Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Static analysis
Inspect source code for bugs, code smells and security issues, and track the findings across branches and pull requests.
比較表
| ツール | スター | ライセンス | 利用条件 | セルフホスト | 言語 | 最新リリース | 最終プッシュ |
|---|---|---|---|---|---|---|---|
| Semgrep | 17k | LGPL-2.1 | オープンソース | 可 | C | v1.179.0 | 2026-10-06 |
| SonarQube Community Build | 11k | LGPL-3.0 | オープンソース | 可 | Java | 26.9.0.129388 | 2026-10-05 |
| gosec | 9k | Apache-2.0 | オープンソース | 可 | Go | v2.29.0 | 2026-10-05 |
| Bandit | 8.3k | Apache-2.0 | オープンソース | 可 | Python | 1.9.4 | 2026-10-06 |
| Brakeman | 7.3k | Other | ソースアベイラブル | 可 | Ruby | v8.1.0 | 2026-10-05 |
| Cppcheck | 6.8k | GPL-3.0 | オープンソース | 可 | C++ | 2.22.0 | 2026-10-06 |
| Opengrep | 3.1k | LGPL-2.1 | オープンソース | 可 | OCaml | v1.30.0 | 2026-10-06 |
| Bearer | 2.8k | Other | ソースアベイラブル | 可 | Go | v2.1.1 | 2026-10-05 |
| CodeChecker | 2.6k | Apache-2.0 | オープンソース | 可 | Python | v6.29.1 | 2026-10-03 |
| MegaLinter | 2.6k | AGPL-3.0 | オープンソース | 可 | Dockerfile | v10.1.0 | 2026-10-06 |
10件のツール
Continuous Inspection
- 言語
- Java
- ライセンス
- LGPL-3.0
- スター
- 11k
- 最新リリース
- 26.9.0.129388
- 最終プッシュ
- 2026-10-05
Go security checker
- 言語
- Go
- ライセンス
- Apache-2.0
- スター
- 9k
- 最新リリース
- v2.29.0
- 最終プッシュ
- 2026-10-05
Bandit is a tool designed to find common security issues in Python code.
- 言語
- Python
- ライセンス
- Apache-2.0
- スター
- 8.3k
- 最新リリース
- 1.9.4
- 最終プッシュ
- 2026-10-06
A static analysis security vulnerability scanner for Ruby on Rails applications
static analysis of C/C++ code
🔎 Static code analysis engine to find security issues in code.
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
CodeChecker is an analyzer tooling, defect database and viewer extension for static and dynamic analyzer tools.
- 言語
- Python
- ライセンス
- Apache-2.0
- スター
- 2.6k
- 最新リリース
- v6.29.1
- 最終プッシュ
- 2026-10-03
🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository sources with a GitHub Action, other CI tools or locally.