static-analysis
find-sec-bugs
Our great sponsors
static-analysis | find-sec-bugs | |
---|---|---|
15 | 8 | |
12,811 | 2,197 | |
1.4% | 0.9% | |
9.4 | 6.1 | |
2 days ago | about 2 months ago | |
Rust | Java | |
MIT License | GNU Lesser General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
static-analysis
-
Static Analysis Tools for C
Readers should also peruse the 'Multiple languages' section, many of the big names, Coverity, Klocwork et al. are listed there.
see https://github.com/analysis-tools-dev/static-analysis#multip...
- Static-analysis – A curated list of static analysis (SAST) tools and linters
- Are you in favor of small functions/clean code or opposed to it?
-
Looking for feedback on our new website for Code Analysis Tools
this is Matthias from https://analysis-tools.dev.
-
Beating a dead horse?
Not an area I've had to deal with much unfortunately. Here is also a curated list of SAST tools grouped by technology. It can take quite some time to properly vet tools like this, but you might find something valuable in there.
- Checked C
-
From Novice to contributor to Linux Kernel and/or other Low-Level projects
You can for example rely on static analyzers and scan the repositories (just please take care of making sure that any fix you make actually makes sense, sometimes people will just make whatever causes the reports to go away without understanding them). This site lists a bunch of them for different languages -> https://analysis-tools.dev/
-
What's the best free security scan tool for C/C++ files?
There's a bunch on https://github.com/analysis-tools-dev/static-analysis
-
Does anyone know of any tool for calculating the cyclomatic complexity of pascal-based source code?
https://github.com/analysis-tools-dev/static-analysis - general list of SAST
find-sec-bugs
- Find Security Bugs
-
What are some useful static analyzers for Java?
SpotBugs have a lot of extensions such as https://find-sec-bugs.github.io/ https://github.com/KengoTODA/findbugs-slf4j and more, I recommend adding them as well
-
Looking for a Static Code Analysis tool for Scala Code
If you don’t have checkmarx/Vera code money, have you looked at https://find-sec-bugs.github.io/? It can be used with a few things such as https://spotbugs.github.io/ and sonarQ
-
Enforcing Coding Best Practices using CI
SpotBugs with Find sec bugs for Java
-
Conducting SAST for Java Applications
How can the article fail to mention Find Security Bugs (find-sec-bugs) when talking about using SpotBugs (ex-FindBugs) for analyzing code for security issues?
-
Design an Effective Build Stage for Continuous Integration
Find Security Bugs uses a security database to detect almost 140 different vulnerability types in Java web applications.
-
ShellCheck: A static analysis tool for shell scripts
find-sec-bugs does that. It's used by, for example, SonarQube.
See hhttps://github.com/find-sec-bugs/find-sec-bugs/blob/master/f... and do a "CTRL-F" and search for "References".
What are some alternatives?
solana - Web-Scale Blockchain for fast, secure, scalable, decentralized apps and marketplaces.
Spotbugs - SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
awesome-rust - A curated list of Rust code and resources.
semgrep-rules - Semgrep rules registry
rust-blog - Educational blog posts for Rust beginners
snyk - Snyk CLI scans and monitors your projects for security vulnerabilities. [Moved to: https://github.com/snyk/cli]
awesome-linters - A community-driven list of awesome linters.
semgrep - Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Solana - Finds price floor for every single attribute in a given collection
infer - A static analyzer for Java, C, C++, and Objective-C
dynamic-analysis - ⚙️ A curated list of dynamic analysis tools and linters for all programming languages, binaries, and more.
soot - Soot - A Java optimization framework