Todas las etiquetas
Etiqueta del catálogo

#sast

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

19 registros
Con la etiqueta «sast»Ordenado por índice de salud
PyPI
78Buenoíndice de salud
semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
OCaml · Python★ 16K↓ 14/mes21 jul 2026
LGPL-2.121 jul 2026 · métricas 1.13.0
npm
71Buenoíndice de salud
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2247/mes15 jul 2026
MIT15 jul 2026 · métricas 1.13.0
Go
69Moderadoíndice de salud
datadog/datadog-saist
AI-native SAST
Go★ 6319 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
PyPI
68Moderadoíndice de salud
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1928/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
npm · crates.io
67Moderadoíndice de salud
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6899/mes17 jul 2026
MIT17 jul 2026 · métricas 1.13.0
PyPI
67Moderadoíndice de salud
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/mes14 jul 2026
Licencia propia14 jul 2026 · métricas 1.13.0
RubyGems
66Moderadoíndice de salud
0dayinc/pwn
PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Ruby★ 73↓ 0/mes14 jul 2026
MIT14 jul 2026 · métricas 1.13.0
Go · Maven
66Moderadoíndice de salud
seqra/seqra
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 11017 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
PyPI
66Moderadoíndice de salud
sjkim1127/Reversecore_MCP
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
Python★ 18121 jul 2026
MIT21 jul 2026 · métricas 1.13.0
Go
65Moderadoíndice de salud
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
npm
61Moderadoíndice de salud
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6125/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Go
58Moderadoíndice de salud
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 317 jul 2026
MIT17 jul 2026 · métricas 1.13.0
Go · npm
57Moderadoíndice de salud
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 319 jul 2026
MIT19 jul 2026 · métricas 1.13.0
PyPI · crates.io · Maven +2
56Moderadoíndice de salud
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 1217 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
Go
56Moderadoíndice de salud
vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Open Policy Agent · Go★ 25↓ 0/mes14 jul 2026
Licencia propia14 jul 2026 · métricas 1.13.0
npm
53Moderadoíndice de salud
sudoeren/arhus
local-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2972/mes17 jul 2026
MIT17 jul 2026 · métricas 1.13.0
Go
51Moderadoíndice de salud
greprules/greprules
CLI & Agent plugin for fetching SAST rule packs from greprules.io and scanning local code changes.
Go · Python★ 718 jul 2026
Apache-2.018 jul 2026 · métricas 1.13.0
Go
39En riesgoíndice de salud
fyfran/ironwall
8-step open-source security audit CLI. Secrets, SAST, dependency CVEs, IaC, supply chain. MIT. AI-assisted.
Go · Python★ 015 jul 2026
MIT15 jul 2026 · métricas 1.13.0
npm · PyPI
38En riesgoíndice de salud
wangai003/scan5
El repositorio no publica descripción.
TypeScript · HTML★ 0↓ 2941/mes16 jul 2026
Sin licencia16 jul 2026 · métricas 1.13.0