Усі теги
Тег каталогу

#sarif

Усі репозиторії публічного реєстру з цим тегом — із тем GitHub або ключових слів, які публікують їхні реєстри пакетів. Здоров'я вимірюється за тією ж версіонованою методологією, що й решта реєстру.

47 записів
З тегом «sarif»Упорядковано за індексом здоров'я
PyPI · npm
94Винятковийіндекс здоров'я
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5 301/міс16 лип. 2026 р.
Apache-2.016 лип. 2026 р. · метрики 2.10.0
PyPI · npm
94Винятковийіндекс здоров'я
sattyamjjain/agent-audit-kit
Static scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2 808/міс2 серп. 2026 р.
MIT2 серп. 2026 р. · метрики 2.10.0
npm
91Відміннийіндекс здоров'я
Siteimprove/alfa
:wheelchair: Suite of open and standards-based tools for performing reliable accessibility conformance testing at scale
HTML · TypeScript★ 130↓ 96.3K/міс31 лип. 2026 р.
MIT31 лип. 2026 р. · метрики 2.10.0
PyPI
87Відміннийіндекс здоров'я
Cranot/roam-code
Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 238 commands, 224 MCP tools, change-safety gates, audit evidence, zero API keys.
Python★ 498↓ 5 430/міс15 лип. 2026 р.
Apache-2.015 лип. 2026 р. · метрики 2.10.0
Go
86Відміннийіндекс здоров'я
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 024 лип. 2026 р.
Apache-2.024 лип. 2026 р. · метрики 2.10.0
Go · PyPI
86Відміннийіндекс здоров'я
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 2.10.0
npm
86Відміннийіндекс здоров'я
microsoft/axe-sarif-converter
An axe-core reporter that outputs axe scan results in SARIF format (http://sarifweb.azurewebsites.net/)
TypeScript★ 38↓ 76.1K/міс21 лип. 2026 р.
MIT21 лип. 2026 р. · метрики 2.10.0
npm
86Відміннийіндекс здоров'я
ofri-peretz/eslint
Security & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/міс25 лип. 2026 р.
MIT25 лип. 2026 р. · метрики 2.10.0
npm · PyPI
84Відміннийіндекс здоров'я
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 7 189/міс22 серп. 2026 р.
AGPL-3.022 серп. 2026 р. · метрики 2.10.0
PyPI
84Відміннийіндекс здоров'я
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 5022 серп. 2026 р.
Власна ліцензія22 серп. 2026 р. · метрики 2.10.0
Go
81Відміннийіндекс здоров'я
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 823 лип. 2026 р.
Apache-2.023 лип. 2026 р. · метрики 2.10.0
npm · crates.io
78Добрийіндекс здоров'я
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6 899/міс17 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 2.10.0
npm
78Добрийіндекс здоров'я
Null-Square/Null-CLi
Open-source AI pentest and compliance-readiness CLI by NullSquare.
TypeScript · JavaScript★ 81↓ 147/міс4 серп. 2026 р.
Власна ліцензія4 серп. 2026 р. · метрики 2.10.0
PyPI
78Добрийіндекс здоров'я
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1 928/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 2.10.0
PyPI
78Добрийіндекс здоров'я
justinchuby/lintrunner-adapters
Adapters and tools for lintrunner
Python★ 6↓ 940.1K/міс21 лип. 2026 р.
Власна ліцензія21 лип. 2026 р. · метрики 2.10.0
Go
77Добрийіндекс здоров'я
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 2.10.0
npm · PyPI
77Добрийіндекс здоров'я
raccioly/docguard
The enforcement tool for Canonical-Driven Development (CDD). Audit, generate, and guard your project documentation. Zero dependencies.
JavaScript★ 21↓ 5 005/міс21 лип. 2026 р.
MIT21 лип. 2026 р. · метрики 2.10.0
npm · Go
73Добрийіндекс здоров'я
HodeTech/Leakwatch
High-performance open-source secret scanner — detect, verify & report leaked API keys, tokens & credentials in code, Git history, container images, and the cloud.
Go★ 2↓ 46/міс27 лип. 2026 р.
MIT27 лип. 2026 р. · метрики 2.10.0
npm · PyPI
73Добрийіндекс здоров'я
oaslananka/boardreadyops
End-to-end hardware release pipeline for KiCad: generate, validate, sign, and package manufacturer-ready releases as a CLI and GitHub Action.
TypeScript★ 3↓ 3 738/міс17 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 2.10.0
npm
73Добрийіндекс здоров'я
stainless-code/codemap
Cut AI-agent token waste ~90% — query a local SQLite structural index of your JS/TS/CSS codebase with SQL in one round-trip instead of 3–5 file reads. Symbols, imports, calls, components, CSS tokens, coverage, markers. CLI, MCP (21 tools), HTTP, GitHub Action, ESM API. 71 recipes; AST+resolver; SARIF/audit/baselines for CI.
TypeScript★ 8↓ 8 315/міс26 лип. 2026 р.
MIT26 лип. 2026 р. · метрики 2.10.0
Go
71Добрийіндекс здоров'я
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 255 вер. 2026 р.
Власна ліцензія5 вер. 2026 р. · метрики 2.10.0
npm
71Добрийіндекс здоров'я
YawLabs/ctxlint
Lint your AI agent context files (CLAUDE.md, AGENTS.md, etc.) against your actual codebase
TypeScript★ 7↓ 21.4K/міс6 серп. 2026 р.
MIT6 серп. 2026 р. · метрики 2.10.0
npm
69Добрийіндекс здоров'я
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6 125/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 2.10.0
PyPI
67Добрийіндекс здоров'я
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 231 лип. 2026 р.
MIT31 лип. 2026 р. · метрики 2.10.0
Go
67Добрийіндекс здоров'я
tiagosilva07/zyrax-guard
Audit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 228 серп. 2026 р.
MIT28 серп. 2026 р. · метрики 2.10.0
Packagist · npm
65Добрийіндекс здоров'я
blundergoat/gruff-php
Opinionated PHP code-quality analyzer that scores findings across quality pillars and emits reports for terminals, CI, SARIF, HTML, and a local dashboard.
PHP★ 1↓ 8 483/міс16 лип. 2026 р.
MIT16 лип. 2026 р. · метрики 2.10.0
Go · npm
62Помірнийіндекс здоров'я
LarsArtmann/art-dupl
Professional code clone detection for Go. AST-based structural + semantic detection with suffix tree algorithms, 3 matching modes, 7 output formats, templ support, and CI baseline gating.
Go★ 231 серп. 2026 р.
Власна ліцензія31 серп. 2026 р. · метрики 2.10.0
Go
62Помірнийіндекс здоров'я
git-pkgs/sarif
Go library for reading, writing, and validating SARIF 2.1.0 logs
Go★ 115 лип. 2026 р.
MIT15 лип. 2026 р. · метрики 2.10.0
Go
62Помірнийіндекс здоров'я
icearp/disco-cli
Discover, map & secure AWS, Azure, & GCP. Scan resources and their relationships into a local inventory, visualize the graph, and run OPA policy checks with SARIF output.
Go★ 130 серп. 2026 р.
MIT30 серп. 2026 р. · метрики 2.10.0
Go
62Помірнийіндекс здоров'я
kanywst/brtc
Cost calculator for offline password brute-force attacks: time + USD per GPU profile, with a CI gatekeeper.
Go★ 026 лип. 2026 р.
MIT26 лип. 2026 р. · метрики 2.10.0