Усі теги
Тег каталогу

#sarif

Усі репозиторії публічного реєстру з цим тегом — із тем GitHub або ключових слів, які публікують їхні реєстри пакетів. Здоров'я вимірюється за тією ж версіонованою методологією, що й решта реєстру.

27 записів
З тегом «sarif»Упорядковано за індексом здоров'я
PyPI · npm
80Добрийіндекс здоров'я
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5 301/міс16 лип. 2026 р.
Apache-2.016 лип. 2026 р. · метрики 1.13.0
PyPI
73Добрийіндекс здоров'я
Cranot/roam-code
Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 238 commands, 224 MCP tools, change-safety gates, audit evidence, zero API keys.
Python★ 498↓ 5 430/міс15 лип. 2026 р.
Apache-2.015 лип. 2026 р. · метрики 1.13.0
npm
72Добрийіндекс здоров'я
microsoft/axe-sarif-converter
An axe-core reporter that outputs axe scan results in SARIF format (http://sarifweb.azurewebsites.net/)
TypeScript★ 38↓ 76.1K/міс21 лип. 2026 р.
MIT21 лип. 2026 р. · метрики 1.13.0
npm · PyPI
71Добрийіндекс здоров'я
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 14.1K/міс14 лип. 2026 р.
AGPL-3.014 лип. 2026 р. · метрики 1.13.0
Go · PyPI
71Добрийіндекс здоров'я
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 1.13.0
PyPI
68Помірнийіндекс здоров'я
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1 928/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 1.13.0
PyPI
68Помірнийіндекс здоров'я
justinchuby/lintrunner-adapters
Adapters and tools for lintrunner
Python★ 6↓ 940.1K/міс21 лип. 2026 р.
Власна ліцензія21 лип. 2026 р. · метрики 1.13.0
npm · crates.io
67Помірнийіндекс здоров'я
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6 899/міс17 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 1.13.0
PyPI
67Помірнийіндекс здоров'я
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/міс14 лип. 2026 р.
Власна ліцензія14 лип. 2026 р. · метрики 1.13.0
Go
66Помірнийіндекс здоров'я
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 821 лип. 2026 р.
Apache-2.021 лип. 2026 р. · метрики 1.13.0
Go
65Помірнийіндекс здоров'я
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 1.13.0
npm · PyPI
65Помірнийіндекс здоров'я
raccioly/docguard
The enforcement tool for Canonical-Driven Development (CDD). Audit, generate, and guard your project documentation. Zero dependencies.
JavaScript★ 21↓ 5 005/міс21 лип. 2026 р.
MIT21 лип. 2026 р. · метрики 1.13.0
npm · PyPI
63Помірнийіндекс здоров'я
oaslananka/boardreadyops
End-to-end hardware release pipeline for KiCad: generate, validate, sign, and package manufacturer-ready releases as a CLI and GitHub Action.
TypeScript★ 3↓ 3 738/міс17 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 1.13.0
npm
61Помірнийіндекс здоров'я
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6 125/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 1.13.0
Packagist · npm
60Помірнийіндекс здоров'я
blundergoat/gruff-php
Opinionated PHP code-quality analyzer that scores findings across quality pillars and emits reports for terminals, CI, SARIF, HTML, and a local dashboard.
PHP★ 1↓ 8 483/міс16 лип. 2026 р.
MIT16 лип. 2026 р. · метрики 1.13.0
Go
57Помірнийіндекс здоров'я
git-pkgs/sarif
Go library for reading, writing, and validating SARIF 2.1.0 logs
Go★ 115 лип. 2026 р.
MIT15 лип. 2026 р. · метрики 1.13.0
PyPI · crates.io · Maven +2
56Помірнийіндекс здоров'я
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 1217 лип. 2026 р.
Власна ліцензія17 лип. 2026 р. · метрики 1.13.0
Go
56Помірнийіндекс здоров'я
rudrendupaul/tenantguard
CLI security scanner for self-hosted multi-tenant AI-agent platforms. 16 fail-closed OPA/Rego rules catch tenant-isolation defects (sandbox scoping, SSRF, cross-tenant cron/auth, secret leakage). SARIF and JSON output for CI.
Go · Open Policy Agent★ 015 лип. 2026 р.
Apache-2.015 лип. 2026 р. · метрики 1.13.0
Go
56Помірнийіндекс здоров'я
skyway-harness-builder/workflow-lint
Standalone open-source linter for Skylence .sky workflow files
Go★ 021 лип. 2026 р.
Apache-2.021 лип. 2026 р. · метрики 1.13.0
Go
56Помірнийіндекс здоров'я
vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Open Policy Agent · Go★ 25↓ 0/міс14 лип. 2026 р.
Власна ліцензія14 лип. 2026 р. · метрики 1.13.0
Go
55Помірнийіндекс здоров'я
kidoz/vulners-cli
CLI vulnerability scanner powered by Vulners — search, audit, scan, offline mode
Go★ 617 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 1.13.0
Go
49У зоні ризикуіндекс здоров'я
bunta-expert/git-path-audit
Read-only CLI that finds Git paths that collide, change meaning, or fail to check out across Windows, macOS, and Linux.
Go★ 1↓ 0/міс14 лип. 2026 р.
MIT14 лип. 2026 р. · метрики 1.13.0
npm
48У зоні ризикуіндекс здоров'я
criticaldeveloper/critical-gate
Опис репозиторію не опубліковано.
TypeScript★ 1↓ 3 922/міс16 лип. 2026 р.
MIT16 лип. 2026 р. · метрики 1.13.0
Go
45У зоні ризикуіндекс здоров'я
safetylab/ShadowSecurityScanner
Free, open-source network vulnerability scanner & penetration testing tool that ranks findings by real-world exploitability (EPSS + CISA KEV). Single desktop app for Windows, macOS, Linux. No cloud, no telemetry. MIT.
Go★ 021 лип. 2026 р.
MIT21 лип. 2026 р. · метрики 1.13.0
npm
43У зоні ризикуіндекс здоров'я
nsasoft/nsauditor-ai
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 19↓ 5 644/міс15 лип. 2026 р.
MIT15 лип. 2026 р. · метрики 1.13.0
Go
38У зоні ризикуіндекс здоров'я
tamish560/mcprobe
Security scanner and introspection tool for MCP servers. Connect, inspect, detect injection patterns, find tool shadowing, baseline for drift. Single binary, zero dependencies, Go stdlib only.
Go★ 220 лип. 2026 р.
MIT20 лип. 2026 р. · метрики 1.13.0
npm
35У зоні ризикуіндекс здоров'я
nsasoft/nsauditor-ai-agent-skill
AI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows. Works with Claude Code, Cursor, Windsurf, and any MCP-aware agent.
Змішані★ 3↓ 4 001/міс15 лип. 2026 р.
MIT15 лип. 2026 р. · метрики 1.13.0