Todas las etiquetas
Etiqueta del catálogo

#sast

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

33 registros
Con la etiqueta «sast»Ordenado por índice de salud
PyPI
97Excepcionalíndice de salud
semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
OCaml · Python★ 16.1K↓ 34.9M/mes5 ago 2026
LGPL-2.15 ago 2026 · métricas 2.10.0
npm
96Excepcionalíndice de salud
NodeSecure/js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
TypeScript★ 286↓ 14.6K/mes4 ago 2026
MIT4 ago 2026 · métricas 2.10.0
npm
88Excelenteíndice de salud
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5893/mes6 sept 2026
MIT6 sept 2026 · métricas 2.10.0
Go
88Excelenteíndice de salud
betterleaks/betterleaks
Find leaked secrets everywhere.
Go★ 172920 ago 2026
MIT20 ago 2026 · métricas 2.10.0
PyPI
88Excelenteíndice de salud
cycodehq/cycode-cli
Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning
Python★ 99↓ 127.9K/mes27 jul 2026
MIT27 jul 2026 · métricas 2.10.0
PyPI
88Excelenteíndice de salud
jimmy058910/jmo-security-repo
JMo Security Suite - Terminal-first security audit toolkit with many tools, multi-target scanning, & compliance
Python★ 731 jul 2026
Licencia propia31 jul 2026 · métricas 2.10.0
npm
86Excelenteíndice de salud
ofri-peretz/eslint
Security & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/mes25 jul 2026
MIT25 jul 2026 · métricas 2.10.0
Go
84Excelenteíndice de salud
datadog/datadog-saist
AI-native SAST
Go★ 6319 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
PyPI
84Excelenteíndice de salud
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 5022 ago 2026
Licencia propia22 ago 2026 · métricas 2.10.0
RubyGems
81Excelenteíndice de salud
0dayInc/pwn
PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Ruby★ 785 sept 2026
MIT5 sept 2026 · métricas 2.10.0
npm · crates.io
78Buenoíndice de salud
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6899/mes17 jul 2026
MIT17 jul 2026 · métricas 2.10.0
PyPI
78Buenoíndice de salud
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1928/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
Go
77Buenoíndice de salud
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
Go · Maven
77Buenoíndice de salud
seqra/seqra
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 11017 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
PyPI
77Buenoíndice de salud
sjkim1127/Reversecore_MCP
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
Python★ 18121 jul 2026
MIT21 jul 2026 · métricas 2.10.0
Go · npm · PyPI
75Buenoíndice de salud
KKloudTarus/synapse-ce
Synapse - a governed control plane for software composition analysis, recon, evidence, and reporting. Verify Everything. Trust Nothing.
Go · Python★ 336 ago 2026
Apache-2.06 ago 2026 · métricas 2.10.0
Go
71Buenoíndice de salud
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 255 sept 2026
Licencia propia5 sept 2026 · métricas 2.10.0
Packagist
69Buenoíndice de salud
dgtlss/warden
A Laravel package that proactively monitors your dependencies for security vulnerabilities by running automated composer audits and sending notifications via webhooks and email
PHP★ 97↓ 7100/mes5 sept 2026
MIT5 sept 2026 · métricas 2.10.0
npm
69Buenoíndice de salud
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6125/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
PyPI
67Buenoíndice de salud
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 231 jul 2026
MIT31 jul 2026 · métricas 2.10.0
npm
63Moderadoíndice de salud
TypeScript★ 89↓ 2730/mes5 ago 2026
Apache-2.05 ago 2026 · métricas 2.10.0
Go
63Moderadoíndice de salud
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 317 jul 2026
MIT17 jul 2026 · métricas 2.10.0
Go · npm
62Moderadoíndice de salud
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 319 jul 2026
MIT19 jul 2026 · métricas 2.10.0
Go
60Moderadoíndice de salud
alexpermiakov/sast-triage
AI-powered triage for SAST findings.
Go★ 026 jul 2026
MIT26 jul 2026 · métricas 2.10.0
PyPI · crates.io · Maven +2
57Moderadoíndice de salud
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 1217 jul 2026
Licencia propia17 jul 2026 · métricas 2.10.0
npm
54Moderadoíndice de salud
sudoeren/arhus
local-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2972/mes17 jul 2026
MIT17 jul 2026 · métricas 2.10.0
Go
51Moderadoíndice de salud
greprules/greprules
CLI & Agent plugin for fetching SAST rule packs from greprules.io and scanning local code changes.
Go · Python★ 718 jul 2026
Apache-2.018 jul 2026 · métricas 2.10.0
crates.io
48Débilíndice de salud
eezz4/zzop
Deterministic cross-repo contract analysis you can gate CI on — joins frontend calls to backend routes across repo boundaries and flags drift (typo'd path, version skew, dead endpoint). Also a multi-language SAST/architecture engine (TS/JS, Prisma, Java), extensible via adapters. Rust core, npm CLI/SDK.
Rust★ 123 jul 2026
MIT23 jul 2026 · métricas 2.10.0
Go
42Débilíndice de salud
malandas/andas
Sift real security risk from the noise — a cross-platform CLI that live-validates leaked secrets and reachability-ranks npm/Yarn vulnerabilities, so you fix what's actually exploitable.
Go★ 06 ago 2026
MIT6 ago 2026 · métricas 2.10.0
npm
39Débilíndice de salud
KaraboGerald/SeamShieldCLI
SeamShield Community CLI: local-first access-lane scanning for AI-built apps
TypeScript · JavaScript★ 0↓ 2130/mes4 ago 2026
MIT4 ago 2026 · métricas 2.10.0