An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with static-analysis

A curated list of projects in awesome lists tagged with static-analysis .

https://github.com/astral-sh/ruff

An extremely fast Python linter and code formatter, written in Rust.

linter pep8 python python3 ruff rust rustpython static-analysis static-code-analysis style-guide styleguide

Last synced: 12 Dec 2025

https://github.com/koalaman/shellcheck

ShellCheck, a static analysis tool for shell scripts

bash developer-tools haskell linter shell static-analysis

Last synced: 12 May 2025

https://github.com/charliermarsh/ruff

An extremely fast Python linter and code formatter, written in Rust.

linter pep8 python python3 ruff rust rustpython static-analysis static-code-analysis style-guide styleguide

Last synced: 02 Sep 2025

https://github.com/mobsf/mobile-security-framework-mobsf

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

android-security api-testing apk cwe devsecops dynamic-analysis ios-security malware-analysis mastg masvs mobile-security mobsf mstg owasp rest runtime-security static-analysis web-security windows-mobile-security

Last synced: 09 Sep 2025

https://github.com/realm/SwiftLint

A tool to enforce Swift style and conventions.

code-quality hacktoberfest linter linting static-analysis swift

Last synced: 06 Aug 2025

https://github.com/realm/swiftlint

A tool to enforce Swift style and conventions.

code-quality hacktoberfest linter linting static-analysis swift

Last synced: 09 Sep 2025

https://realm.github.io/SwiftLint/

A tool to enforce Swift style and conventions.

code-quality hacktoberfest linter linting static-analysis swift

Last synced: 24 Mar 2025

https://github.com/nikic/php-parser

A PHP parser written in PHP

ast parser php static-analysis

Last synced: 09 Sep 2025

https://github.com/nikic/PHP-Parser

A PHP parser written in PHP

ast parser php static-analysis

Last synced: 14 Mar 2025

https://github.com/MobSF/Mobile-Security-Framework-MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

android-security api-testing apk cwe devsecops dynamic-analysis ios-security malware-analysis mastg masvs mobile-security mobsf mstg owasp rest runtime-security static-analysis web-security windows-mobile-security

Last synced: 19 Mar 2025

https://github.com/facebook/infer

A static analyzer for Java, C, C++, and Objective-C

c code-quality cpp java objective-c static-analysis static-code-analysis

Last synced: 12 May 2025

https://github.com/konloch/bytecode-viewer

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

android apk baksmali bytecode bytecode-viewer cfr compiler decompiler dex2jar fernflower hacktoberfest java java-decompiler jsp krakatau procyon recompiler smali static-analysis war

Last synced: 14 May 2025

https://github.com/Konloch/bytecode-viewer

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

android apk baksmali bytecode bytecode-viewer cfr compiler decompiler dex2jar fernflower hacktoberfest java java-decompiler jsp krakatau procyon recompiler smali static-analysis war

Last synced: 24 Mar 2025

https://github.com/phpstan/phpstan

PHP Static Analysis Tool - discover bugs in your code without running it!

php php7 phpstan static-analysis static-analyzer static-code-analysis testing

Last synced: 12 May 2025

https://github.com/php-cs-fixer/php-cs-fixer

A tool to automatically fix PHP Coding Standards issues

code-standards code-style php static-analysis

Last synced: 04 Jan 2026

https://github.com/mre/awesome-static-analysis

⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.

analysis awesome-list code-quality hacktoberfest linter sast static-analysis static-analyzers static-code-analysis

Last synced: 19 Mar 2025

https://github.com/PHP-CS-Fixer/PHP-CS-Fixer

A tool to automatically fix PHP Coding Standards issues

code-standards code-style hacktoberfest php static-analysis

Last synced: 14 Mar 2025

https://github.com/OWASP/owasp-mstg

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

android android-application compliancy-checklist dynamic-analysis hacking ios ios-app mast mastg mobile-app mobile-security mstg network-analysis pentesting reverse-engineering reverse-enginnering runtime-analysis static-analysis testing-cryptography

Last synced: 17 Aug 2025

https://github.com/owasp/owasp-mastg

The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).

android android-application compliancy-checklist dynamic-analysis hacking ios ios-app mast mastg mobile-app mobile-security mstg network-analysis pentesting reverse-engineering reverse-enginnering runtime-analysis static-analysis testing-cryptography

Last synced: 14 May 2025

https://github.com/OWASP/owasp-mastg

The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).

android android-application compliancy-checklist dynamic-analysis hacking ios ios-app mast mastg mobile-app mobile-security mstg network-analysis pentesting reverse-engineering reverse-enginnering runtime-analysis static-analysis testing-cryptography

Last synced: 19 Mar 2025

https://github.com/semgrep/semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

c go java javascript python r2c ruby sast semgrep static-analysis static-code-analysis typescript

Last synced: 14 May 2025

https://github.com/hadolint/hadolint

Dockerfile linter, validate inline bash, written in Haskell

docker dockerfile dockerfile-linter haskell linter shellcheck static-analysis

Last synced: 13 May 2025

https://github.com/squizlabs/php_codesniffer

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards.

automation cli coding-standards php qa static-analysis

Last synced: 13 May 2025

https://github.com/squizlabs/PHP_CodeSniffer

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards.

automation cli coding-standards php qa static-analysis

Last synced: 14 Mar 2025

https://github.com/quay/clair

Vulnerability Static Analysis for Containers

clair containers docker go kubernetes oci oci-image static-analysis vulnerabilities

Last synced: 12 May 2025

https://github.com/coreos/clair

Vulnerability Static Analysis for Containers

clair containers docker go kubernetes oci oci-image static-analysis vulnerabilities

Last synced: 23 Mar 2025

https://hadolint.github.io/hadolint/

Dockerfile linter, validate inline bash, written in Haskell

docker dockerfile dockerfile-linter haskell linter shellcheck static-analysis

Last synced: 03 Nov 2025

https://github.com/checkstyle/checkstyle

Checkstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.

code-quality command-line-tool hacktoberfest java static-analysis static-code-analysis

Last synced: 30 Nov 2025

https://github.com/ast-grep/ast-grep

⚡A CLI tool for code structural search, lint and rewriting. Written in Rust

ast babel codemod codereview command-line command-line-tool grep linter refactoring rust search static-analysis structural-search tree-sitter typescript

Last synced: 12 May 2025

https://github.com/reviewdog/reviewdog

🐶 Automated code review tool integrated with any code analysis tools regardless of programming language

bitbucket ci cli code-quality code-review codereview github gitlab go lint linter static-analysis static-code-analysis

Last synced: 12 May 2025

https://github.com/bridgecrewio/checkov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

aws aws-security azure cloudformation compliance devops gcp hacktoberfest infrastructure-as-code kubernetes scans static-analysis terraform

Last synced: 12 May 2025

https://github.com/presidentbeef/brakeman

A static analysis security vulnerability scanner for Ruby on Rails applications

brakeman rails ruby security security-audit security-tools security-vulnerability static-analysis vulnerabilities

Last synced: 12 May 2025

https://github.com/google/error-prone

Catch common Java mistakes as compile-time errors

java static-analysis

Last synced: 12 May 2025

https://github.com/anchore/syft

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

containers cyclonedx docker go golang hacktoberfest oci sbom spdx static-analysis tool

Last synced: 12 May 2025

https://github.com/dominikh/go-tools

Staticcheck - The advanced Go linter

linter linters sponsor static-analysis staticcheck

Last synced: 12 May 2025

https://github.com/ondrajz/go-callvis

Visualize call graph of a Go program using Graphviz

awesome-go callgraph golang golang-tools graphviz static-analysis visualization

Last synced: 23 Apr 2025

https://github.com/danmar/cppcheck

static analysis of C/C++ code

c c-plus-plus cpp cppcheck cross-platform static-analysis

Last synced: 12 May 2025

https://github.com/davidhalter/jedi

Awesome autocompletion, static analysis and refactoring library for python

auto-complete python refactoring static-analysis type-inference

Last synced: 12 May 2025

https://github.com/palantir/tslint

:vertical_traffic_light: An extensible linter for the TypeScript language

linter linting-rules octo-correct-managed static-analysis tslint typescript

Last synced: 05 Oct 2025

https://github.com/sverweij/dependency-cruiser

Validate and visualize dependencies. Your rules. JavaScript, TypeScript, CoffeeScript. ES6, CommonJS, AMD.

architecture-diagram circular-dependencies dependencies dependency-analysis dependency-cruiser dependency-graph javascript jsx static-analysis tsx typescript vue

Last synced: 12 Dec 2025

https://github.com/vimeo/psalm

A PHP static analysis tool for finding errors and security vulnerabilities in PHP applications

hacktoberfest php security-analysis static-analysis taint-analysis type-inference

Last synced: 13 May 2025

https://github.com/crytic/slither

Static Analyzer for Solidity and Vyper

ethereum solidity static-analysis vyper

Last synced: 13 May 2025

https://github.com/phan/phan

Phan is a static analyzer for PHP. Phan prefers to avoid false-positives and attempts to prove incorrectness rather than correctness.

analysis analyzer phan php static-analysis static-code-analysis

Last synced: 13 May 2025

https://github.com/dsherret/ts-morph

TypeScript Compiler API wrapper for static analysis and programmatic code changes.

ast code-generation javascript static-analysis typescript

Last synced: 12 May 2025

https://github.com/pmd/pmd

An extensible multilanguage static code analyzer.

apex code-analysis code-quality hacktoberfest java linter plsql static-analysis static-code-analysis swift

Last synced: 09 Sep 2025

https://github.com/mgechev/revive

🔥 ~6x faster, stricter, configurable, extensible, and beautiful drop-in replacement for golint

go golang golint hacktoberfest linter static-analysis static-code-analysis

Last synced: 09 Sep 2025

https://github.com/rrrene/credo

A static code analysis tool for the Elixir language with a focus on code consistency and teaching.

code-analysis credo elixir linter static-analysis

Last synced: 14 May 2025

https://github.com/didi/booster

🚀Optimizer for mobile applications

android bytecode-manipulation gradle-plugin optimizer static-analysis

Last synced: 12 May 2025

https://github.com/google/pytype

A static type analyzer for Python code

linter python static-analysis static-code-analysis typechecker types typing

Last synced: 13 May 2025

https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.

android-application dynamic-analysis ios-app mobile-app network-analysis pentesting reverse-engineers runtime-analysis static-analysis

Last synced: 19 Mar 2025

https://github.com/tanprathan/mobileapp-pentest-cheatsheet

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.

android-application dynamic-analysis ios-app mobile-app network-analysis pentesting reverse-engineers runtime-analysis static-analysis

Last synced: 25 Feb 2025

https://github.com/microsoft/applicationinspector

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.

application-inspector detection security-scanner security-tools software-characterization static-analysis

Last synced: 06 May 2025

https://github.com/microsoft/ApplicationInspector

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.

application-inspector detection security-scanner security-tools software-characterization static-analysis

Last synced: 24 Mar 2025

https://github.com/shobrook/adrenaline

Instant answers to any programming question

ai chatbot codegen developer-tool gpt-4 llm static-analysis

Last synced: 07 Jul 2025

https://github.com/uber/nullaway

A tool to help eliminate NullPointerExceptions (NPEs) in your Java code with low build-time overhead

android java nullability nullability-analysis static-analysis static-code-analysis

Last synced: 13 May 2025

https://github.com/uber/NullAway

A tool to help eliminate NullPointerExceptions (NPEs) in your Java code with low build-time overhead

android java nullability nullability-analysis static-analysis static-code-analysis

Last synced: 27 Mar 2025

https://github.com/spotbugs/spotbugs

SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.

code-analysis findbugs hacktoberfest linter static-analysis static-code-analysis

Last synced: 12 May 2025

https://github.com/pycqa/flake8

flake8 is a python tool that glues together pycodestyle, pyflakes, mccabe, and third-party plugins to check the style and quality of some python code.

complexity-analysis flake8 linter linter-flake8 pep8 python python3 static-analysis static-code-analysis style-guide styleguide stylelint

Last synced: 12 May 2025

https://github.com/PyCQA/flake8

flake8 is a python tool that glues together pycodestyle, pyflakes, mccabe, and third-party plugins to check the style and quality of some python code.

complexity-analysis flake8 linter linter-flake8 pep8 python python3 static-analysis static-code-analysis style-guide styleguide stylelint

Last synced: 27 Mar 2025

https://github.com/uber-go/nilaway

Static analysis tool to detect potential nil panics in Go code

go nil-pointer nilability nilability-analysis static-analysis

Last synced: 14 May 2025

https://github.com/stackrox/kube-linter

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best practices.

hactoberfest helm-charts kubernetes static-analysis yaml-files

Last synced: 13 May 2025

https://github.com/qax-os/goreporter

A Golang tool that does static analysis, unit testing, code review and generate code quality report.

codereview examination golang golang-tools linter quality-report reporter static-analysis staticcheck test unit-test unit-testing

Last synced: 15 Dec 2025

https://github.com/shivammathur/setup-php

GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and various tools.

code-coverage composer continuous-integration github-actions php php-extensions static-analysis tools

Last synced: 12 May 2025

https://github.com/nasa-sw-vnv/ikos

Static analyzer for C/C++ based on the theory of Abstract Interpretation.

abstract-interpretation program-analysis software-verification static-analysis

Last synced: 14 May 2025

https://mtshiba.github.io/pylyzer/

A fast, feature-rich static code analyzer & language server for Python

language-server python rust static-analysis type-checker

Last synced: 21 Nov 2025

https://github.com/exakat/php-static-analysis-tools

A reviewed list of useful PHP static analysis tools

php php-analysis php-applications php-formatter phplint static-analysis

Last synced: 14 May 2025

https://github.com/mtshiba/pylyzer

A fast, feature-rich static code analyzer & language server for Python

language-server python rust static-analysis type-checker

Last synced: 14 May 2025

https://github.com/qltysh/qlty

Qlty CLI: Universal linting, formatting, maintainability, security scanning, and metrics

code-quality formatter linter quality static-analysis

Last synced: 13 May 2025

https://github.com/zizmorcore/zizmor

Static analysis for GitHub Actions

github-actions security security-tools static-analysis

Last synced: 20 Oct 2025

https://github.com/ajinabraham/nodejsscan

nodejsscan is a static security code scanner for Node.js applications.

code-analysis code-review devsecops javascript lint node node-security nodejs nodejsscan sast security security-scanner static-analysis

Last synced: 14 May 2025

https://github.com/ericsson/codechecker

CodeChecker is an analyzer tooling, defect database and viewer extension for static and dynamic analyzer tools.

analysis c clang clang-tidy codechecker cpp database defects docker linux llvm macosx objective-c results-viewer static-analysis static-analyzer static-analyzers vue

Last synced: 12 May 2025

https://github.com/Ericsson/codechecker

CodeChecker is an analyzer tooling, defect database and viewer extension for static and dynamic analyzer tools.

analysis c clang clang-tidy codechecker cpp database defects docker linux llvm macosx objective-c results-viewer static-analysis static-analyzer static-analyzers vue

Last synced: 28 Apr 2025