Repository navigation

#

sast

analysis-tools-dev/static-analysis

⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.

Rust
14026
3 小时前
semgrep/semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

OCaml
12539
1 天前
tenable/terrascan
Go
5120
19 天前

nodejsscan is a static security code scanner for Node.js applications.

CSS
2492
1 个月前
1670
2 年前
ZupIT/horusec

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Go
1250
4 天前

IDEA静态代码安全审计及漏洞一键修复插件

Java
1038
3 年前

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and Git friendly.

Python
850
2 年前

APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.

Go
829
7 个月前

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.

Python
687
7 个月前

基于pytorch的ocr算法库,包括 psenet, pan, dbnet, sast , crnn

C++
681
4 年前

Static Application Security Testing (SAST) engine focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code, focused on a agile and easy to implement software inside your DevOps pipeline. Support the following technologies: Java (Maven and Android), Kotlin (Android), Swift (iOS), .NET Full Framework, C#, and Javascript (Node.js).

Go
547
3 年前

ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.

Python
472
12 天前

Globstar is a fast, feature-rich, and open-source static analysis toolkit for writing and running code checkers. Based on tree-sitter.

Go
456
2 个月前

"chanzi" is a simple and user-friendly JAVA SAST tool that utilizes taint analysis technology, includes built-in common vulnerability rules, supports decompile, custom rule, and is compatible with the technology stacks of Servlet&filter, Spring,struts,Dubbo,Thrift, jax-rs,jax-ws,JFinal,Netty,MyBatis,and JSP.

415
4 天前

xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".

Java
411
5 天前

njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.

JavaScript
408
9 个月前