#sast (20 Repositories)
Ranked open-source repositories tagged with #sast, scored by pull request acceptance likelihood and maintainer engagement velocity.
37.7%
25.6h
20 repositories tagged #sast
arthurpanhku/dvalincode
Approvable, local-first AI coding agent for regulated teams: policy controls, governed MCP, evidence packs, audit trails, secure remediation, and any OpenAI-compatible model.
NodeSecure/js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
duriantaco/skylos
Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/
seqra/opentaint
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
awslabs/automated-security-helper
ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.
Agent-Field/sec-af
AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.
MustacheCase/zanadir
zanadir is an open-source CLI tool that analyzes GitHub repositories and suggests open-source tools to enhance CI/CD best practices.
sjkim1127/Reversecore_MCP
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
openhackai/OpenHack
Open Source Agentic Security Scanner
DeepSourceCorp/globstar
Globstar is a fast, feature-rich, and open-source static analysis toolkit for writing and running code checkers. Based on tree-sitter.
semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
ZupIT/horusec
Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
DataDog/datadog-saist
AI-native SAST
controlplaneio/kubesec
Security risk analysis for Kubernetes resources
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
alipay/ant-application-security-testing-benchmark
xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".
agentgg-dev/agentgg
Open source agentic SAST. The engine behind hundreds of disclosed zero-days. 100+ AI security agents, any repo or PR diff, bring your own model.
BytecodeDL/ByteCodeDL
A declarative static analysis tool for jvm bytecode based Datalog like CodeQL
cycodehq/cycode-cli
Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning
Feysh-Group/corax-community
Corax for Java: A general static analysis framework for java code checking.