Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
#

sast

Here are 259 public repositories matching this topic...

static-analysis

⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.

  • UpdatedMar 10, 2025
  • Rust
semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

  • UpdatedMar 18, 2025
  • OCaml
terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

  • UpdatedDec 10, 2024
  • Go

nodejsscan is a static security code scanner for Node.js applications.

  • UpdatedMar 5, 2025
  • CSS

《深入理解CodeQL》Finding vulnerabilities with CodeQL.

  • UpdatedNov 21, 2023
horusec

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

  • UpdatedMar 15, 2025
  • Go

IDEA静态代码安全审计及漏洞一键修复插件

  • UpdatedMar 10, 2022
  • Java

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and Git friendly.

  • UpdatedSep 1, 2023
  • Python
APKHunt

APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.

  • UpdatedJan 17, 2025
  • Go

基于pytorch的ocr算法库,包括 psenet, pan, dbnet, sast , crnn

  • UpdatedMay 19, 2021
  • C++

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.

  • UpdatedJan 31, 2025
  • Python

Static Application Security Testing (SAST) engine focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code, focused on a agile and easy to implement software inside your DevOps pipeline. Support the following technologies: Java (Maven and Android), Kotlin (Android), Swift (iOS), .NET Ful…

  • UpdatedApr 10, 2022
  • Go

njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.

  • UpdatedNov 14, 2024
  • JavaScript
globstar

Globstar is a fast, feature-rich, and open-source static analysis toolkit for writing and running code checkers. Based on tree-sitter.

  • UpdatedMar 18, 2025
  • Go

xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".

  • UpdatedMar 4, 2025
  • Java

"chanzi" is a simple and user-friendly JAVA SAST tool that utilizes taint analysis technology, includes built-in common vulnerability rules, supports decompile, custom rule, and is compatible with the technology stacks of Servlet&filter, Spring,struts,Dubbo,Thrift, jax-rs,jax-ws,JFinal,Netty,MyBatis,and JSP.

  • UpdatedMar 16, 2025

《深入理解SAST静态应用安全测试》Static Application Security Testing.

  • UpdatedApr 13, 2024

A declarative static analysis tool for jvm bytecode based Datalog like CodeQL

  • UpdatedJan 6, 2024
  • Shell

Improve this page

Add a description, image, and links to thesast topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with thesast topic, visit your repo's landing page and select "manage topics."

Learn more


[8]ページ先頭

©2009-2025 Movatter.jp