Skip to content
#

sarif

Here are 837 public repositories matching this topic...

sbom-tools

Semantic SBOM/CBOM/AI-BOM diff, quality scoring, and compliance validation for CycloneDX/SPDX — component, license, and vulnerability change analysis, cryptographic inventory grading, PQC readiness (CNSA 2.0, NIST IR 8547), and regulatory gates for NTIA, FDA, EU CRA, BSI TR-03183, EUCC, SSDF, EO 14028, and the EU AI Act.

  • Updated Aug 1, 2026
  • Rust

Modern offline-first Application Security Intelligence Platform for Android, iOS, Flutter and React Native with attack-chain analysis, explainable findings, source exploration, AI-assisted investigation and professional reporting.

  • Updated Jul 21, 2026
  • Python

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

  • Updated Aug 5, 2026
  • TypeScript
agents-shipgate

The deterministic merge gate for AI-generated agent capability changes — a local-first, static Tool-Use Readiness review for MCP, OpenAPI, and SDK tool surfaces. Open-source CLI + GitHub Action.

  • Updated Aug 5, 2026
  • Python

Improve this page

Add a description, image, and links to the sarif topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the sarif topic, visit your repo's landing page and select "manage topics."

Learn more