia propia21 jul 2026 · métricas 1.13.0
npm · crates.io
67Moderadoíndice de salud
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6899/mes17 jul 2026
MIT17 jul 2026 · métricas 1.13.0
PyPI
67Moderadoíndice de salud
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/mes14 jul 2026
Licencia propia14 jul 2026 · métricas 1.13.0
Go
66Moderadoíndice de salud
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 821 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
Go
65Moderadoíndice de salud
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
npm · PyPI
65Moderadoíndice de salud
raccioly/docguard
The enforcement tool for Canonical-Driven Development (CDD). Audit, generate, and guard your project documentation. Zero dependencies.
JavaScript★ 21↓ 5005/mes21 jul 2026
MIT21 jul 2026 · métricas 1.13.0
npm · PyPI
63Moderadoíndice de salud
oaslananka/boardreadyops
End-to-end hardware release pipeline for KiCad: generate, validate, sign, and package manufacturer-ready releases as a CLI and GitHub Action.
TypeScript★ 3↓ 3738/mes17 jul 2026
MIT17 jul 2026 · métricas 1.13.0
npm
61Moderadoíndice de salud
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6125/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Packagist · npm
60Moderadoíndice de salud
blundergoat/gruff-php
Opinionated PHP code-quality analyzer that scores findings across quality pillars and emits reports for terminals, CI, SARIF, HTML, and a local dashboard.
PHP★ 1↓ 8483/mes16 jul 2026
MIT16 jul 2026 · métricas 1.13.0
Go
57Moderadoíndice de salud
git-pkgs/sarif
Go library for reading, writing, and validating SARIF 2.1.0 logs
Go★ 115 jul 2026
MIT15 jul 2026 · métricas 1.13.0
PyPI · crates.io · Maven +2
56Moderadoíndice de salud
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 1217 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
Go
56Moderadoíndice de salud
rudrendupaul/tenantguard
CLI security scanner for self-hosted multi-tenant AI-agent platforms. 16 fail-closed OPA/Rego rules catch tenant-isolation defects (sandbox scoping, SSRF, cross-tenant cron/auth, secret leakage). SARIF and JSON output for CI.
Go · Open Policy Agent★ 015 jul 2026
Apache-2.015 jul 2026 · métricas 1.13.0
Go
56Moderadoíndice de salud
skyway-harness-builder/workflow-lint
Standalone open-source linter for Skylence .sky workflow files
Go★ 021 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
Go
56Moderadoíndice de salud
vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Open Policy Agent · Go★ 25↓ 0/mes14 jul 2026
Licencia propia14 jul 2026 · métricas 1.13.0
Go
55Moderadoíndice de salud
kidoz/vulners-cli
CLI vulnerability scanner powered by Vulners — search, audit, scan, offline mode
Go★ 617 jul 2026
MIT17 jul 2026 · métricas 1.13.0
Go
49En riesgoíndice de salud
bunta-expert/git-path-audit
Read-only CLI that finds Git paths that collide, change meaning, or fail to check out across Windows, macOS, and Linux.
Go★ 1↓ 0/mes14 jul 2026
MIT14 jul 2026 · métricas 1.13.0
npm
48En riesgoíndice de salud
criticaldeveloper/critical-gate
El repositorio no publica descripción.
TypeScript★ 1↓ 3922/mes16 jul 2026
MIT16 jul 2026 · métricas 1.13.0
Go
45En riesgoíndice de salud
safetylab/ShadowSecurityScanner
Free, open-source network vulnerability scanner & penetration testing tool that ranks findings by real-world exploitability (EPSS + CISA KEV). Single desktop app for Windows, macOS, Linux. No cloud, no telemetry. MIT.
Go★ 021 jul 2026
MIT21 jul 2026 · métricas 1.13.0
npm
43En riesgoíndice de salud
nsasoft/nsauditor-ai
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 19↓ 5644/mes15 jul 2026
MIT15 jul 2026 · métricas 1.13.0
Go
38En riesgoíndice de salud
tamish560/mcprobe
Security scanner and introspection tool for MCP servers. Connect, inspect, detect injection patterns, find tool shadowing, baseline for drift. Single binary, zero dependencies, Go stdlib only.
Go★ 220 jul 2026
MIT20 jul 2026 · métricas 1.13.0
npm
35En riesgoíndice de salud
nsasoft/nsauditor-ai-agent-skill
AI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows. Works with Claude Code, Cursor, Windsurf, and any MCP-aware agent.
Mixto★ 3↓ 4001/mes15 jul 2026
MIT15 jul 2026 · métricas 1.13.0