#sarif (8 Repositories)
Ranked open-source repositories tagged with #sarif, scored by pull request acceptance likelihood and maintainer engagement velocity.
34.8%
4.0h
8 repositories tagged #sarif
arthurpanhku/dvalincode
Approvable, local-first AI coding agent for regulated teams: policy controls, governed MCP, evidence packs, audit trails, secure remediation, and any OpenAI-compatible model.
santhreal/keyhog
GPU-accelerated secret scanner for code, Git history, containers, cloud, browser assets, and CI. 923 detectors, live verification, CUDA, Metal, WGPU.
Agent-Field/sec-af
AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.
MustacheCase/zanadir
zanadir is an open-source CLI tool that analyzes GitHub repositories and suggests open-source tools to enhance CI/CD best practices.
gensecaihq/Shai-Hulud-2.0-Detector
GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.
JetBrains/qodana-action
⚙️ Scan your Go, Java, Kotlin, PHP, Python, JavaScript, TypeScript, .NET projects at GitHub with Qodana. This repository contains Qodana for Azure, GitHub, CircleCI and Gradle
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Feysh-Group/corax-community
Corax for Java: A general static analysis framework for java code checking.