Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Static Analysis

Static Analysis

663 projects

Showing 36 of 663 projects

clair
clairGo

Static vulnerability analysis for container images (OCI/Docker) via an API that indexes and matches against known security flaws.

#container-security#vulnerabilities#oci
Stars11.0k
Forks1.2k
Last commit5 days ago
sonarqube
sonarqubeJava

An open-source platform for continuous code quality inspection and security analysis across 30+ programming languages.

#devops#software-metrics#security-scanning
Stars10.6k
Forks2.2k
Last commit2 days ago
Rector
RectorPHP

Automated PHP code upgrades and refactoring tool that instantly updates PHP versions and major frameworks.

#rector#framework-migration#dev-tools
Stars10.3k
Forks741
Last commit3 days ago
codeql
codeqlCodeQL

Standard libraries and queries for CodeQL, powering GitHub Advanced Security and static application security testing.

#codeql#vulnerability-detection#security
Stars9.7k
Forks2.0k
Last commit1 day ago
android-security-awesome
android-security-awesomeMakefile

A comprehensive, curated collection of tools, research, and resources for Android application security analysis and penetration testing.

#vulnerability-assessment#mobile-security#android
Stars9.5k
Forks1.6k
Last commit
Android Security
Android SecurityMakefile

A comprehensive, curated collection of tools, research, and resources for Android application security analysis and reverse engineering.

#vulnerability-assessment#mobile-security#android
Stars9.5k
Forks1.6k
Last commit
Reviewdog
ReviewdogGo

Automated code review tool that integrates with any linter and posts results as comments on pull requests.

#developer-tools#lint#linter
Stars9.3k
Forks489
Last commit1 day ago
React
ReactJavaScript

A comprehensive ESLint plugin providing React-specific linting rules to enforce best practices and catch common errors.

#developer-tools#lint#ecmascript
Stars9.3k
Forks2.7k
Last commit26 days ago
Syft
SyftGo

A CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems.

#sbom#container-security#cyclonedx
Stars9.1k
Forks869
Last commit1 day ago
syft
syftGo

A CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems.

#sbom#container-security#cyclonedx
Stars9.1k
Forks869
Last commit1 day ago
JSHint
JSHintJavaScript

A community-driven static code analysis tool that detects errors and potential problems in JavaScript code.

#developer-tools#open-source#code-quality
Stars9.1k
Forks1.6k
Last commit1 year ago
Checkstyle
CheckstyleJava

A development tool that helps programmers write Java code adhering to configurable coding standards and best practices.

#hacktoberfest#development-tool#coding-standards
Stars8.9k
Forks4.1k
Last commit1 day ago
Golang Security Checker
Golang Security CheckerGo

A static analysis tool that scans Go source code for security vulnerabilities by analyzing the AST and SSA representations.

#ast-analysis#taint-analysis#security-automation
Stars8.9k
Forks698
Last commit1 day ago
sh
shGo

A Go library and toolset for parsing, formatting, and interpreting POSIX Shell, Bash, and Zsh scripts.

#developer-tools#code-formatter#interpreter
Stars8.8k
Forks410
Last commit6 days ago
checkov
checkovPython

A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.

#aws-security#azure#kubernetes
Stars8.8k
Forks1.3k
Last commit1 day ago
Checkov
CheckovPython

A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.

#aws-security#azure#static-code-analysis
Stars8.8k
Forks1.3k
Last commit1 day ago
Gixy - Nginx configuration static analyzer
Gixy - Nginx configuration static analyzerPython

A static analysis tool for detecting security misconfigurations and flaws in Nginx configuration files.

#devops#web-server#vulnerability-detection
Stars8.6k
Forks451
Last commit1 year ago
retdec
retdecC++

A retargetable machine-code decompiler based on LLVM, supporting multiple architectures and file formats.

#disassembler#malware-analysis#binary-analysis
Stars8.5k
Forks992
Last commit13 days ago
scc
sccGo

A very fast and accurate code counter with complexity calculations, COCOMO/LOCOMO estimates, and unique line metrics written in pure Go.

#developer-tools#statistics#code-metrics
Stars8.5k
Forks319
Last commit6 days ago
XO
XOTypeScript

An opinionated, zero-config ESLint wrapper for JavaScript/TypeScript with great defaults and automatic fixes.

#developer-tools#zero-config#linter
Stars8.0k
Forks305
Last commit2 months ago
xo
xoTypeScript

An opinionated, zero-config ESLint wrapper for JavaScript and TypeScript with great defaults and automatic fixes.

#eslint-wrapper#developer-tools#automated-fixes
Stars8.0k
Forks305
Last commit2 months ago
arkregex
arkregexTypeScript

A TypeScript validator that maintains 1:1 type-safety from editor to runtime with optimized performance.

#parsing#developer-tools#runtime-typechecking
Stars7.8k
Forks145
Last commit6 days ago
ClassyShark
ClassySharkJava

A standalone binary inspection tool for Android developers to browse executables and analyze bytecode.

#dex#bytecode-viewer#jar
Stars7.6k
Forks872
Last commit3 years ago
brakeman
brakemanRuby

A static analysis security vulnerability scanner for Ruby on Rails applications.

#vulnerabilities#rails#vulnerability-detection
Stars7.2k
Forks770
Last commit4 days ago
error-prone
error-proneJava

A static analysis tool for Java that catches common programming mistakes at compile-time.

#developer-tools#build-tools#bug-detection
Stars7.2k
Forks793
Last commit3 days ago
pyre-check
pyre-checkOCaml

A performant, incremental type checker for Python with integrated security analysis via Pysa.

#type-check#developer-tools#taint-analysis
Stars7.2k
Forks452
Last commit1 day ago
Tfsec
TfsecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#rego#google-cloud-platform#multi-cloud
Stars7.0k
Forks554
Last commit2 months ago
tfsec
tfsecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#google-cloud-platform#azure#terraform-security
Stars7.0k
Forks554
Last commit2 months ago
tfsec
tfsecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#google-cloud-platform#multi-cloud#azure
Stars7.0k
Forks554
Last commit2 months ago
TFSec
TFSecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#google-cloud-platform#multi-cloud#azure
Stars7.0k
Forks554
Last commit2 months ago
Detekt
DetektKotlin

A static code analysis tool for Kotlin that identifies code smells and enforces coding standards.

#hacktoberfest#code-smells#developer-tools
Stars7.0k
Forks837
Last commit1 day ago
staticcheck
staticcheckGo

A state-of-the-art static analysis linter for Go that finds bugs, performance issues, and enforces style rules.

#developer-tools#linter#bug-detection
Stars6.8k
Forks410
Last commit1 day ago
go-tools
go-toolsGo

A state-of-the-art static analysis linter for Go that finds bugs, performance issues, and enforces style rules.

#developer-tools#linter#bug-detection
Stars6.8k
Forks410
Last commit1 day ago
cxx
cxxRust

A safe, zero-overhead FFI bridge for calling C++ code from Rust and Rust code from C++.

#safe-ffi#ffi#c-plus-plus
Stars6.7k
Forks408
Last commit9 days ago
cppcheck
cppcheckC++

A static analysis tool for detecting bugs and undefined behavior in C and C++ code.

#undefined-behavior#c-cpp#bug-detection
Stars6.6k
Forks1.6k
Last commit3 days ago
Pyrefly
PyreflyRust

A fast type checker and language server for Python with powerful IDE features like code navigation and completion.

#type-check#incremental-checking#language-server
Stars6.6k
Forks389
Last commit1 day ago
PreviousPage 2 of 19

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
14 days ago
14 days ago
Next
#Code Quality343
#Developer Tools247
#Linting142
#Linter116
#Ci Cd98
#Javascript90
#Eslint72
#Eslint Plugin67
#Go66
#Python65
#Security65
#Php62