sarif
Here are 212 public repositories matching this topic...
⚙️ Scan your Go, Java, Kotlin, PHP, Python, JavaScript, TypeScript, .NET projects at GitHub with Qodana. This repository contains Qodana for Azure, GitHub, CircleCI and Gradle
- Updated
- JavaScript
Corax for Java: A general static analysis framework for java code checking.
- Updated
- Kotlin
Lint, format and auto-fix your Groovy / Jenkinsfile / Gradle files using command line
- Updated
- JavaScript
🔧 JetBrains Qodana’s official command line tool
- Updated
- Go
AI Bill of Materials — discover every AI agent, model, and API in your infrastructure
- Updated
- Python
Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure DevOps, Google CloudBuild, VS Code and Visual Studio. No server required!
- Updated
- Python
Semantic SBOM diff and TUI analysis tool. Compares CycloneDX/SPDX files to component changes, dependency shifts, license conflicts, and vulnerabilities.
- Updated
- Rust
♿ Suite of open and standards-based tools for performing reliable accessibility conformance testing at scale
- Updated
- HTML
Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.
- Updated
- TypeScript
Go library for SARIF - Static Analysis Results Interchange Format
- Updated
- Go
🐚 GitHub Action for running ShellCheck differentially
- Updated
- Shell
SARIF Explorer: A VSCode extension that helps you visualize and triage static analysis results
- Updated
- TypeScript
vexctl is a tool to attest VEX impact statements
- Updated
- Go
PHP static analysis for architecture & maintainability — 60+ metrics, complexity analysis, dependency graphs, git churn hotspots, and AI-ready MCP server. Alternative to PHPMetrics.
- Updated
- PHP
AI-native security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.
- Updated
- Python
GitHub Action for filtering Code Scanning alerts by path and id
- Updated
- Java
GitHub issue manager from vulnerability scan results for private repositories
- Updated
- Go
Improve this page
Add a description, image, and links to the sarif topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the sarif topic, visit your repo's landing page and select "manage topics."
