Sarif Collection
Repositories tagged with "sarif"
Repositories tagged with "sarif"
sarif-tutorials
microsoft
โUser-friendly documentation for the SARIF file format.โ
qodana-action
JetBrains
โโ๏ธ Scan your Go, Java, Kotlin, PHP, Python, JavaScript, TypeScript, .NET projects at GitHub with Qodana. This repository contains Qodana for Azure, GitHub, CircleCI and Gradleโ
foxguard
0sec-labs
โA blazingly fast security scanner, written in Rust. Batteries included, TUI for triage, secrets, post-quantum audits, diff-aware scans and more ๐ฅโ
ai-bom
Trusera
โAI Bill of Materials โ discover every AI agent, model, and API in your infrastructureโ
corax-community
Feysh-Group
โCorax for Java: A general static analysis framework for java code checking.โ
AutoRedTeam-Orchestrator
Coff0xc
โEnterprise AI Red Team Platform | ไผไธ็บงAI็บข้ๅนณๅฐ | 132 MCP Tools | Pure Python Engines | SDK+CLI+MCP | Auto-Download sqlmap/nuclei/ffuf | Production C2 | LLM Enhanced | Docker Sandbox | SARIF CI/CD | 1980 Testsโ
npm-groovy-lint
nvuillam
โLint, format and auto-fix your Groovy / Jenkinsfile / Gradle files using command lineโ
qodana-cli
JetBrains
โ๐ง JetBrains Qodanaโs official command line toolโ
sbom-tools
sbom-tool
โSemantic SBOM/CBOM diff, quality scoring, and TUI analysis tool for CycloneDX/SPDX โ covering component changes, dependency shifts, license conflicts, vulnerabilities, cryptographic inventory grading, and PQC compliance (CNSA 2.0, NIST IR 8547).โ
sec-af
Agent-Field
โAI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.โ
pwned-deps
mkbhardwas12
โLockfile-first scanner for compromised npm/PyPI/Maven/Cargo/Go/RubyGems packages โ OSV + curated extras feed, SLSA L3, locked-container CIโ
sast-scan
AppThreat
โFully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure DevOps, Google CloudBuild, VS Code and Visual Studio. No server required!โ
Shai-Hulud-2.0-Detector
gensecaihq
โDetect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.โ
sarif-rs
psastras
โA group of Rust projects for interacting with the SARIF formatโ
alfa
Siteimprove
โ:wheelchair: Suite of open and standards-based tools for performing reliable accessibility conformance testing at scaleโ
ImpactGuard
daedalus
โImpactGuard โ Lightweight multi-language API impact analyzerโ
sarif-web-component
microsoft
โ A React-based component for viewing SARIF files.โ
agents-shipgate
ThreeMoonsLab
โThe deterministic merge gate for AI-generated agent capability changes โ a local-first, static Tool-Use Readiness review for MCP, OpenAPI, and SDK tool surfaces. Open-source CLI + GitHub Action.โ
