static-analysis

Ruff

An extremely fast Python linter, written in Rust.

Details
quick-lint-js

Find bugs in JavaScript programs.

Details
OpenSCA-cli

OpenSCA-cli is a supply-chain security tool for security researchers and developers.

Details
zizmor

Static analysis for GitHub Actions.

Details
rumdl

A fast Markdown linter and formatter written in Rust.

Details
KubeLinter

Analyze Kubernetes YAML files and Helm charts, and check them against a variety of best practices, with a focus on production readiness and security.

Details
GauntletCI

Deterministic pre-commit risk detection engine for git diffs.

Details
Grype

A vulnerability scanner for container images and filesystems

Details
Syft

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Details
ast-grep

A fast and polyglot tool for code searching, linting, rewriting at large scale.

Details
Mago

Mago is a toolchain for PHP that aims to provide a set of tools to help developers write better code.

Details
CredScope

CredScope is a deterministic, offline-first static credential exposure and reachability analyzer for Docker Compose and GitHub Actions.

Details
SearchDeadCode

Detect and safely remove dead code in Android projects (Kotlin & Java)

Details
ShellCheck

ShellCheck, a static analysis tool for shell scripts

Details
FLOSS

Automatically extract obfuscated strings from malware.

Details
Haskell Dockerfile Linter

Dockerfile linter, validate inline bash, written in Haskell

Details