fucking-static-analysis
⚙️ A curated list of static analysis (SAST) tools for all programming languages, config files, build tools, and more. With repository stars⭐ and forks🍴
https://github.com/correia-jpv/fucking-static-analysis
Last synced: 11 days ago
JSON representation
-
Meaning of Symbols:
-
More Collections
-
Multiple languages
- ApplicationInspector
- Bearer - Source static code analysis tool to discover, filter and prioritize security risks and vulnerabilities leading to sensitive data exposures (PII, PHI, PD). Highly configurable and easily extensible, built for security and engineering teams.
- callGraph
- ClassGraph
- codeql - semantic queries and dataflow for several languages with VSCode plugin support.
- Depends
- DevSkim - based static analysis tool for Visual Studio, VS Code, and Sublime Text - C/C++, C#, PHP, ASP, Python, Ruby, Java, and others.
- dotnet-format - format is able to format C# and Visual Basic projects with a subset of supported `.editorconfig` options.
- emerge
- ESLint
- graudit - source code auditing tool.
- lizard - paste detection (code clone detection/code duplicate detection) and many other forms of static code analysis. Counts lines of code without comments, CCN (cyclomatic complexity number), token count of functions, parameter count of functions.
- OpenStaticAnalyzer
- Pronto
- Putout - in eslint, babel plugins support for js, jsx typescript, flow, markdown, yaml and json.
- relint
- Roslyn Analyzers - based implementation of FxCop analyzers.
- ShiftLeft Scan - source DevSecOps platform for detecting security issues in source code and dependencies. It supports a broad range of languages and CI/CD pipelines.
- ThreatMapper - of-exploit.
- todocheck
- trivy
- TscanCode
- Undebt - independent tool for massive, automatic, programmable refactoring based on simple pattern definitions.
- WALA
- LangLint - 20x faster with concurrent processing.
- sqlvet - and column names.
- Rev-dep
- oxc - performance tools for the JavaScript / TypeScript language re-written in Rust.
- BlockWatch - agnostic linter that keeps code, documentation, and configuration in sync and enforces strict formatting and validation rules.
- pfff - preserving source transformation for many languages.
- diesel-guard
- Skylos - aware analysis with 98% recall. Includes CI/CD GitHub Action, VS Code extension, and MCP server for AI agent integration.
- nestjs-doctor - patterns across security, performance, correctness, and architecture with 30+ built-in rules. Outputs a 0-100 health score. Includes module graph visualization, endpoint dependency graphs, and database schema analysis. CLI and VS Code extension.
- sem - level diffs, blame, and impact analysis on top of git. Uses tree-sitter to parse 26 languages and builds a cross-file dependency graph with structural hashing. Commands include sem diff, sem blame, sem graph, and sem impact for blast-radius analysis of code changes.
- Super-Linter
- weave - level semantic merge driver for git. Resolves false conflicts that line-based merge produces when independent changes touch the same file. Parses functions and classes via tree-sitter, matches by name, and merges at the entity level. Benchmarked at 100% clean merges vs git's 48% on a 31-scenario suite.
- Neurolint-CLI - based transformations.
-
Other
- alquitran
- angr
- binbloom
- BinSkim
- bloaty - O parsers, Bloaty aims to accurately attribute every byte of the binary to the symbol or compileunit that produced it. It will even disassemble the binary looking for references to anonymous data. F
- cwe_checker
- Jakstab - based, integrated disassembly and static analysis framework for designing analyses on executables and recovering reliable control flow graphs.
- Nauz File Detector
- VMware chap - instrumented ELF core files for leaks, memory growth, and corruption. It is sufficiently reliable that it can be used in automation to catch leaks before they are committed. As an interactive tool, it helps explain memory growth, can identify some forms of corruption, and supplements a debugger by giving the status of various memory locations.
- checkmake
- CSScomb
- Specificity Graph
- gixy
- AWS CloudFormation Guard - as-code rules and generate rules from existing templates.
- cfn_nag
- metadata-json-lint
- terrascan
- tfsec
- clair
- Dockle - Practice Docker Image. Scans Docker images for security vulnerabilities and CIS Benchmark compliance. Checks for secrets, credential exposure, and security best practices. Provides multiple severity levels (FATAL, WARN, INFO) and supports various output formats for CI/CD integration.
- Grype
- krane
- deno_lint
- oelint-adv - embedded and YOCTO
- Bootlint
- chart-testing
- clusterlint
- klint
- kube-lint - lint will evaluate those rules against them.
- kube-linter
- kubeconform
- markdownlint - based style checker and lint tool for Markdown/CommonMark files.
- mdsf
- FlowDroid
- deadnix
- lockfile-lint
- rpmlint
- promval
- protolint
- Credential Digger - model). This scanner is able to detect passwords and non structured tokens with a low false positive rate.
- detect-secrets
- Gitleaks
- scorecard - Security health metrics for Open Source
- Tsunami Security Scanner - like vulnerabilities with high confidence. Custom detectors for finding vulnerabilities (e.g. open APIs) can be added.
- mythril
- LibVCS4j
- ember-template-lint
- haml-lint
- slim-lint
- codespell
- misspell-fixer
- proselint
- write-good
- mdl
- statix
- tflint
- Manalyze
- promformat
- packj - source software packages for "risky" attributes that make them vulnerable to supply chain attacks. This is the tool behind our large-scale security analysis platform Packj.dev that continuously vets packages and provides free reports.
-
Programming Languages
- STOKE - language agnostic stochastic optimizer for the x86_64 instruction set. It uses random search to explore the extremely high-dimensional space of all possible program transformations.
- clazy - oriented static code analyzer based on the Clang framework. clazy is a compiler plugin which allows clang to understand Qt semantics. You get more than 50 Qt related compiler warnings, ranging from unneeded memory allocations to misusage of API, including fix-its for automatic refactoring.
- CMetrics
- cqmetrics
- ENRE-cpp - cpp is a ENtity Relationship Extractor for C/C++ based on @eclipse/CDT. (Under development)
- ESBMC - bounded model checker based on satisfiability modulo theories for the verification of single- and multi-threaded C/C++ programs.
- cpplint
- IKOS
- KLEE - generate test cases for programs such that the test cases exercise as much of the program as possible.
- splint - assisted static program checker.
- .NET Analyzers
- ArchUnitNET
- Meziantou.Analyzer
- SonarAnalyzer.CSharp
- Wintellect.Analyzers
- lint - driven set of lint rules for Dart and Flutter projects. Like pedantic but stricter
- DelphiLint - the-fly code analysis and linting, powered by SonarDelphi.
- SonarDelphi
- D-scanner - Scanner is a tool for analyzing D source code.
- credo
- dialyxir
- sobelow - focused static analysis for the Phoenix Framework.
- elvis
- FSharpLint
- bodyclose
- deadcode
- dogsled
- errcheck
- errwrap
- flen
- go-consistent
- go-critic
- gochecknoglobals
- goconst
- gofumpt - compatible. That is, `gofumpt` is happy with a subset of the formats that `gofmt` is happy with.
- gokart
- golint
- goreporter
- goroutine-inspect
- ineffassign
- misspell
- nakedret
- nargs
- prealloc
- structslop
- unconvert
- unparam
- wsl
- HLint
- Weeder
- ck - oriented metrics by processing the source Java files.
- Dataflow Framework - strength dataflow framework for Java. The Dataflow Framework is used in the Checker Framework, Google’s Error Prone, Uber’s NullAway, Meta’s Nullsafe, and in other contexts. It is distributed with the Checker Framework.
- DesigniteJava
- forbidden-apis
- google-java-format
- NullAway - based null-pointer checker with low build-time overhead; an [Error Prone](http://errorprone.info/) plugin.
- RefactorFirst
- Violations Lib
- JSLint - jpv/fucking-static-analysis/issues/223>) — The JavaScript Code Quality Tool.
- Polymer-analyzer
- xo
- JET
- StaticLint
- luacheck
- lualint - based static analysis of global variable usage in Lua source code.
- Sys
- VeriFast - threaded and multithreaded C and Java programs annotated with preconditions and postconditions written in separation logic. To express rich specifications, the programmer can define inductive datatypes, primitive recursive pure functions over these datatypes, and abstract separation logic predicates.
- churn-php
- composer-dependency-analyser
- dephpend
- deptrac
- DesignPatternDetector
- GrumPHP
- larastan
- parallel-lint
- Parse
- phan
- PHP Architecture Tester
- PHP Assumptions
- PHP Insights
- PHP-Parser
- php-speller
- PHPArkitect
- phploc
- phpmnd
- phpqa - jakzal
- phpqa - jmolivas - in-one Analyzer CLI tool.
- Progpilot
- Reflection
- Tuli
- twig-lint - lint is a lint tool for your twig files.
- zarn
- autoflake
- bellybutton - specific rules.
- cohesion
- Dlint
- flake8
Programming Languages
Categories
Sub Categories
Keywords
static-analysis
42
linter
39
security
22
golang
19
go
19
python
18
static-code-analysis
16
php
16
lint
14
rust
11
security-tools
11
kubernetes
10
cli
9
formatter
9
ruby
9
code-quality
9
typescript
7
static-analyzer
7
security-audit
6
devsecops
6
linters
6
java
6
eslint
6
docker
6
containers
5
vulnerability
5
javascript
5
code-analysis
5
analyzer
5
sast
5
compliance
5
analysis
5
security-scanner
5
nodejs
4
vulnerability-scanners
4
architecture
4
cargo
4
vulnerabilities
4
best-practices
4
linting
4
testing
4
quality
4
elixir
4
tool
4
program-analysis
4
qatools
3
metrics
3
rails
3
flake8
3
complexity
3