ShellCheck, a static analysis tool for shell scripts
-
Updated
Aug 18, 2021 - Haskell
{{ message }}
ShellCheck, a static analysis tool for shell scripts
A static analyzer for Java, C, C++, and Objective-C
A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)
A tool to automatically fix PHP Coding Standards issues
PHP Static Analysis Tool - discover bugs in your code without running it!
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
A curated list of static analysis (SAST) tools for all programming languages, config files, build tools, and more.
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards.
Vulnerability Static Analysis for Containers
Defund the Police.
A static analysis security vulnerability scanner for Ruby on Rails applications
Checkstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.
Useful CMake Examples
Dockerfile linter, validate inline bash, written in Haskell
Performant type-checking for python.
Golang security checker
I can’t use //nosemgrep because my autoformatter moves it to its own line, where it is ignored by semgrep.
To reproduce: https://semgrep.dev/s/340G
Desired behavior: I'd like all of the examples in the above snippet to be suppressed by the nosemgrep annotation, including:
nosemgrep is on its own line before the target linenosemgrep is inside the matched range.This
Phan is a static analyzer for PHP. Phan prefers to avoid false-positives and attempts to prove incorrectness rather than correctness.
Awesome autocompletion, static analysis and refactoring library for python
A static analysis tool for finding errors in PHP applications
Many repositories need to fix, so please help if you like.
If you could help, it would be helpful if you could comment before starting the work not to overlapping.
Run exit command after lint.
echo '::group:: Running golangci-lint with reviewdog 🐶 ...'
goStaticcheck - The advanced Go linter
A static code analysis tool for the Elixir language with a focus on code consistency and teaching.
A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.
static analysis of C/C++ code
Add a description, image, and links to the static-analysis topic page so that developers can more easily learn about it.
To associate your repository with the static-analysis topic, visit your repo's landing page and select "manage topics."
App Attest allows your app to attach a hardware-backed assertion as a part of the request. Your server can use assertion to verify the request came from your genuine app, on a genuine Apple device.
https://developer.apple.com/videos/play/wwdc2021/10244/
https://developer.apple.com/documentation/devicecheck/assessing_fraud_risk
https://developer.apple.com/documentation/bundleresources/entit