Static Application Security Testing - SAST
References
https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/code-review-tools
https://owasp.org/www-community/Source_Code_Analysis_Tools
https://github.com/analysis-tools-dev/static-analysisGeneral
https://github.com/semgrep/semgrep
https://github.com/snyk/cli
https://www.sonarsource.com/open-source-editions/sonarqube-community-edition/Python
https://github.com/PyCQA/banditGolang
https://github.com/securego/gosec.NET
https://security-code-scan.github.io/Ruby
https://github.com/presidentbeef/brakemanJava
https://find-sec-bugs.github.io/
https://spotbugs.github.io/NodeJs
https://github.com/ajinabraham/nodejsscan
https://github.com/eslint/eslintPHP
https://github.com/phpstan/phpstan
https://github.com/vimeo/psalmReferences
https://github.com/analysis-tools-dev/static-analysisLast updated