GitHub 中文社区
回车: Github搜索    Shift+回车: Google搜索
论坛
排行榜
趋势
登录

©2025 GitHub中文社区论坛GitHub官网网站地图GitHub官方翻译

  • X iconGitHub on X
  • Facebook iconGitHub on Facebook
  • Linkedin iconGitHub on LinkedIn
  • YouTube iconGitHub on YouTube
  • Twitch iconGitHub on Twitch
  • TikTok iconGitHub on TikTok
  • GitHub markGitHub’s organization on GitHub
集合主题趋势排行榜
#

sast

Website
Wikipedia
analysis-tools-dev/static-analysis
https://static.github-zh.com/github_avatars/analysis-tools-dev?size=40
analysis-tools-dev / static-analysis

#Awesome#⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.

static-analysisstatic-analyzerslinterCode qualityAwesome ListsStatic code analysissastanalysisHacktoberfest
Rust 13.86 k
1 个月前
semgrep/semgrep
https://static.github-zh.com/github_avatars/semgrep?size=40
semgrep / semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

static-analysisStatic code analysisJavaGosastsemgrepr2cCPythonRubyJavaScriptTypeScript
OCaml 11.84 k
3 天前
tenable/terrascan
https://static.github-zh.com/github_avatars/tenable?size=40
tenable / terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

安全Infrastructure as codedevsecopsDevOpsTerraformAmazon Web Servicescloudsecuritycloud-securityterrascaninfrastructurearchitectureKubernetessastazure-securityaws-securitygcp-securityscans
Go 4.96 k
1 个月前
https://static.github-zh.com/github_avatars/ajinabraham?size=40
ajinabraham / nodejsscan

nodejsscan is a static security code scanner for Node.js applications.

JavaScriptNode.jsstatic-analysis安全security-scannersastdevsecopscode-analysis代码审查lint
CSS 2.47 k
1 个月前
https://static.github-zh.com/github_avatars/Bearer?size=40
Bearer / bearer

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

appseccompliancedevsecopsdevsecops-tools安全dataflowgdpr隐私sastStatic code analysisvulnerabilitysecurity-scannervulnerabilitiesCode qualitystatic-analysissecurity-automationowasp
Go 2.31 k
1 个月前
https://static.github-zh.com/github_avatars/ASTTeam?size=40
ASTTeam / CodeQL

《深入理解CodeQL》Finding vulnerabilities with CodeQL.

0e0wcodeqlhackjavahackaspxhackgolangjavasecqllearning-codeqlcodeql-queriessemmle-qldevsecopssast
1.63 k
2 年前
ZupIT/horusec
https://static.github-zh.com/github_avatars/ZupIT?size=40
ZupIT / horusec

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

sastJavaKotlinGoPythonRubyTerraformnetcore安全security-development持续集成CD (Disambiguation)命令行界面Hacktoberfestvulnerabilitiesanalysisscannerstatic-analysis
Go 1.23 k
7 天前
https://static.github-zh.com/github_avatars/momosecurity?size=40
momosecurity / momo-code-sec-inspector-java

IDEA静态代码安全审计及漏洞一键修复插件

sastJavaidea
Java 1.03 k
3 年前
https://static.github-zh.com/github_avatars/tcosolutions?size=40
tcosolutions / betterscan

Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners with One Report (Code, IaC) - Betterscan

sastCode qualitycode-quality-analyzerstatic-analysisStatic code analysisstatic-analyzersdevsecopssonarqubecomplianceDevOpsdevops-toolsgdprowasp安全security-automationsecurity-scannervulnerabilityvulnerability-scannersecurity-orchestration
Python 864
6 天前
https://static.github-zh.com/github_avatars/ShiftLeftSecurity?size=40
ShiftLeftSecurity / sast-scan

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and Git friendly.

sastdevsecopsappseclicense-scanworkflowscanners
Python 843
2 年前
https://static.github-zh.com/github_avatars/Cyber-Buddy?size=40
Cyber-Buddy / APKHunt

APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers,...

android-securityCybersecurityowasppenetration-testingpentestpentestingpentesting-toolssastsecure-coding安全static-analysisstatic-analyzer代码审查masvsmstg
Go 812
5 个月前
https://static.github-zh.com/github_avatars/BADBADBADBOY?size=40
BADBADBADBOY / pytorchOCR

基于pytorch的ocr算法库,包括 psenet, pan, dbnet, sast , crnn

OCRtextdetectiondbnetpsenetcrnntextrecognitionsast
C++ 684
4 年前
https://static.github-zh.com/github_avatars/MobSF?size=40
MobSF / mobsfscan

#安卓#mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis r...

Androidstatic-analysisappseccodereviewiOSJavaKotlinObjective-Csast安全Swift
Python 663
4 个月前
https://static.github-zh.com/github_avatars/insidersec?size=40
insidersec / insider

#安卓#Static Application Security Testing (SAST) engine focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code, focused on a agile and easy to im...

sast安全security-scannersecurity-automation命令行界面android-securityios-securityinsiderowaspNode.jsJavaScriptAndroidKotlinSwift.NETC#MaveniOSstatic-analyzerstatic-analysis
Go 540
3 年前
https://static.github-zh.com/github_avatars/DeepSourceCorp?size=40
DeepSourceCorp / globstar

Globstar is a fast, feature-rich, and open-source static analysis toolkit for writing and running code checkers. Based on tree-sitter.

Code qualitycode-securitysaststatic-analysisTree-sitter
Go 439
19 天前
https://static.github-zh.com/github_avatars/awslabs?size=40
awslabs / automated-security-helper

ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.

Amazon Web ServicesInfrastructure as codesastscascanner安全
Shell 426
5 天前
https://static.github-zh.com/github_avatars/ajinabraham?size=40
ajinabraham / njsscan

njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.

Node.jsExpresssastdevsecopslinter安全semanticPythonappsecstatic-analysiscodereviewstatic-analyzerlint
JavaScript 401
7 个月前
https://static.github-zh.com/github_avatars/alipay?size=40
alipay / ant-application-security-testing-benchmark

xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".

applicationbenchmarkevaluation安全Testingdastiastsastsca
Java 394
2 个月前
https://static.github-zh.com/github_avatars/Chanzi-keji?size=40
Chanzi-keji / chanzi

"chanzi" is a simple and user-friendly JAVA SAST tool that utilizes taint analysis technology, includes built-in common vulnerability rules, supports decompile, custom rule, and is compatible with th...

sastJavajavasecjavasecurity安全java-securitystatic-analysisstatic-analyzerstatic-analyzers
391
13 天前
https://static.github-zh.com/github_avatars/ASTTeam?size=40
ASTTeam / SAST

《深入理解SAST静态应用安全测试》Static Application Security Testing.

0e0wsast
344
1 年前
loading...