{"repo":"Corgea/Sighthound","free":true,"listed":false,"github":"https://github.com/Corgea/Sighthound","clone":"git clone https://github.com/Corgea/Sighthound.git","description":"Corgea's rule-based SAST scanner","language":"Rust","stars":275,"topics":["appsec","csharp","go","golang","java","javascript","php","python","ruby","rust"],"license":"MIT","category":"security-tools","readme_excerpt":"Sighthound Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis. Want Sighthound without the setup? Sign up for Corgea, where Sighthound is built in alongside AI SAST, secrets, container, dependency, and IaC scanning—with false-positive reduction and automated fixes. What It Does - Scans source code for security issues using AST-aware rules. - Supports pattern mode and taint mode (source to sink tracking). - Handles multi-file projects and parallel execution. - Outputs findings as text, JSON, CSV, or SARIF. - Loads embedded rule packs by file extension, with optional file-based custom rules. Language Support Language Extensions Parser Bundled Rules --- --- --- --- Python .py , .pyw , .pyi , .pyx Yes Yes JavaScript .js , .mjs , .cjs , .jsx , .vue , .svelte Yes Yes TypeScript / TSX .ts , .tsx , .mts , .cts Yes Yes (JS rules) Java .java Yes Yes PHP .php , .phtml Yes Yes C# .cs , .csx Yes Yes Go .go Yes Yes Ruby .rb Yes Yes ObjectScript .cls , .mac , .inc , .int , .rtn Yes (class and routine grammars) Yes HTML .html , .htm , .twig , .ejs , .hbs , ... Yes Yes Django templates .html (Django syntax) Yes Yes (HTML rules) Not currently supported: Razor ( .cshtml ), C/C++ ( .c , .h ). Installation Prerequisites: - Rust 1.85+ - Git Build from source: Binary path: target/release/sighthound Linux-container-compatible release export: Or run ./build all platforms.sh . Agent skill Using Claude Code, Cursor, Codex, or another coding agent? Install the S","default_branch":null,"files":null,"tree":[],"storefront":"/r/Corgea","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Corgea/Sighthound/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}