Skip to content
#

sarif

Here are 1,075 public repositories matching this topic...

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

  • Updated Aug 28, 2026
  • TypeScript
sbom-tools

Semantic SBOM/CBOM/AI-BOM diff, quality scoring, and compliance validation for CycloneDX/SPDX — component, license, and vulnerability change analysis, cryptographic inventory grading, PQC readiness (CNSA 2.0, NIST IR 8547), and regulatory gates for NTIA, FDA, EU CRA, BSI TR-03183, EUCC, SSDF, EO 14028, and the EU AI Act.

  • Updated Aug 29, 2026
  • Rust

Modern offline-first Application Security Intelligence Platform for Android, iOS, Flutter and React Native with attack-chain analysis, explainable findings, source exploration, AI-assisted investigation and professional reporting.

  • Updated Jul 21, 2026
  • Python

GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.

  • Updated Aug 30, 2026
  • TypeScript

Independent security verification for code written by humans and AI agents. Scan, repair, then prove it — Dvalin runs your project's own checks and issues a Verified Fix Record anyone can re-derive offline. Local-first, policy-bound, MIT.

  • Updated Aug 26, 2026
  • TypeScript

Improve this page

Add a description, image, and links to the sarif topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the sarif topic, visit your repo's landing page and select "manage topics."

Learn more