Усі теги
Тег каталогу

#sast

Усі репозиторії публічного реєстру з цим тегом — із тем GitHub або ключових слів, які публікують їхні реєстри пакетів. Здоров'я вимірюється за тією ж версіонованою методологією, що й решта реєстру.

19 записів
З тегом «sast»Упорядковано за індексом здоров'я
PyPI
78Добрийіндекс здоров'я
semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
OCaml · Python★ 16K↓ 14/міс21 лип. 2026 р.
LGPL-2.121 лип. 2026 р. · метрики 1.13.0
npm
71Добрийіндекс здоров'я
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2 247/міс15 лип. 2026 р.
MIT15 лип. 2026 р. · метрики 1.13.0
Go
69Помірнийіндекс здоров'я
datadog/datadog-saist
AI-native SAST
Go★ 6319 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 1.13.0
PyPI
68Помірнийіндекс здоров'я
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1 928/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 1.13.0
npm · crates.io
67Помірнийіндекс здоров'я
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6 899/міс17 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 1.13.0
PyPI
67Помірнийіндекс здоров'я
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/міс14 лип. 2026 р.
Власна ліцензія14 лип. 2026 р. · метрики 1.13.0
RubyGems
66Помірнийіндекс здоров'я
0dayinc/pwn
PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Ruby★ 73↓ 0/міс14 лип. 2026 р.
MIT14 лип. 2026 р. · метрики 1.13.0
Go · Maven
66Помірнийіндекс здоров'я
seqra/seqra
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 11017 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 1.13.0
PyPI
66Помірнийіндекс здоров'я
sjkim1127/Reversecore_MCP
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
Python★ 18121 лип. 2026 р.
MIT21 лип. 2026 р. · метрики 1.13.0
Go
65Помірнийіндекс здоров'я
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 1.13.0
npm
61Помірнийіндекс здоров'я
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6 125/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 1.13.0
Go
58Помірнийіндекс здоров'я
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 317 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 1.13.0
Go · npm
57Помірнийіндекс здоров'я
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 319 лип. 2026 р.
MIT19 лип. 2026 р. · метрики 1.13.0
PyPI · crates.io · Maven +2
56Помірнийіндекс здоров'я
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 1217 лип. 2026 р.
Власна ліцензія17 лип. 2026 р. · метрики 1.13.0
Go
56Помірнийіндекс здоров'я
vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Open Policy Agent · Go★ 25↓ 0/міс14 лип. 2026 р.
Власна ліцензія14 лип. 2026 р. · метрики 1.13.0
npm
53Помірнийіндекс здоров'я
sudoeren/arhus
local-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2 972/міс17 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 1.13.0
Go
51Помірнийіндекс здоров'я
greprules/greprules
CLI & Agent plugin for fetching SAST rule packs from greprules.io and scanning local code changes.
Go · Python★ 718 лип. 2026 р.
Apache-2.018 лип. 2026 р. · метрики 1.13.0
Go
39У зоні ризикуіндекс здоров'я
fyfran/ironwall
8-step open-source security audit CLI. Secrets, SAST, dependency CVEs, IaC, supply chain. MIT. AI-assisted.
Go · Python★ 015 лип. 2026 р.
MIT15 лип. 2026 р. · метрики 1.13.0
npm · PyPI
38У зоні ризикуіндекс здоров'я
wangai003/scan5
Опис репозиторію не опубліковано.
TypeScript · HTML★ 0↓ 2 941/міс16 лип. 2026 р.
Без ліцензії16 лип. 2026 р. · метрики 1.13.0