All tags
Catalogue tag

#sarif

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

27 records
Tagged “sarif”Ranked by health index
PyPI · npm
80Goodhealth index
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 1.13.0
PyPI
73Goodhealth index
Cranot/roam-code
Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 238 commands, 224 MCP tools, change-safety gates, audit evidence, zero API keys.
Python★ 498↓ 5,430/moJul 15, 2026
Apache-2.0Jul 15, 2026 · metrics 1.13.0
npm
72Goodhealth index
microsoft/axe-sarif-converter
An axe-core reporter that outputs axe scan results in SARIF format (http://sarifweb.azurewebsites.net/)
TypeScript★ 38↓ 76.1K/moJul 21, 2026
MITJul 21, 2026 · metrics 1.13.0
npm · PyPI
71Goodhealth index
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 14.1K/moJul 14, 2026
AGPL-3.0Jul 14, 2026 · metrics 1.13.0
Go · PyPI
71Goodhealth index
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 9Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
PyPI
68Moderatehealth index
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
PyPI
68Moderatehealth index
justinchuby/lintrunner-adapters
Adapters and tools for lintrunner
Python★ 6↓ 940.1K/moJul 21, 2026
Custom licenseJul 21, 2026 · metrics 1.13.0
npm · crates.io
67Moderatehealth index
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6,899/moJul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
PyPI
67Moderatehealth index
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/moJul 14, 2026
Custom licenseJul 14, 2026 · metrics 1.13.0
Go
66Moderatehealth index
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 8Jul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 1.13.0
Go
65Moderatehealth index
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 0Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 1.13.0
npm · PyPI
65Moderatehealth index
raccioly/docguard
The enforcement tool for Canonical-Driven Development (CDD). Audit, generate, and guard your project documentation. Zero dependencies.
JavaScript★ 21↓ 5,005/moJul 21, 2026
MITJul 21, 2026 · metrics 1.13.0
npm · PyPI
63Moderatehealth index
oaslananka/boardreadyops
End-to-end hardware release pipeline for KiCad: generate, validate, sign, and package manufacturer-ready releases as a CLI and GitHub Action.
TypeScript★ 3↓ 3,738/moJul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
npm
61Moderatehealth index
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
Packagist · npm
60Moderatehealth index
blundergoat/gruff-php
Opinionated PHP code-quality analyzer that scores findings across quality pillars and emits reports for terminals, CI, SARIF, HTML, and a local dashboard.
PHP★ 1↓ 8,483/moJul 16, 2026
MITJul 16, 2026 · metrics 1.13.0
Go
57Moderatehealth index
git-pkgs/sarif
Go library for reading, writing, and validating SARIF 2.1.0 logs
Go★ 1Jul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
PyPI · crates.io · Maven +2
56Moderatehealth index
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 12Jul 17, 2026
Custom licenseJul 17, 2026 · metrics 1.13.0
Go
56Moderatehealth index
rudrendupaul/tenantguard
CLI security scanner for self-hosted multi-tenant AI-agent platforms. 16 fail-closed OPA/Rego rules catch tenant-isolation defects (sandbox scoping, SSRF, cross-tenant cron/auth, secret leakage). SARIF and JSON output for CI.
Go · Open Policy Agent★ 0Jul 15, 2026
Apache-2.0Jul 15, 2026 · metrics 1.13.0
Go
56Moderatehealth index
skyway-harness-builder/workflow-lint
Standalone open-source linter for Skylence .sky workflow files
Go★ 0Jul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 1.13.0
Go
56Moderatehealth index
vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Open Policy Agent · Go★ 25↓ 0/moJul 14, 2026
Custom licenseJul 14, 2026 · metrics 1.13.0
Go
55Moderatehealth index
kidoz/vulners-cli
CLI vulnerability scanner powered by Vulners — search, audit, scan, offline mode
Go★ 6Jul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
Go
49At riskhealth index
bunta-expert/git-path-audit
Read-only CLI that finds Git paths that collide, change meaning, or fail to check out across Windows, macOS, and Linux.
Go★ 1↓ 0/moJul 14, 2026
MITJul 14, 2026 · metrics 1.13.0
npm
48At riskhealth index
criticaldeveloper/critical-gate
No repository description published.
TypeScript★ 1↓ 3,922/moJul 16, 2026
MITJul 16, 2026 · metrics 1.13.0
Go
45At riskhealth index
safetylab/ShadowSecurityScanner
Free, open-source network vulnerability scanner & penetration testing tool that ranks findings by real-world exploitability (EPSS + CISA KEV). Single desktop app for Windows, macOS, Linux. No cloud, no telemetry. MIT.
Go★ 0Jul 21, 2026
MITJul 21, 2026 · metrics 1.13.0
npm
43At riskhealth index
nsasoft/nsauditor-ai
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 19↓ 5,644/moJul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
Go
38At riskhealth index
tamish560/mcprobe
Security scanner and introspection tool for MCP servers. Connect, inspect, detect injection patterns, find tool shadowing, baseline for drift. Single binary, zero dependencies, Go stdlib only.
Go★ 2Jul 20, 2026
MITJul 20, 2026 · metrics 1.13.0
npm
35At riskhealth index
nsasoft/nsauditor-ai-agent-skill
AI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows. Works with Claude Code, Cursor, Windsurf, and any MCP-aware agent.
Mixed★ 3↓ 4,001/moJul 15, 2026
MITJul 15, 2026 · metrics 1.13.0