⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.
☆14,440Mar 17, 2026Updated this week
Alternatives and similar repositories for static-analysis
Users that are interested in static-analysis are comparing it to the libraries listed below
Sorting:
- ⚙️ A curated list of dynamic analysis tools and linters for all programming languages, binaries, and more.☆1,076Feb 24, 2026Updated 3 weeks ago
- Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.☆14,430Mar 13, 2026Updated last week
- A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on…☆5,774Apr 3, 2024Updated last year
- A static analyzer for Java, C, C++, and Objective-C☆15,544Updated this week
- OSS-Fuzz - continuous fuzzing for open source software.☆11,967Updated this week
- ShellCheck, a static analysis tool for shell scripts☆39,110Mar 12, 2026Updated last week
- A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.☆14,117Jan 11, 2026Updated 2 months ago
- Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more☆33,205Updated this week
- Go security checker☆8,721Mar 13, 2026Updated last week
- Vulnerability Static Analysis for Containers☆10,945Updated this week
- An incremental parsing system for programming tools☆24,191Mar 13, 2026Updated last week
- CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security☆9,357Updated this week
- A curated list of resources for learning about application security☆6,849Feb 22, 2025Updated last year
- Find secrets with Gitleaks 🔑☆25,446Mar 12, 2026Updated last week
- Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.…☆3,014Updated this week
- Curated list of awesome resources on Compilers, Interpreters and Runtimes☆9,695May 26, 2024Updated last year
- Defund the Police.☆13,523Jun 7, 2024Updated last year
- UNIX-like reverse engineering framework and command-line toolset☆23,237Updated this week
- A collection of awesome penetration testing resources, tools and other shiny things☆25,569Jan 25, 2026Updated last month
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆6,096Mar 13, 2026Updated last week
- Checklist of the most important security countermeasures when designing, testing, and releasing your API☆23,198Feb 10, 2026Updated last month
- A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications☆2,205Dec 25, 2020Updated 5 years ago
- A command-line benchmarking tool☆27,714Feb 14, 2026Updated last month
- Bandit is a tool designed to find common security issues in Python code.☆7,863Mar 9, 2026Updated last week
- ripgrep recursively searches directories for a regex pattern while respecting your gitignore☆60,919Feb 27, 2026Updated 3 weeks ago
- Secure and fast microVMs for serverless computing.☆33,042Updated this week
- Find, verify, and analyze leaked credentials☆25,025Mar 13, 2026Updated last week
- A tool for exploring each layer in a docker image☆53,575Dec 15, 2025Updated 3 months ago
- A curated list of awesome command-line frameworks, toolkits, guides and gizmos. Inspired by awesome-php.☆36,634Aug 28, 2025Updated 6 months ago
- Performant type-checking for python.☆7,152Mar 13, 2026Updated last week
- Parsing, analyzing, and comparing source code across many languages☆9,051Apr 1, 2025Updated 11 months ago
- A simple, fast and user-friendly alternative to 'find'☆42,076Updated this week
- A powerful and user-friendly binary analysis platform!☆8,546Updated this week
- A collection of links related to Linux kernel security and exploitation☆6,375Mar 7, 2026Updated last week
- Scalable fuzzing infrastructure.☆5,535Updated this week
- A LLVM-based static analysis framework.☆1,036Updated this week
- A syntax-highlighting pager for git, diff, grep, and blame output☆29,464Mar 9, 2026Updated last week
- SQL powered operating system instrumentation, monitoring, and analytics.☆23,165Mar 12, 2026Updated last week
- Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices☆12,070Updated this week