Static Analysis & Code Scanning

17 repos

Tools and rule sets for static program analysis, pattern matching, and security scanning across multiple languages. Semgrep is the primary engine here—an OCaml-based static analysis framework that detects bugs, security vulnerabilities, and code quality issues using custom rules. The cluster includes Semgrep's rule repositories, language interfaces, and related analysis tooling, making it a coherent ecosystem for building and deploying static analysis pipelines at scale.

OCaml · 6
Go · 4
Python · 3
HCL · 2
Java · 1
static-analysis ·42,239
static-code-analysis ·38,080
java ·37,283
semgrep ·36,441
sast ·34,835
go ·33,975
r2c ·33,178
javascript ·33,178
ruby ·33,178
c ·33,178