All tags
Catalogue tag

#sast

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

19 records
Tagged “sast”Ranked by health index
PyPI
78Goodhealth index
semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
OCaml · Python★ 16K↓ 14/moJul 21, 2026
LGPL-2.1Jul 21, 2026 · metrics 1.13.0
npm
71Goodhealth index
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2,247/moJul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
Go
69Moderatehealth index
datadog/datadog-saist
AI-native SAST
Go★ 63Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 1.13.0
PyPI
68Moderatehealth index
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
npm · crates.io
67Moderatehealth index
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6,899/moJul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
PyPI
67Moderatehealth index
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/moJul 14, 2026
Custom licenseJul 14, 2026 · metrics 1.13.0
RubyGems
66Moderatehealth index
0dayinc/pwn
PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Ruby★ 73↓ 0/moJul 14, 2026
MITJul 14, 2026 · metrics 1.13.0
Go · Maven
66Moderatehealth index
seqra/seqra
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 110Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
PyPI
66Moderatehealth index
sjkim1127/Reversecore_MCP
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
Python★ 181Jul 21, 2026
MITJul 21, 2026 · metrics 1.13.0
Go
65Moderatehealth index
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 0Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 1.13.0
npm
61Moderatehealth index
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
Go
58Moderatehealth index
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 3Jul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
Go · npm
57Moderatehealth index
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 3Jul 19, 2026
MITJul 19, 2026 · metrics 1.13.0
PyPI · crates.io · Maven +2
56Moderatehealth index
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 12Jul 17, 2026
Custom licenseJul 17, 2026 · metrics 1.13.0
Go
56Moderatehealth index
vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Open Policy Agent · Go★ 25↓ 0/moJul 14, 2026
Custom licenseJul 14, 2026 · metrics 1.13.0
npm
53Moderatehealth index
sudoeren/arhus
local-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2,972/moJul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
Go
51Moderatehealth index
greprules/greprules
CLI & Agent plugin for fetching SAST rule packs from greprules.io and scanning local code changes.
Go · Python★ 7Jul 18, 2026
Apache-2.0Jul 18, 2026 · metrics 1.13.0
Go
39At riskhealth index
fyfran/ironwall
8-step open-source security audit CLI. Secrets, SAST, dependency CVEs, IaC, supply chain. MIT. AI-assisted.
Go · Python★ 0Jul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
npm · PyPI
38At riskhealth index
wangai003/scan5
No repository description published.
TypeScript · HTML★ 0↓ 2,941/moJul 16, 2026
No licenseJul 16, 2026 · metrics 1.13.0