Static Analysis & Code Quality
535 items from analysis-tools-dev/static-analysis ★14,830
-
Trivy github.com
Aqua Security's open source simple and comprehensive vulnerability scanner for containers (suitable for CI).
-
-
Deepfence Threat Mapper github.com
Powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.
-
-
Gitleaks github.com
A SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repos.
-
pyright github.com
Fast type checker meant for large Python source bases. It can run in a “watch” mode and performs fast incremental updates when files are modified.
-
-
-
-
-
-
-
bundler-audit github.com
Audit Gemfile.lock for gems with security vulnerabilities reported in Ruby Advisory Database.
-
-
Tsunami Security Scanner github.com
A general purpose network security scanner with an extensible plugin system for detecting high severity RCE-like vulnerabilities with high confidence. Custom detectors for finding vulnerabilities (e.g. open APIs) can be added.
-
-
-
-
.NET Compiler Platform ("Roslyn") Analyzers github.com
Roslyn-based implementation of FxCop analyzers.
-
tfsec github.com
Terraform static analysis tool that prevents potential security issues by checking cloud misconfigurations at build time and directly integrates with the HCL parser for better results. Checks for violations of AWS, Azure and GCP security best practice recommendations.
-
PHP Insights github.com
Instant PHP quality checks from your console. Analysis of code quality and coding style as well as overview of code architecture and its complexity.
-
oxc github.com
The Oxidation Compiler is creating a suite of high-performance tools for the JavaScript / TypeScript language re-written in Rust.
-
credo github.com
A static code analysis tool with a focus on code consistency and teaching Elixir. (Docs).
-
-
-
detect-secrets github.com
An enterprise friendly way of detecting and preventing secrets in code. It does this by running periodic diff outputs against heuristically crafted regex statements, to identify whether any new secret has been committed. This way, it avoids the overhead of digging through all…
-
DevSkim github.com
Regex-based static analysis tool for Visual Studio, VS Code, and Sublime Text - C/C++, C#, PHP, ASP, Python, Ruby, Java, and others.
-
-
-
- next page of items loading…