Усі теги
Тег каталогу

#sast

Усі репозиторії публічного реєстру з цим тегом — із тем GitHub або ключових слів, які публікують їхні реєстри пакетів. Здоров'я вимірюється за тією ж версіонованою методологією, що й решта реєстру.

33 записи
З тегом «sast»Упорядковано за індексом здоров'я
PyPI
97Винятковийіндекс здоров'я
semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
OCaml · Python★ 16.1K↓ 34.9M/міс5 серп. 2026 р.
LGPL-2.15 серп. 2026 р. · метрики 2.10.0
npm
96Винятковийіндекс здоров'я
NodeSecure/js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
TypeScript★ 286↓ 14.6K/міс4 серп. 2026 р.
MIT4 серп. 2026 р. · метрики 2.10.0
npm
88Відміннийіндекс здоров'я
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5 893/міс6 вер. 2026 р.
MIT6 вер. 2026 р. · метрики 2.10.0
Go
88Відміннийіндекс здоров'я
betterleaks/betterleaks
Find leaked secrets everywhere.
Go★ 1 72920 серп. 2026 р.
MIT20 серп. 2026 р. · метрики 2.10.0
PyPI
88Відміннийіндекс здоров'я
cycodehq/cycode-cli
Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning
Python★ 99↓ 127.9K/міс27 лип. 2026 р.
MIT27 лип. 2026 р. · метрики 2.10.0
PyPI
88Відміннийіндекс здоров'я
jimmy058910/jmo-security-repo
JMo Security Suite - Terminal-first security audit toolkit with many tools, multi-target scanning, & compliance
Python★ 731 лип. 2026 р.
Власна ліцензія31 лип. 2026 р. · метрики 2.10.0
npm
86Відміннийіндекс здоров'я
ofri-peretz/eslint
Security & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/міс25 лип. 2026 р.
MIT25 лип. 2026 р. · метрики 2.10.0
Go
84Відміннийіндекс здоров'я
datadog/datadog-saist
AI-native SAST
Go★ 6319 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 2.10.0
PyPI
84Відміннийіндекс здоров'я
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 5022 серп. 2026 р.
Власна ліцензія22 серп. 2026 р. · метрики 2.10.0
RubyGems
81Відміннийіндекс здоров'я
0dayInc/pwn
PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Ruby★ 785 вер. 2026 р.
MIT5 вер. 2026 р. · метрики 2.10.0
npm · crates.io
78Добрийіндекс здоров'я
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6 899/міс17 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 2.10.0
PyPI
78Добрийіндекс здоров'я
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1 928/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 2.10.0
Go
77Добрийіндекс здоров'я
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 2.10.0
Go · Maven
77Добрийіндекс здоров'я
seqra/seqra
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 11017 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 2.10.0
PyPI
77Добрийіндекс здоров'я
sjkim1127/Reversecore_MCP
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
Python★ 18121 лип. 2026 р.
MIT21 лип. 2026 р. · метрики 2.10.0
Go · npm · PyPI
75Добрийіндекс здоров'я
KKloudTarus/synapse-ce
Synapse - a governed control plane for software composition analysis, recon, evidence, and reporting. Verify Everything. Trust Nothing.
Go · Python★ 336 серп. 2026 р.
Apache-2.06 серп. 2026 р. · метрики 2.10.0
Go
71Добрийіндекс здоров'я
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 255 вер. 2026 р.
Власна ліцензія5 вер. 2026 р. · метрики 2.10.0
Packagist
69Добрийіндекс здоров'я
dgtlss/warden
A Laravel package that proactively monitors your dependencies for security vulnerabilities by running automated composer audits and sending notifications via webhooks and email
PHP★ 97↓ 7 100/міс5 вер. 2026 р.
MIT5 вер. 2026 р. · метрики 2.10.0
npm
69Добрийіндекс здоров'я
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6 125/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 2.10.0
PyPI
67Добрийіндекс здоров'я
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 231 лип. 2026 р.
MIT31 лип. 2026 р. · метрики 2.10.0
npm
63Помірнийіндекс здоров'я
TypeScript★ 89↓ 2 730/міс5 серп. 2026 р.
Apache-2.05 серп. 2026 р. · метрики 2.10.0
Go
63Помірнийіндекс здоров'я
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 317 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 2.10.0
Go · npm
62Помірнийіндекс здоров'я
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 319 лип. 2026 р.
MIT19 лип. 2026 р. · метрики 2.10.0
Go
60Помірнийіндекс здоров'я
alexpermiakov/sast-triage
AI-powered triage for SAST findings.
Go★ 026 лип. 2026 р.
MIT26 лип. 2026 р. · метрики 2.10.0
PyPI · crates.io · Maven +2
57Помірнийіндекс здоров'я
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 1217 лип. 2026 р.
Власна ліцензія17 лип. 2026 р. · метрики 2.10.0
npm
54Помірнийіндекс здоров'я
sudoeren/arhus
local-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2 972/міс17 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 2.10.0
Go
51Помірнийіндекс здоров'я
greprules/greprules
CLI & Agent plugin for fetching SAST rule packs from greprules.io and scanning local code changes.
Go · Python★ 718 лип. 2026 р.
Apache-2.018 лип. 2026 р. · метрики 2.10.0
crates.io
48Слабкийіндекс здоров'я
eezz4/zzop
Deterministic cross-repo contract analysis you can gate CI on — joins frontend calls to backend routes across repo boundaries and flags drift (typo'd path, version skew, dead endpoint). Also a multi-language SAST/architecture engine (TS/JS, Prisma, Java), extensible via adapters. Rust core, npm CLI/SDK.
Rust★ 123 лип. 2026 р.
MIT23 лип. 2026 р. · метрики 2.10.0
Go
42Слабкийіндекс здоров'я
malandas/andas
Sift real security risk from the noise — a cross-platform CLI that live-validates leaked secrets and reachability-ranks npm/Yarn vulnerabilities, so you fix what's actually exploitable.
Go★ 06 серп. 2026 р.
MIT6 серп. 2026 р. · метрики 2.10.0
npm
39Слабкийіндекс здоров'я
KaraboGerald/SeamShieldCLI
SeamShield Community CLI: local-first access-lane scanning for AI-built apps
TypeScript · JavaScript★ 0↓ 2 130/міс4 серп. 2026 р.
MIT4 серп. 2026 р. · метрики 2.10.0