User-friendly documentation for the SARIF file format.
-
Updated
Dec 15, 2023
User-friendly documentation for the SARIF file format.
⚙️ Scan your Go, Java, Kotlin, PHP, Python, JavaScript, TypeScript, .NET projects at GitHub with Qodana. This repository contains Qodana for Azure, GitHub, CircleCI and Gradle
Corax for Java: A general static analysis framework for java code checking.
Lint, format and auto-fix your Groovy / Jenkinsfile / Gradle files using command line
🔧 JetBrains Qodana’s official command line tool
A security scanner as fast as a linter, written in Rust.
Enterprise AI Red Team Platform | 企业级AI红队平台 | 132 MCP Tools | Pure Python Engines | SDK+CLI+MCP | Auto-Download sqlmap/nuclei/ffuf | Production C2 | LLM Enhanced | Docker Sandbox | SARIF CI/CD | 1980 Tests
AI Bill of Materials — discover every AI agent, model, and API in your infrastructure
Semantic SBOM/CBOM diff, quality scoring, and TUI analysis tool for CycloneDX/SPDX — covering component changes, dependency shifts, license conflicts, vulnerabilities, cryptographic inventory grading, and PQC compliance (CNSA 2.0, NIST IR 8547).
Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure DevOps, Google CloudBuild, VS Code and Visual Studio. No server required!
♿ Suite of open and standards-based tools for performing reliable accessibility conformance testing at scale
Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.
A React-based component for viewing SARIF files.
Go library for SARIF - Static Analysis Results Interchange Format
🐚 GitHub Action for running ShellCheck differentially
PHP static analysis for architecture & maintainability — 60+ metrics, complexity analysis, dependency graphs, git churn hotspots, and AI-ready MCP server. Alternative to PHPMetrics.
SARIF Explorer: A VSCode extension that helps you visualize and triage static analysis results
Automated threat modeling toolkit — STRIDE + AI-specific threats in one command
vexctl is a tool to attest VEX impact statements
Add a description, image, and links to the sarif topic page so that developers can more easily learn about it.
To associate your repository with the sarif topic, visit your repo's landing page and select "manage topics."