{"repo":"seqra/opentaint","free":true,"listed":false,"github":"https://github.com/seqra/opentaint","clone":"git clone https://github.com/seqra/opentaint.git","description":"The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.","language":"Kotlin","stars":129,"topics":["java","kotlin","sast","security","security-tools","spring","static-analysis","vulnerabilities","vulnerability-detection","vulnerability-scanners"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"The open source taint analysis engine for the AI era Formal taint analysis for application security — finds what AST-pattern matchers miss, lets LLM agents enact rules from vulnerabilities, scales where neither can alone. English 简体中文 繁體中文 한국어 Deutsch Español Français Italiano Dansk 日本語 Polski Русский Bosanski العربية Norsk Svenska Português (Brasil) ไทย Türkçe Українська বাংলা हिन्दी Ελληνικά Tiếng Việt Bahasa Indonesia Supported technologies and integrations &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; The most thorough taint analysis engine for Spring apps Roadmap &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; More screenshots --- Why OpenTaint? OpenTaint is an open-source alternative to Semgrep Pro and CodeQL — a formal inter-procedural taint engine you can customize and self-host, built so AI agents drive your security analysis without burning tokens on every scan. AI generates production code faster than security teams can keep up with, and the two kinds of tooling built to catch what it gets wrong each force a bad trade-off: - AST-pattern matchers (Semgrep OSS, ast-grep, linters) are free and fast, but they match syntax, not data flow — untrusted input that crosses a function boundary or a persistence layer slips right past. The deeper, inter-procedural analysis that does catch it has long been locked inside proprietary tools. - LLM security agents find what patt","default_branch":null,"files":null,"tree":[],"storefront":"/r/seqra","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/seqra/opentaint/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}