Code analysis
SAST, code review, and vulnerability scanning
SAST and code analysis 97
- Ghost Security CAST Reportreports.ghostsecurity.com
- DryRun - Beyond Pattern Matchingdryrun.security
- Semgrep - Finding Vulns with Claude and Codexsemgrep.dev
- How to Scan for Vulnerabilities with GitHub Security Lab's Open Source AI-Powered Frameworkgithub.blog
- 5 Types of Reachability Analysis and Which is Right for Youendorlabs.com
- A Comparative Study of Vulnerability Reporting by Software Composition Analysis Toolsarxiv.org
- A Deeper Look at Modern SAST Tools - CodeQL vs Semgrepgoingbeyondgrep.com
- AGHAST - AI Guided Hybrid Application Static Testinggithub.com
- AI Deep SAST - LLM-powered deep static analysis combining Semgrep and frontier modelsgithub.com
- Announcing OpenGrep - and the importance of a commoditized SASTpulse.latio.tech
- Announcing the Trail of Bits Testing Handbookblog.trailofbits.com
- APKHunt - OWASP MASVS static analyzer for Android appsgithub.com
- AppSec guides, not gates: Introducing secure guardrails with Semgrepsemgrep.dev
- AppThreat/atom - intermediate representation for supply-chain, vulnerability and reachability analysisgithub.com
- AstGrep MCP - structural code search as an MCP tool for agent code reviewkensei-builds-hub.vercel.app
- audit - 8-stage vulnerability-discovery agent built on the Claude Agent SDKgithub.com
- Awesome LLMs for Vulnerability Detectiongithub.com
- Bridgecrew Azure Pipelines security policiesdocs.bridgecrew.io
- Claude Security public beta - AI codebase vulnerability scanning with validated findings and patchesx.com
- CodeCrucible: A blueprint for LLM-driven SASTengineering.block.xyz
- CodeQL threat model settings for Java make code scanning more adaptable to your codebasegithub.blog
- CodeQL updates from the first half of 2023github.blog
- CodeSheriff.NET - Roslyn-based security scanner for ASP.NET Coregithub.com
- Datadog acquires Codigadatadoghq.com
- Did Semgrep Just Get A Lot More Interestingfly.io
- DryRun Security vs. Semgrep, SonarQube, CodeQL and Snyk - C# Security Analysis Showdowndryrun.security
- Finding Vulnerabilities with MRVA CodeQLmaikypedia.gitlab.io
- Fixing security vulnerabilities with AI - GitHub code scanning autofixgithub.blog
- Found means fixed: Secure code more than three times faster with Copilot Autofixgithub.blog
- GitHub code scanning: customize CodeQL default setup at scale with a config filegithub.blog
- globstar - open-source static analysis toolkitgithub.com
- How AI Code Scanning Breaks SAST's Limits - Corgea as an Examplemedium.com
- How Semgrep Multimodal Finds the IDORs Other Tools Miss - benchmark vs Mythossemgrep.dev
- How we are self-hosting code scanning at Reddit - r/RedditEngreddit.com
- ICYMI: CodeQL enhancementsgithub.blog
- Important updates to Semgrep OSS - Semgrep Community Edition and LGPL licensingsemgrep.dev
- Introducing AGHAST: AI-Guided Hybrid Application Static Testingbouncesecurity.com
- Introducing Antares: Highly Efficient Open Weight AI Models for Vulnerability Localizationblogs.cisco.com
- Introducing deepsec: The security harness for finding vulnerabilities in your codebasevercel.com
- Java projects no longer require a build when using code scanning via default setupgithub.blog
- Joern - the Bug Hunter's Workbenchjoern.io
- jswzl - JavaScript static analysis for penetration testers and bug huntersjswzl.io
- Kyle Kelly on Semgrep removing open-source metadata fields and the rise of Opengreplinkedin.com
- LAST - Latio Application Security Tester, AI code scanning CLIgithub.com
- Learning CodeQLgoingbeyondgrep.com
- LLM-Driven SAST-Genius: A Hybrid Static Analysis Framework for Comprehensive and Actionable Securityarxiv.org
- llm-sast-scanner - SAST skill for AI coding agentsgithub.com
- Martin Torp on the Semgrep and Opengrep fork situationlinkedin.com
- MegaLinter - multi-language linter with security scanning for CIgithub.com
- Microsoft Azure Security expands variant hunting capacity at a cloud tempoazure.microsoft.com
- Modern Static Analysis: how the best tools empower creativitydevd.me
- Multi-repository variant analysis: a powerful new way to perform security research across GitHubgithub.blog
- nano-analyzer - minimal LLM-powered zero-day vulnerability scanner by AISLEgithub.com
- octoscan - static vulnerability scanner for GitHub Actions workflowsgithub.com
- open-kritt - self-hosted AI vulnerability research platform orchestrating agentsgithub.com
- openai/codex-security - Codex Security CLI and SDK for finding, validating and fixing vulnerabilitiesgithub.com
- OpenCodeReview - Alibaba's hybrid deterministic plus LLM agent code review toolgithub.com
- Opengrep - open source SAST engine, fork of Semgrepgithub.com
- Opengrep - open-source code security engine, fork of Semgrep CEopengrep.dev
- opentaint - open source taint analysis engine built for AI agents, alternative to Semgrep Pro and CodeQLgithub.com
- OpenVuln - AI-powered open source vulnerability analysishuggingface.co
- OWASP Noir - attack surface detector that finds endpoints via static analysisowasp-noir.github.io
- OWASP Noir - hybrid static and AI-driven endpoint and attack surface analyzergithub.com
- Peter Winter-Smith announces wSAST, a code analyser for application security consultantsx.com
- railguard-skill - Netflix Skunkworks experiment in LLM-driven static security analysisgithub.com
- RepoAudit - autonomous LLM agent for repository-level code auditinggithub.com
- route-detect - find authentication and authorization bugs in web application routesgithub.com
- Rule Writing for CodeQL and Semgrep - Spaceraccoonspaceraccoon.dev
- SAST Code Security Showdown, ChatGPT vs. Snyk Code - Latioyoutube.com
- SAST Code Security Showdown, ChatGPT vs. Snyk Code - video summarysummarize.tech
- sec-af - AI-native code security auditorgithub.com
- Securing CodeQL queries with Semgrepsemgrep.dev
- Semgrep for Terraform Securityramimac.me
- Semgrep Guardiandocs.semgrep.dev
- semgrep-rules - 0xdea's Semgrep rules for vulnerability researchgithub.com
- semgrep-rules-android-security - Semgrep rules derived from OWASP MASTG for Android appsgithub.com
- semgrep-server-rules - Semgrep rule servergithub.com
- Sighthound - open-source Rust static vulnerability scanner with taint analysis from Corgeax.com
- Sighthound - tree-sitter based static vulnerability scannergithub.com
- Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Processarxiv.org
- Swival security-audits - reports from automated AI security audits of open source projectsgithub.com
- tfrev - AI-powered Terraform plan reviewer catching security risks before applygithub.com
- TheAuditor - queryable code intelligence and polyglot SAST platform for AI agentsgithub.com
- Trailmark - Build and query a graph database of source code for security analysisgithub.com
- Trailmark turns code into graphsblog.trailofbits.com
- Varun Badhwar on the launch of Opengrep, an open-source SAST fork of Semgreplinkedin.com
- Velonus - AI-native security copilot that scans Python for secrets, vulns and dependency CVEsgithub.com
- Visa Vulnerability Agentic Harness - agentic SAST pipelinegithub.com
- vscode-security-notes - VSCode extension for security code review notes and SAST findingsgithub.com
- VulnHunter - Capital One's agentic AI attacker-first source code security toolgithub.com
- VulnHunter - Capital One's open-source agentic AI code security toolcapitalone.com
- vulnhuntr - zero shot vulnerability discovery using LLMs and static code analysisgithub.com
- We Audited the Same Codebase with Claude Opus 4.8 and MiniMax M3blog.kilo.ai
- We Put GPT-4 in Semgrep to Point Out False Positives and Fix Codesemgrep.dev
- Whitepaper: BLAST, the AI-powered SAST scanner - Corgeacorgea.com
- wSAST - static analysis security testing framework for code reviewwsast.co.uk
- Xpsd - LLM-driven reachability triage for vulnerability scan findingsgithub.com
Platforms 22
- AISLEaisle.com
- DepthFirstdepthfirst.com
- ZeroPathzeropath.com
- Announcing general availability of GitHub Advanced Security for Azure DevOpsgithub.blog
- Application security orchestration with GitHub Advanced Securitygithub.blog
- CodeRabbit - AI code review platformcoderabbit.ai
- Corgea - AI application security platform that finds, triages and fixes vulnerabilitiescorgea.com
- Cycode - GitHub Advanced Security alternative for software supply chain securitycycode.com
- Cycode Acquires Bearer to Deliver AI-Powered SAST and API Discoverycycode.com
- DryRun Security Q1 2026: Everything We Shipped and Why It Mattersdryrun.security
- GitHub code scanning adds a mitigated alert dismissal reasongithub.blog
- Introducing the Mend AppSec Platformmend.io
- Launch HN: Corgea - Auto fix vulnerable codenews.ycombinator.com
- Legit Security Launches VibeGuard 2.0 - securing AI-generated codelegitsecurity.com
- Pi - agentic product security platformpi.security
- Pixee - Agentic AppSec platform to triage and fix vulnerabilitiespixee.ai
- SecHub - central API to orchestrate security scanning tools, archivedgithub.com
- Semgrep Managed Scanssemgrep.dev
- Snyk Studio - Secure at Inception code scanning for AI coding assistants via the Snyk MCP Serversnyk.io
- The Firewall - open source shift-left AppSec platform for secrets scanning and SCAthefirewall.org
- winfunc - AI security agents that find, triage, and patch codebase vulnerabilitiesasterisk.so
- ZeroPath - AI code security platform changelogzeropath.com
Security tools and analysis 67
- New in Corgea: Container Scanning + IaC Scanning - Corgeacorgea.com
- How to Kill the Code Reviewlatent.space
- New Feature: Corgea Agent - Corgeacorgea.com
- New Product: Code Quality - Corgeacorgea.com
- Enable external threat detection and protection for Copilot Studiolearn.microsoft.com
- About GitHub Copilot coding agent - GitHub Enterprise Cloud Docsdocs.github.com
- Apiiro AI-SAST: Static Scanning Reimagined – From Code to Runtimeapiiro.com
- Vulnhalla: Picking the true vulnerabilities from the CodeQL haystackcyberark.com
- IDEsaster: A Novel Vulnerability Class in AI IDEsmaccarita.com
- WildCode: An Empirical Analysis of Code Generated by ChatGPTarxiv.org
- New public preview features in Copilot code review: AI reviews thatgithub.blog
- Introducing Corgea Dependency Scanning - Corgeacorgea.com
- we now do [#curlmastodon.social
- AI and Secure Code Learning: An Empirical Analysis of 420 AI-Generasecdim.com
- Constructing a Trustworthy Evaluation Methodology for Contextual Sedryrun.security
- AI Native LLM Security: A comprehensive guide to leveraging OWASP Tamazon.com
- SAST Accuracy Reportdryrun.security
- SAIL Framework: A Practical Guide for AI Securitypillar.security
- Copy of OWASP LLM_GenAI Security Solutions Reference Guide Q2'25 3/docs.google.com
- Free AI code reviews for VS Code - Code Reviewscoderabbit.ai
- One Year of Using LLMs for Application Security: What We Learneddryrun.security
- Automate code reviews, patching agithub.com
- 10x your AppSec program with Semgrep Assistantsemgrep.dev
- Security Code Review With ChatGPTresearch.nccgroup.com
- Securing our codebase with autonomous agentscursor.com
- State of AI code qualityqodo.ai
- Notes: AI Copilot Code Quality · Technical Ramblingskracekumar.com
- 42Crunch API Security Testing plugin for Claude Codeclaude.com
- AISLE Discovers 38 CVEs in Healthcare Software Used by 100,000 Medical Providersaisle.com
- Attacking browser extensions - GitHub Security Labgithub.blog
- CLM-Forge - PowerShell WDAC script enforcement and Constrained Language Mode readiness toolkitgithub.com
- Daniel Stenberg on Joshua Rogers' AI-assisted bug findings in curl - 22 fixes landed alreadymastodon.social
- defending-code-reference-harness - Anthropic autonomous vulnerability discovery and patching harnessgithub.com
- diffalayze - LLM-assisted automated binary patch diffing and security analysisgithub.com
- Dohyun Lee on an LLM finding a Linux library vuln, writing a PoC and variant Firefox CVEsx.com
- FlowMate - BurpSuite extension for web application taint analysisgithub.com
- From finding to fixing: GitHub Advanced Security integrates Endor Labs SCAgithub.blog
- Gadi Evron on an LLM-based, language-agnostic vulnerability variant hunter presented at BlueHat ILx.com
- GhidrAssist - LLM-powered reverse engineering assistant for Ghidragithub.com
- GitHub security campaigns and assignable alerts for code scanning and secret scanninggithub.blog
- grep.app - code search across a million GitHub repositoriesgrep.app
- hermes-dec - decompiler and disassembler for React Native Hermes bytecodegithub.com
- How Aikido finds more vulnerabilities than Claude Security with Mythos at half the costaikido.dev
- Introducing AI-powered application security testing with GitHub Advanced Securitygithub.blog
- Is runtime SCA reachability a gimmick? A look at Oligo Security - Latioyoutube.com
- LVRP - local LLM-driven vulnerability research pipelinegithub.com
- MAD Bugs: All Your Reverse Engineering Tools Are Belong to US - AI-found RCEs in Ghidra, radare2, IDA, Binary Ninjablog.calif.io
- Master fuzzing with our new Testing Handbook chapter - Trail of Bitsblog.trailofbits.com
- Mav Levin on AI security agents finding and patching RCE CVE-2025-59304 in Swetrixx.com
- Mobb - AI-powered vulnerability remediationdocs.mobb.ai
- Monocle - LLM-backed natural language search over compiled binariesgithub.com
- Ocular - Kubernetes-native security scanning orchestration for software assetsgithub.com
- oss-fuzz-gen - LLM-powered fuzzing via OSS-Fuzzgithub.com
- OVRSE - Open Vulnerability Remediation Specification engine for AI-driven vulnerability fixinggithub.com
- OWASP Noir - hunt every endpoint in your code, expose shadow APIs, map the attack surfacegithub.com
- PatchDiff-AI - LLM CVE binary-diff root-cause analysisgithub.com
- Rate My OpenAPI - find API quality and security issues via OpenAPI specgithub.com
- Review every MR for $0.25 - GitLab Duo Code Reviewduo-review-bench-6f7260.gitlab.io
- Schemathesis - property-based API testing and fuzzing for OpenAPI and GraphQLschemathesis.io
- Securing your Codebase - learning DevSecOps and a security-first approach for Feluda, part 1tattle.co.in
- Slice: SAST + LLM Interprocedural Context Extractornoperator.dev
- Specula - agentic bug finding in system code using TLA+github.com
- The Cheapest Token Is The One You Never Spendapiiro.com
- The Diminishing Returns of DAST - Boring AppSec Edition 18boringappsec.substack.com
- trace37 on tuning Claude Code skills to autonomously hunt bugs with taint tracingx.com
- Trail of Bits open-sources Trailmark to give Claude call graphs of source code for security analysisx.com
- watchtower - Dependabot vulnerability SLA dashboard and merge gategithub.com