A curated directory of static analysis (SAST) tools and linters for all programming languages, config files, and build tools.
Static Analysis is a curated directory of static analysis tools (SAST) and linters for all programming languages, configuration files, build tools, and more. It helps developers find tools that improve code quality by detecting bugs, enforcing style guides, and identifying security vulnerabilities without executing the code. The project also powers a website with additional features like rankings and user comments.
Developers, engineering teams, and security engineers looking to integrate static analysis into their workflow across diverse technology stacks.
It provides a single, comprehensive, and community-maintained reference for discovering static analysis tools, saving time compared to scattered searches, and emphasizes open-source and quality-focused tools.
⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Covers over 50 programming languages and technologies, making it a go-to resource for diverse tech stacks, as highlighted in the key features.
Focuses on tools that improve code quality like linters and formatters, not just any static analysis tools, ensuring relevance for developers, per the project's philosophy.
Clearly marks proprietary tools and highlights open-source alternatives, encouraging the use of free software, which is a core emphasis in the README.
Accepts pull requests and has sister projects, ensuring continuous improvement through community contributions, as stated in the repository.
While it lists hundreds of tools, it lacks ratings, benchmarks, or side-by-side comparisons, leaving users to evaluate options on their own without guidance.
The project focuses on listing tools but offers little practical advice on setup, configuration, or CI/CD integration, which can hinder implementation.
Some tools are marked with warnings for not being updated in over a year, indicating potential outdated entries despite community efforts, as shown by the :warning: symbol.