User-friendly documentation for the SARIF file format.
-
Updated
Dec 15, 2023
User-friendly documentation for the SARIF file format.
⚙️ Scan your Go, Java, Kotlin, PHP, Python, JavaScript, TypeScript, .NET projects at GitHub with Qodana. This repository contains Qodana for Azure, GitHub, CircleCI and Gradle
A security scanner as fast as a linter, written in Rust. Batteries included, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Corax for Java: A general static analysis framework for java code checking.
Lint, format and auto-fix your Groovy / Jenkinsfile / Gradle files using command line
AI Bill of Materials — discover every AI agent, model, and API in your infrastructure
🔧 JetBrains Qodana’s official command line tool
Enterprise AI Red Team Platform | 企业级AI红队平台 | 132 MCP Tools | Pure Python Engines | SDK+CLI+MCP | Auto-Download sqlmap/nuclei/ffuf | Production C2 | LLM Enhanced | Docker Sandbox | SARIF CI/CD | 1980 Tests
Semantic SBOM/CBOM diff, quality scoring, and TUI analysis tool for CycloneDX/SPDX — covering component changes, dependency shifts, license conflicts, vulnerabilities, cryptographic inventory grading, and PQC compliance (CNSA 2.0, NIST IR 8547).
Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure DevOps, Google CloudBuild, VS Code and Visual Studio. No server required!
Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.
Lockfile-first scanner for compromised npm/PyPI/Maven/Cargo/Go/RubyGems packages — OSV + curated extras feed, SLSA L3, locked-container CI
♿ Suite of open and standards-based tools for performing reliable accessibility conformance testing at scale
A React-based component for viewing SARIF files.
Go library for SARIF - Static Analysis Results Interchange Format
AI-native security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.
PHP static analysis for architecture & maintainability — 60+ metrics, complexity analysis, dependency graphs, git churn hotspots, and AI-ready MCP server. Alternative to PHPMetrics.
Threat modeling and AI-reasoning vulnerability detection harness for Claude Code — STRIDE + AI + MAESTRO
🐚 GitHub Action for running ShellCheck differentially
Add a description, image, and links to the sarif topic page so that developers can more easily learn about it.
To associate your repository with the sarif topic, visit your repo's landing page and select "manage topics."