Todas las etiquetas
Etiqueta del catálogo

#sarif

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

47 registros
Con la etiqueta «sarif»Ordenado por índice de salud
npm
60Moderadoíndice de salud
calllint/calllint
Pre-flight risk linting for MCP and agent tools — check the blast radius before your agent runs them.
TypeScript · HTML★ 2↓ 3504/mes31 jul 2026
Apache-2.031 jul 2026 · métricas 2.10.0
Go
59Moderadoíndice de salud
rudrendupaul/tenantguard
CLI security scanner for self-hosted multi-tenant AI-agent platforms. 16 fail-closed OPA/Rego rules catch tenant-isolation defects (sandbox scoping, SSRF, cross-tenant cron/auth, secret leakage). SARIF and JSON output for CI.
Go · Open Policy Agent★ 015 jul 2026
Apache-2.015 jul 2026 · métricas 2.10.0
Go
59Moderadoíndice de salud
skyway-harness-builder/workflow-lint
Standalone open-source linter for Skylence .sky workflow files
Go★ 021 jul 2026
Apache-2.021 jul 2026 · métricas 2.10.0
Go
57Moderadoíndice de salud
kidoz/vulners-cli
CLI vulnerability scanner powered by Vulners — search, audit, scan, offline mode
Go★ 617 jul 2026
MIT17 jul 2026 · métricas 2.10.0
PyPI · crates.io · Maven +2
57Moderadoíndice de salud
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 1217 jul 2026
Licencia propia17 jul 2026 · métricas 2.10.0
crates.io
57Moderadoíndice de salud
tacticaldoll/tianheng
Reactive architectural governance for Rust — declare boundaries in Rust, react to drift in CI and at runtime. The 三儀: 圭表 (static) · 渾儀 (semantic) · 漏刻 (runtime). Govern by reaction, not instruction. On crates.io as the tianheng family.
Rust★ 0↓ 16.6K/mes29 jul 2026
Apache-2.029 jul 2026 · métricas 2.10.0
PyPI · npm · crates.io
53Moderadoíndice de salud
JunHwan-Kwon/deepbom
Local static analysis and evidence generation for deployed AI model artifacts
JavaScript · Rust★ 2↓ 3094/mes4 sept 2026
Apache-2.04 sept 2026 · métricas 2.10.0
npm
51Moderadoíndice de salud
nsasoft/nsauditor-ai
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 20↓ 3215/mes6 sept 2026
MIT6 sept 2026 · métricas 2.10.0
Go
50Moderadoíndice de salud
bunta-expert/git-path-audit
Read-only CLI that finds Git paths that collide, change meaning, or fail to check out across Windows, macOS, and Linux.
Go★ 15 sept 2026
MIT5 sept 2026 · métricas 2.10.0
Packagist
50Moderadoíndice de salud
phpcpd-next/phpcpd
phpcpd-next is a token-based copy/paste (clone) detector for PHP 8.5+, a modernized, openly-licensed successor to Sebastian Bergmann's phpcpd
PHP★ 34↓ 2961/mes18 ago 2026
BSD-3-Clause18 ago 2026 · métricas 2.10.0
npm
48Débilíndice de salud
BenAHammond/code-auditor-mcp
Architectural invariants and code quality analysis, enforced inside your AI agent's edit loop. MCP server + CLI + Claude Code plugin. TypeScript, JavaScript, Go.
TypeScript★ 7↓ 5432/mes26 jul 2026
MIT26 jul 2026 · métricas 2.10.0
npm
48Débilíndice de salud
criticaldeveloper/critical-gate
El repositorio no publica descripción.
TypeScript★ 1↓ 3922/mes16 jul 2026
MIT16 jul 2026 · métricas 2.10.0
Packagist
42Débilíndice de salud
jbelien/phpstan-sarif-formatter
SARIF formatter for PHPStan
PHP★ 13↓ 17.3K/mes29 jul 2026
MIT29 jul 2026 · métricas 2.10.0
Go
42Débilíndice de salud
safetylab/ShadowSecurityScanner
Free, open-source network vulnerability scanner & penetration testing tool that ranks findings by real-world exploitability (EPSS + CISA KEV). Single desktop app for Windows, macOS, Linux. No cloud, no telemetry. MIT.
Go★ 021 jul 2026
MIT21 jul 2026 · métricas 2.10.0
npm
41Débilíndice de salud
nsasoft/nsauditor-ai-agent-skill
AI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows. Works with Claude Code, Cursor, Windsurf, and any MCP-aware agent.
JavaScript★ 4↓ 7235/mes6 sept 2026
MIT6 sept 2026 · métricas 2.10.0
npm
39Débilíndice de salud
KaraboGerald/SeamShieldCLI
SeamShield Community CLI: local-first access-lane scanning for AI-built apps
TypeScript · JavaScript★ 0↓ 2130/mes4 ago 2026
MIT4 ago 2026 · métricas 2.10.0
Go
33En riesgoíndice de salud
tamish560/mcprobe
Security scanner and introspection tool for MCP servers. Connect, inspect, detect injection patterns, find tool shadowing, baseline for drift. Single binary, zero dependencies, Go stdlib only.
Go★ 220 jul 2026
MIT20 jul 2026 · métricas 2.10.0