全部标签
目录标签

#sast

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

33 条记录
标签为“sast”按健康指数排序
PyPI
97卓越健康指数
semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
OCaml · Python★ 16.1K↓ 34.9M/月2026年8月5日
LGPL-2.12026年8月5日 · 指标 2.10.0
npm
96卓越健康指数
NodeSecure/js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
TypeScript★ 286↓ 14.6K/月2026年8月4日
MIT2026年8月4日 · 指标 2.10.0
npm
88优秀健康指数
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5,893/月2026年9月6日
MIT2026年9月6日 · 指标 2.10.0
Go
88优秀健康指数
betterleaks/betterleaks
Find leaked secrets everywhere.
Go★ 1,7292026年8月20日
MIT2026年8月20日 · 指标 2.10.0
PyPI
88优秀健康指数
cycodehq/cycode-cli
Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning
Python★ 99↓ 127.9K/月2026年7月27日
MIT2026年7月27日 · 指标 2.10.0
PyPI
88优秀健康指数
jimmy058910/jmo-security-repo
JMo Security Suite - Terminal-first security audit toolkit with many tools, multi-target scanning, & compliance
Python★ 72026年7月31日
自定义许可证2026年7月31日 · 指标 2.10.0
npm
86优秀健康指数
ofri-peretz/eslint
Security & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/月2026年7月25日
MIT2026年7月25日 · 指标 2.10.0
Go
84优秀健康指数
datadog/datadog-saist
AI-native SAST
Go★ 632026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
PyPI
84优秀健康指数
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 502026年8月22日
自定义许可证2026年8月22日 · 指标 2.10.0
RubyGems
81优秀健康指数
0dayInc/pwn
PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Ruby★ 782026年9月5日
MIT2026年9月5日 · 指标 2.10.0
npm · crates.io
78良好健康指数
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6,899/月2026年7月17日
MIT2026年7月17日 · 指标 2.10.0
PyPI
78良好健康指数
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/月2026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
Go
77良好健康指数
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 02026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
Go · Maven
77良好健康指数
seqra/seqra
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 1102026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
PyPI
77良好健康指数
sjkim1127/Reversecore_MCP
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
Python★ 1812026年7月21日
MIT2026年7月21日 · 指标 2.10.0
Go · npm · PyPI
75良好健康指数
KKloudTarus/synapse-ce
Synapse - a governed control plane for software composition analysis, recon, evidence, and reporting. Verify Everything. Trust Nothing.
Go · Python★ 332026年8月6日
Apache-2.02026年8月6日 · 指标 2.10.0
Go
71良好健康指数
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 252026年9月5日
自定义许可证2026年9月5日 · 指标 2.10.0
Packagist
69良好健康指数
dgtlss/warden
A Laravel package that proactively monitors your dependencies for security vulnerabilities by running automated composer audits and sending notifications via webhooks and email
PHP★ 97↓ 7,100/月2026年9月5日
MIT2026年9月5日 · 指标 2.10.0
npm
69良好健康指数
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/月2026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
PyPI
67良好健康指数
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 22026年7月31日
MIT2026年7月31日 · 指标 2.10.0
npm
63中等健康指数
TypeScript★ 89↓ 2,730/月2026年8月5日
Apache-2.02026年8月5日 · 指标 2.10.0
Go
63中等健康指数
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 32026年7月17日
MIT2026年7月17日 · 指标 2.10.0
Go · npm
62中等健康指数
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 32026年7月19日
MIT2026年7月19日 · 指标 2.10.0
Go
60中等健康指数
alexpermiakov/sast-triage
AI-powered triage for SAST findings.
Go★ 02026年7月26日
MIT2026年7月26日 · 指标 2.10.0
PyPI · crates.io · Maven +2
57中等健康指数
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 122026年7月17日
自定义许可证2026年7月17日 · 指标 2.10.0
npm
54中等健康指数
sudoeren/arhus
local-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2,972/月2026年7月17日
MIT2026年7月17日 · 指标 2.10.0
Go
51中等健康指数
greprules/greprules
CLI & Agent plugin for fetching SAST rule packs from greprules.io and scanning local code changes.
Go · Python★ 72026年7月18日
Apache-2.02026年7月18日 · 指标 2.10.0
crates.io
48薄弱健康指数
eezz4/zzop
Deterministic cross-repo contract analysis you can gate CI on — joins frontend calls to backend routes across repo boundaries and flags drift (typo'd path, version skew, dead endpoint). Also a multi-language SAST/architecture engine (TS/JS, Prisma, Java), extensible via adapters. Rust core, npm CLI/SDK.
Rust★ 12026年7月23日
MIT2026年7月23日 · 指标 2.10.0
Go
42薄弱健康指数
malandas/andas
Sift real security risk from the noise — a cross-platform CLI that live-validates leaked secrets and reachability-ranks npm/Yarn vulnerabilities, so you fix what's actually exploitable.
Go★ 02026年8月6日
MIT2026年8月6日 · 指标 2.10.0
npm
39薄弱健康指数
KaraboGerald/SeamShieldCLI
SeamShield Community CLI: local-first access-lane scanning for AI-built apps
TypeScript · JavaScript★ 0↓ 2,130/月2026年8月4日
MIT2026年8月4日 · 指标 2.10.0