Todas las etiquetas
Etiqueta del catálogo

#sarif

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

47 registros
Con la etiqueta «sarif»Ordenado por índice de salud
PyPI · npm
94Excepcionalíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
PyPI · npm
94Excepcionalíndice de salud
sattyamjjain/agent-audit-kit
Static scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2808/mes2 ago 2026
MIT2 ago 2026 · métricas 2.10.0
npm
91Excelenteíndice de salud
Siteimprove/alfa
:wheelchair: Suite of open and standards-based tools for performing reliable accessibility conformance testing at scale
HTML · TypeScript★ 130↓ 96.3K/mes31 jul 2026
MIT31 jul 2026 · métricas 2.10.0
PyPI
87Excelenteíndice de salud
Cranot/roam-code
Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 238 commands, 224 MCP tools, change-safety gates, audit evidence, zero API keys.
Python★ 498↓ 5430/mes15 jul 2026
Apache-2.015 jul 2026 · métricas 2.10.0
Go
86Excelenteíndice de salud
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 024 jul 2026
Apache-2.024 jul 2026 · métricas 2.10.0
Go · PyPI
86Excelenteíndice de salud
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
npm
86Excelenteíndice de salud
microsoft/axe-sarif-converter
An axe-core reporter that outputs axe scan results in SARIF format (http://sarifweb.azurewebsites.net/)
TypeScript★ 38↓ 76.1K/mes21 jul 2026
MIT21 jul 2026 · métricas 2.10.0
npm
86Excelenteíndice de salud
ofri-peretz/eslint
Security & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/mes25 jul 2026
MIT25 jul 2026 · métricas 2.10.0
npm · PyPI
84Excelenteíndice de salud
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 7189/mes22 ago 2026
AGPL-3.022 ago 2026 · métricas 2.10.0
PyPI
84Excelenteíndice de salud
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 5022 ago 2026
Licencia propia22 ago 2026 · métricas 2.10.0
Go
81Excelenteíndice de salud
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 823 jul 2026
Apache-2.023 jul 2026 · métricas 2.10.0
npm · crates.io
78Buenoíndice de salud
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6899/mes17 jul 2026
MIT17 jul 2026 · métricas 2.10.0
npm
78Buenoíndice de salud
Null-Square/Null-CLi
Open-source AI pentest and compliance-readiness CLI by NullSquare.
TypeScript · JavaScript★ 81↓ 147/mes4 ago 2026
Licencia propia4 ago 2026 · métricas 2.10.0
PyPI
78Buenoíndice de salud
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1928/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
PyPI
78Buenoíndice de salud
justinchuby/lintrunner-adapters
Adapters and tools for lintrunner
Python★ 6↓ 940.1K/mes21 jul 2026
Licencia propia21 jul 2026 · métricas 2.10.0
Go
77Buenoíndice de salud
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
npm · PyPI
77Buenoíndice de salud
raccioly/docguard
The enforcement tool for Canonical-Driven Development (CDD). Audit, generate, and guard your project documentation. Zero dependencies.
JavaScript★ 21↓ 5005/mes21 jul 2026
MIT21 jul 2026 · métricas 2.10.0
npm · Go
73Buenoíndice de salud
HodeTech/Leakwatch
High-performance open-source secret scanner — detect, verify & report leaked API keys, tokens & credentials in code, Git history, container images, and the cloud.
Go★ 2↓ 46/mes27 jul 2026
MIT27 jul 2026 · métricas 2.10.0
npm · PyPI
73Buenoíndice de salud
oaslananka/boardreadyops
End-to-end hardware release pipeline for KiCad: generate, validate, sign, and package manufacturer-ready releases as a CLI and GitHub Action.
TypeScript★ 3↓ 3738/mes17 jul 2026
MIT17 jul 2026 · métricas 2.10.0
npm
73Buenoíndice de salud
stainless-code/codemap
Cut AI-agent token waste ~90% — query a local SQLite structural index of your JS/TS/CSS codebase with SQL in one round-trip instead of 3–5 file reads. Symbols, imports, calls, components, CSS tokens, coverage, markers. CLI, MCP (21 tools), HTTP, GitHub Action, ESM API. 71 recipes; AST+resolver; SARIF/audit/baselines for CI.
TypeScript★ 8↓ 8315/mes26 jul 2026
MIT26 jul 2026 · métricas 2.10.0
Go
71Buenoíndice de salud
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 255 sept 2026
Licencia propia5 sept 2026 · métricas 2.10.0
npm
71Buenoíndice de salud
YawLabs/ctxlint
Lint your AI agent context files (CLAUDE.md, AGENTS.md, etc.) against your actual codebase
TypeScript★ 7↓ 21.4K/mes6 ago 2026
MIT6 ago 2026 · métricas 2.10.0
npm
69Buenoíndice de salud
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6125/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
PyPI
67Buenoíndice de salud
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 231 jul 2026
MIT31 jul 2026 · métricas 2.10.0
Go
67Buenoíndice de salud
tiagosilva07/zyrax-guard
Audit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 228 ago 2026
MIT28 ago 2026 · métricas 2.10.0
Packagist · npm
65Buenoíndice de salud
blundergoat/gruff-php
Opinionated PHP code-quality analyzer that scores findings across quality pillars and emits reports for terminals, CI, SARIF, HTML, and a local dashboard.
PHP★ 1↓ 8483/mes16 jul 2026
MIT16 jul 2026 · métricas 2.10.0
Go · npm
62Moderadoíndice de salud
LarsArtmann/art-dupl
Professional code clone detection for Go. AST-based structural + semantic detection with suffix tree algorithms, 3 matching modes, 7 output formats, templ support, and CI baseline gating.
Go★ 231 ago 2026
Licencia propia31 ago 2026 · métricas 2.10.0
Go
62Moderadoíndice de salud
git-pkgs/sarif
Go library for reading, writing, and validating SARIF 2.1.0 logs
Go★ 115 jul 2026
MIT15 jul 2026 · métricas 2.10.0
Go
62Moderadoíndice de salud
icearp/disco-cli
Discover, map & secure AWS, Azure, & GCP. Scan resources and their relationships into a local inventory, visualize the graph, and run OPA policy checks with SARIF output.
Go★ 130 ago 2026
MIT30 ago 2026 · métricas 2.10.0
Go
62Moderadoíndice de salud
kanywst/brtc
Cost calculator for offline password brute-force attacks: time + USD per GPU profile, with a CI gatekeeper.
Go★ 026 jul 2026
MIT26 jul 2026 · métricas 2.10.0