All tags
Catalogue tag

#sast

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

33 records
Tagged “sast”Ranked by health index
PyPI
97Exceptionalhealth index
semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
OCaml · Python★ 16.1K↓ 34.9M/moAug 5, 2026
LGPL-2.1Aug 5, 2026 · metrics 2.10.0
npm
96Exceptionalhealth index
NodeSecure/js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
TypeScript★ 286↓ 14.6K/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
npm
88Excellenthealth index
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5,893/moSep 6, 2026
MITSep 6, 2026 · metrics 2.10.0
Go
88Excellenthealth index
betterleaks/betterleaks
Find leaked secrets everywhere.
Go★ 1,729Aug 20, 2026
MITAug 20, 2026 · metrics 2.10.0
PyPI
88Excellenthealth index
cycodehq/cycode-cli
Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning
Python★ 99↓ 127.9K/moJul 27, 2026
MITJul 27, 2026 · metrics 2.10.0
PyPI
88Excellenthealth index
jimmy058910/jmo-security-repo
JMo Security Suite - Terminal-first security audit toolkit with many tools, multi-target scanning, & compliance
Python★ 7Jul 31, 2026
Custom licenseJul 31, 2026 · metrics 2.10.0
npm
86Excellenthealth index
ofri-peretz/eslint
Security & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/moJul 25, 2026
MITJul 25, 2026 · metrics 2.10.0
Go
84Excellenthealth index
datadog/datadog-saist
AI-native SAST
Go★ 63Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
PyPI
84Excellenthealth index
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 50Aug 22, 2026
Custom licenseAug 22, 2026 · metrics 2.10.0
RubyGems
81Excellenthealth index
0dayInc/pwn
PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Ruby★ 78Sep 5, 2026
MITSep 5, 2026 · metrics 2.10.0
npm · crates.io
78Goodhealth index
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6,899/moJul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
PyPI
78Goodhealth index
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
Go
77Goodhealth index
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 0Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
Go · Maven
77Goodhealth index
seqra/seqra
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 110Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
PyPI
77Goodhealth index
sjkim1127/Reversecore_MCP
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
Python★ 181Jul 21, 2026
MITJul 21, 2026 · metrics 2.10.0
Go · npm · PyPI
75Goodhealth index
KKloudTarus/synapse-ce
Synapse - a governed control plane for software composition analysis, recon, evidence, and reporting. Verify Everything. Trust Nothing.
Go · Python★ 33Aug 6, 2026
Apache-2.0Aug 6, 2026 · metrics 2.10.0
Go
71Goodhealth index
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 25Sep 5, 2026
Custom licenseSep 5, 2026 · metrics 2.10.0
Packagist
69Goodhealth index
dgtlss/warden
A Laravel package that proactively monitors your dependencies for security vulnerabilities by running automated composer audits and sending notifications via webhooks and email
PHP★ 97↓ 7,100/moSep 5, 2026
MITSep 5, 2026 · metrics 2.10.0
npm
69Goodhealth index
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
PyPI
67Goodhealth index
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 2Jul 31, 2026
MITJul 31, 2026 · metrics 2.10.0
npm
63Moderatehealth index
TypeScript★ 89↓ 2,730/moAug 5, 2026
Apache-2.0Aug 5, 2026 · metrics 2.10.0
Go
63Moderatehealth index
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 3Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
Go · npm
62Moderatehealth index
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 3Jul 19, 2026
MITJul 19, 2026 · metrics 2.10.0
Go
60Moderatehealth index
alexpermiakov/sast-triage
AI-powered triage for SAST findings.
Go★ 0Jul 26, 2026
MITJul 26, 2026 · metrics 2.10.0
PyPI · crates.io · Maven +2
57Moderatehealth index
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 12Jul 17, 2026
Custom licenseJul 17, 2026 · metrics 2.10.0
npm
54Moderatehealth index
sudoeren/arhus
local-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2,972/moJul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
Go
51Moderatehealth index
greprules/greprules
CLI & Agent plugin for fetching SAST rule packs from greprules.io and scanning local code changes.
Go · Python★ 7Jul 18, 2026
Apache-2.0Jul 18, 2026 · metrics 2.10.0
crates.io
48Weakhealth index
eezz4/zzop
Deterministic cross-repo contract analysis you can gate CI on — joins frontend calls to backend routes across repo boundaries and flags drift (typo'd path, version skew, dead endpoint). Also a multi-language SAST/architecture engine (TS/JS, Prisma, Java), extensible via adapters. Rust core, npm CLI/SDK.
Rust★ 1Jul 23, 2026
MITJul 23, 2026 · metrics 2.10.0
Go
42Weakhealth index
malandas/andas
Sift real security risk from the noise — a cross-platform CLI that live-validates leaked secrets and reachability-ranks npm/Yarn vulnerabilities, so you fix what's actually exploitable.
Go★ 0Aug 6, 2026
MITAug 6, 2026 · metrics 2.10.0
npm
39Weakhealth index
KaraboGerald/SeamShieldCLI
SeamShield Community CLI: local-first access-lane scanning for AI-built apps
TypeScript · JavaScript★ 0↓ 2,130/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0