全部标签
目录标签

#static-analysis

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

362 条记录
标签为“static-analysis”按健康指数排序
PyPI · crates.io · npm
99卓越健康指数
astral-sh/ruff
An extremely fast Python linter and code formatter, written in Rust.
Rust★ 49.1K2026年8月5日
MIT2026年8月5日 · 指标 2.10.0
Go
98卓越健康指数
anchore/syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
Go★ 9,4652026年8月28日
Apache-2.02026年8月28日 · 指标 2.10.0
PyPI · RubyGems
98卓越健康指数
bridgecrewio/checkov
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
Python · HCL★ 8,9732026年8月28日
Apache-2.02026年8月28日 · 指标 2.10.0
PyPI
98卓越健康指数
pylint-dev/pylint
It's not just a linter that annoys you!
Python★ 5,718↓ 61.2M/月2026年8月28日
GPL-2.02026年8月28日 · 指标 2.10.0
PyPI
97卓越健康指数
semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
OCaml · Python★ 16.1K↓ 34.9M/月2026年8月5日
LGPL-2.12026年8月5日 · 指标 2.10.0
Packagist
96卓越健康指数
PHP-CS-Fixer/PHP-CS-Fixer
A tool to automatically fix PHP Coding Standards issues
PHP★ 13.5K↓ 6.6M/月2026年8月27日
MIT2026年8月27日 · 指标 2.10.0
RubyGems · crates.io
96卓越健康指数
Shopify/rubydex
A high-performance static analysis toolkit for Ruby
Rust · Ruby★ 2812026年7月20日
自定义许可证2026年7月20日 · 指标 2.10.0
Go
96卓越健康指数
anchore/grype
A vulnerability scanner for container images and filesystems
Go★ 12.8K2026年8月27日
Apache-2.02026年8月27日 · 指标 2.10.0
PyPI
96卓越健康指数
pylint-dev/astroid
A common base representation of python source code for pylint and other projects
Python★ 5812026年7月17日
LGPL-2.12026年7月17日 · 指标 2.10.0
RubyGems
96卓越健康指数
rubocop/rubocop-rspec
Code style checking for RSpec files.
Ruby★ 8572026年7月16日
MIT2026年7月16日 · 指标 2.10.0
Maven
96卓越健康指数
soot-oss/SootUp
A new version of Soot with a completely overhauled architecture
Java★ 8112026年7月25日
LGPL-2.12026年7月25日 · 指标 2.10.0
Maven
95卓越健康指数
SonarSource/sonar-java
:coffee: SonarSource Static Analyzer for Java Code Quality and Security
Java★ 1,2102026年7月17日
自定义许可证2026年7月17日 · 指标 2.10.0
PyPI
95卓越健康指数
cisco-ai-defense/skill-scanner
Security Scanner for Agent Skills
Python★ 2,4232026年8月13日
自定义许可证2026年8月13日 · 指标 2.10.0
Maven · npm
95卓越健康指数
detekt/detekt
Static code analysis for Kotlin
MDX · Kotlin★ 7,0362026年8月29日
Apache-2.02026年8月29日 · 指标 2.10.0
Go
95卓越健康指数
mgechev/revive
🔥 ~6x faster, stricter, configurable, extensible, and beautiful drop-in replacement for golint
Go★ 5,5472026年8月28日
MIT2026年8月28日 · 指标 2.10.0
Go · npm
95卓越健康指数
open-policy-agent/regal
Regal is a linter and language server for Rego, bringing your policy development experience to the next level!
Go · Open Policy Agent★ 3962026年7月26日
Apache-2.02026年7月26日 · 指标 2.10.0
Go
95卓越健康指数
securego/gosec
Go security checker
Go★ 8,9342026年8月28日
Apache-2.02026年8月28日 · 指标 2.10.0
npm
95卓越健康指数
vuejs/eslint-plugin-vue
Official ESLint plugin for Vue.js
TypeScript · JavaScript★ 4,594↓ 26.8M/月2026年8月27日
MIT2026年8月27日 · 指标 2.10.0
PyPI · crates.io
95卓越健康指数
zizmorcore/zizmor
Static analysis for GitHub Actions
Rust★ 6,402↓ 5.1M/月2026年8月28日
MIT2026年8月28日 · 指标 2.10.0
94卓越健康指数
OWASP/mastg
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
Python★ 13.1K2026年8月3日
CC-BY-SA-4.02026年8月3日 · 指标 2.10.0
npm · PyPI · crates.io
94卓越健康指数
ast-grep/ast-grep
⚡A CLI tool for code structural search, lint and rewriting. Written in Rust
Rust★ 15.4K↓ 3M/月2026年8月5日
MIT2026年8月5日 · 指标 2.10.0
crates.io
94卓越健康指数
codeclimate/codeclimate
💎 Code quality CLI for universal linting, auto-formatting, security scanning, and maintainability
Rust★ 3,0952026年7月15日
自定义许可证2026年7月15日 · 指标 2.10.0
Maven
94卓越健康指数
inria/spoon
Spoon is a metaprogramming library to analyze and transform Java source code. :spoon: is made with :heart:, :beers: and :sparkles:. It parses source files to build a well-designed AST with powerful analysis and transformation API.
Java★ 1,9452026年7月17日
自定义许可证2026年7月17日 · 指标 2.10.0
Packagist
94卓越健康指数
phan/phan
Phan is a static analyzer for PHP. Phan prefers to avoid false-positives and attempts to prove incorrectness rather than correctness.
PHP★ 5,623↓ 230.5K/月2026年8月28日
自定义许可证2026年8月28日 · 指标 2.10.0
Packagist · npm
94卓越健康指数
phpstan/phpstan
PHP Static Analysis Tool - discover bugs in your code without running it!
PHP · TypeScript★ 14.1K↓ 11.3M/月2026年8月22日
MIT2026年8月22日 · 指标 2.10.0
PyPI · npm
94卓越健康指数
sattyamjjain/agent-audit-kit
Static scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2,808/月2026年8月2日
MIT2026年8月2日 · 指标 2.10.0
Maven · PyPI
94卓越健康指数
spotbugs/spotbugs
SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
Java★ 3,9272026年8月28日
LGPL-2.12026年8月28日 · 指标 2.10.0
npm
94卓越健康指数
sverweij/dependency-cruiser
Validate and visualize dependencies. Your rules. JavaScript, TypeScript, CoffeeScript. ES6, CommonJS, AMD.
JavaScript★ 7,105↓ 13.5M/月2026年8月27日
MIT2026年8月27日 · 指标 2.10.0
Packagist
93卓越健康指数
WordPress/WordPress-Coding-Standards
PHP_CodeSniffer rules (sniffs) to enforce WordPress coding conventions
PHP★ 2,823↓ 2.2M/月2026年8月22日
MIT2026年8月22日 · 指标 2.10.0
crates.io · npm
93卓越健康指数
fallow-rs/fallow
Codebase intelligence for TypeScript and JavaScript. Free static analysis of code and styles: unused code, duplication, circular deps, complexity hotspots, architecture boundaries, design-system drift. Optional paid runtime layer (Fallow Runtime): hot-path review and cold-path deletion evidence from real production traffic.
Rust★ 4,419↓ 4,980/月2026年8月28日
MIT2026年8月28日 · 指标 2.10.0