All Categories → Software Quality → static-code-analysis

Top 145 static-code-analysis open source projects

Phpstan Phpunit
PHPUnit extensions and rules for PHPStan
Dg
[LLVM Static Slicer] Various program analyses, construction of dependence graphs and program slicing of LLVM bitcode.
Vue Eslint Parser
The ESLint custom parser for `.vue` files.
Revive
🔥 ~6x faster, stricter, configurable, extensible, and beautiful drop-in replacement for golint
Spotbugs
SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
Sputnik
Static code review for your Gerrit patchsets. Runs Checkstyle, PMD, FindBugs, Scalastyle, CodeNarc, JSLint for you!
Tombstone
Dead code detection with tombstones for PHP 🪦🧟
Infer
A static analyzer for Java, C, C++, and Objective-C
Phpstan Deprecation Rules
PHPStan rules for detecting usage of deprecated classes, methods, properties, constants and traits.
Walkmod Core
walkmod: an open source tool to fix coding style issues
Perl Critic
The leading static analyzer for Perl. Configurable, extensible, powerful.
Wpbullet
A static code analysis for WordPress (and PHP)
Bento
[DEPRECATED] Find Python web-app bugs delightfully fast, without changing your workflow. 🍱
Rubocop
A Ruby static code analyzer and formatter, based on the community Ruby style guide.
I18n Tasks
Manage translation and localization with static analysis, for Ruby i18n
Owasp Orizon
Owasp Orizon is a source code static analyzer tool designed to spot security issues in Java applications.
Fb Contrib
a FindBugs/SpotBugs plugin for doing static code analysis for java code bases
Feram
Feram finds & fixes bugs in your commits
Nsdepcop
NsDepCop is a static code analysis tool that helps to enforce namespace dependency rules in C# projects. No more unplanned or unnoticed dependencies in your system.
Phpstan
PHP Static Analysis Tool - discover bugs in your code without running it!
Drek
A static-code-analysis tool for performing security-focused code reviews. It enables an auditor to swiftly map the attack-surface of a large application, with an emphasis on identifying development anti-patterns and footguns.
Npgsql.fsharp.analyzer
F# analyzer that provides embedded SQL syntax analysis, type-checking for parameters and result sets and nullable column detection when writing queries using Npgsql.FSharp.
Unimport
A linter, formatter for finding and removing unused import statements.
Violations Lib
Java library for parsing report files from static code analysis.
Rubberduck
Every programmer needs a rubberduck. COM add-in for the VBA & VB6 IDE (VBE).
Sourcecodesniffer
The Source Code Sniffer is a poor man’s static code analysis tool (SCA) that leverages regular expressions. Designed to highlight high risk functions (Injection, LFI/RFI, file uploads etc) across multiple languages (ASP, Java, CSharp, PHP, Perl, Python, JavaScript, HTML etc) in a highly configurable manner.
Static Analysis
⚙️ A curated list of static analysis (SAST) tools for all programming languages, config files, build tools, and more.
Hydiomatic
The Hy Transformer
Kube Score
Kubernetes object analysis with recommendations for improved reliability and security
Flake8
The official GitHub mirror of https://gitlab.com/pycqa/flake8
Tscancode
A static code analyzer for C++, C#, Lua
Devreplay
A linter that replay your developing style
Rubocop Packaging
A RuboCop extension focused on enforcing upstream best practices and coding conventions.
Cfmt
cfmt is a tool to wrap Go comments over a certain length to a new line.
Eslint Plugin
ESLint configurations and additional rules for me
Sonar Java
☕️ SonarSource Static Analyzer for Java Code Quality and Security
Checkstyle
Checkstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.
1-60 of 145 static-code-analysis projects