全部标签
目录标签

#sast

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

19 条记录
标签为“sast”按健康指数排序
PyPI
78良好健康指数
semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
OCaml · Python★ 16K↓ 14/月2026年7月21日
LGPL-2.12026年7月21日 · 指标 1.13.0
npm
71良好健康指数
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2,247/月2026年7月15日
MIT2026年7月15日 · 指标 1.13.0
Go
69中等健康指数
datadog/datadog-saist
AI-native SAST
Go★ 632026年7月19日
Apache-2.02026年7月19日 · 指标 1.13.0
PyPI
68中等健康指数
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
npm · crates.io
67中等健康指数
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6,899/月2026年7月17日
MIT2026年7月17日 · 指标 1.13.0
PyPI
67中等健康指数
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/月2026年7月14日
自定义许可证2026年7月14日 · 指标 1.13.0
RubyGems
66中等健康指数
0dayinc/pwn
PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Ruby★ 73↓ 0/月2026年7月14日
MIT2026年7月14日 · 指标 1.13.0
Go · Maven
66中等健康指数
seqra/seqra
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 1102026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
PyPI
66中等健康指数
sjkim1127/Reversecore_MCP
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
Python★ 1812026年7月21日
MIT2026年7月21日 · 指标 1.13.0
Go
65中等健康指数
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 02026年7月19日
Apache-2.02026年7月19日 · 指标 1.13.0
npm
61中等健康指数
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
Go
58中等健康指数
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 32026年7月17日
MIT2026年7月17日 · 指标 1.13.0
Go · npm
57中等健康指数
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 32026年7月19日
MIT2026年7月19日 · 指标 1.13.0
PyPI · crates.io · Maven +2
56中等健康指数
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 122026年7月17日
自定义许可证2026年7月17日 · 指标 1.13.0
Go
56中等健康指数
vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Open Policy Agent · Go★ 25↓ 0/月2026年7月14日
自定义许可证2026年7月14日 · 指标 1.13.0
npm
53中等健康指数
sudoeren/arhus
local-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2,972/月2026年7月17日
MIT2026年7月17日 · 指标 1.13.0
Go
51中等健康指数
greprules/greprules
CLI & Agent plugin for fetching SAST rule packs from greprules.io and scanning local code changes.
Go · Python★ 72026年7月18日
Apache-2.02026年7月18日 · 指标 1.13.0
Go
39存在风险健康指数
fyfran/ironwall
8-step open-source security audit CLI. Secrets, SAST, dependency CVEs, IaC, supply chain. MIT. AI-assisted.
Go · Python★ 02026年7月15日
MIT2026年7月15日 · 指标 1.13.0
npm · PyPI
38存在风险健康指数
wangai003/scan5
该仓库未发布描述。
TypeScript · HTML★ 0↓ 2,941/月2026年7月16日
无许可证2026年7月16日 · 指标 1.13.0