YASA-UAST is an intermediate representation structure for multi-language program analysis. The UAST-Parser parses code from different programming languages into a unified abstract syntax format.
☆88Jul 6, 2026Updated 2 weeks ago
Alternatives and similar repositories for YASA-UAST
Users that are interested in YASA-UAST are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- YASA is an open-source static program analysis project. Its core innovation lies in a unified intermediate representation called UAST, d…☆298May 7, 2026Updated 2 months ago
- xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".☆485May 21, 2026Updated last month
- My presentation slides☆18Oct 31, 2025Updated 8 months ago
- Effective ReDoS Detection by Principled Vulnerability Modeling and Exploit Generation☆15Jul 24, 2025Updated 11 months ago
- ☆16Aug 1, 2025Updated 11 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆211Oct 27, 2025Updated 8 months ago
- The source code of [S&P'25] Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications.☆73Nov 20, 2025Updated 8 months ago
- Hacking GraalVM Espresso - Abusing Continuation API to Make ROP-like Attack☆36Aug 27, 2025Updated 10 months ago
- 高版本Fastjson在Java原生反序列化中的利用演示☆26Jan 12, 2025Updated last year
- Tai-e的Web插件☆23Jun 11, 2024Updated 2 years ago
- Framework for building reliable LLM agents with structured specs, operator-level verification, and progressive solidification.☆68Feb 27, 2026Updated 4 months ago
- Extract entire function source code based on giving line number using Javaparser☆21Jul 15, 2025Updated last year
- A curated list of awesome resources about LLM supply chain security (including papers, security reports and CVEs)☆105Jan 20, 2025Updated last year
- 用于快速启动tabby 分析漏洞或者gadget的环境☆93Jul 14, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- 一个IDEA插件:一键收集项目中所有jar包依赖的工具插件。遍历项目目录收集所有jar文件,复制到all-in-one文件夹,并自动添加为项目库。☆55Oct 30, 2025Updated 8 months ago
- ☆32Mar 31, 2026Updated 3 months ago
- A benchmark for Java gadget chain detecting algorithms.☆16Jun 20, 2025Updated last year
- idea插件,快速生成反序列化中常用的方法,比如setFieldValue、createTemplatesImpl等☆29Oct 2, 2024Updated last year
- Lessons for syntaxflow zero to hero☆56Sep 14, 2024Updated last year
- generate facts from bytecode (source is https://github.com/plast-lab/doop-mirror/tree/master/generators)☆23Nov 24, 2024Updated last year
- FIRE: Combining Multi-Stage Filtering with Taint Analysis for Scalable Recurring Vulnerability Detection.☆16Sep 27, 2024Updated last year
- Leveraging LLM to generate Java deserialization chains☆87Mar 12, 2026Updated 4 months ago
- Collection of CTF Web challenges I made☆53Apr 25, 2023Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A CAT called tabby ( Code Analysis Tool )☆1,655Jan 17, 2026Updated 6 months ago
- VulnGym: A Real-World, Project-Level Vulnerability Benchmark for White-Box Vulnerability-Hunting Agents☆203Jun 26, 2026Updated 3 weeks ago
- Security Vulnerability Repair via Concolic Execution and Code Mutations☆22Sep 12, 2024Updated last year
- TensorFlow API analysis tool and malicious model detection tool☆41May 27, 2025Updated last year
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter Analysis (IEEE S&P 2024)☆17Oct 3, 2024Updated last year
- 利用代理驱动绕过JDBC Attack检测☆146Jun 15, 2025Updated last year
- 闭源系统半自动漏洞挖掘工具,针对 jar/war/zip 进行静态代码分析,输出从source到sink的可达路径。LLM将验证路径可达性,并根据上下文给出该路径可信分数☆512Jan 12, 2026Updated 6 months ago
- 个人使用CodeQL编写的一 些规则☆181Mar 30, 2022Updated 4 years ago
- A neurosymbolic framework for vulnerability detection in code☆408Jul 2, 2026Updated 2 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- An easy-to-learn/use static analysis framework for Java and Android☆1,790Jun 28, 2026Updated 3 weeks ago
- A declarative static analysis tool for jvm bytecode based Datalog like CodeQL☆342Jan 6, 2024Updated 2 years ago
- Predator is a directed fuzzing-based Web application vulnerability validation prototype. It automates verifying static vulnerability repo…☆15May 19, 2025Updated last year
- Query-Based Code Analysis Engine☆356Sep 21, 2025Updated 9 months ago
- simpleIAST- 基于污点追踪的灰盒漏洞扫描工具。☆102Mar 24, 2026Updated 3 months ago
- SAST+AI的代码审计☆25Feb 28, 2026Updated 4 months ago
- ☆12Mar 5, 2026Updated 4 months ago