* [Dependency cruiser v18.2.0](https://github.com/sverweij/dependency-cruiser) – Validate and visualize project dependencies with customizable rules. * [Semgrep v1.175.0](https://github.com/semgrep/semgrep) – Fast static analysis tool that searches code for bugs and enforces coding standards. * [gosec v2.29.0](https://github.com/securego/gosec) – Inspects Go source code for security issues by scanning the AST and SSA representations. * [revive v1.16.0](https://github.com/mgechev/revive) – Fast and configurable linter for Go with support for custom rules and strict presets. * [Syft v1.51.0](https://github.com/anchore/syft) – CLI tool and library for generating Software Bill of Materials from container images and filesystems. * [Mobile Security Framework (MobSF) v4.5.2](https://github.com/MobSF/Mobile-Security-Framework-MobSF) – Automated framework for mobile application security testing, malware analysis, and privacy assessment. * [Rubydex v0.4.0](https://github.com/Shopify/rubydex) – High-performance static analysis toolkit for the Ruby language, providing a shared Ruby and Rust API for building tools like type checkers and linters. * [Brakeman v8.0.6](https://github.com/presidentbeef/brakeman) – Static analysis tool checking Ruby on Rails applications for security vulnerabilities. * [shadscan v0.12.0](https://github.com/TheOrcDev/shadscan) – Deterministic CLI audits for shadcn React apps, scoring UI fundamentals 0–100 with evidence-backed findings across accessibility, states, forms, and polish. * [CodeBoarding v0.13.1](https://github.com/CodeBoarding/CodeBoarding) – LLM-enhanced static-analysis tool that generates interactive, high-level diagrams of codebases to aid onboarding and comprehension. * [Staticcheck 2026.2.1](https://github.com/dominikh/go-tools) – Advanced linter for the Go programming language that detects bugs, performance issues, and enforces style rules. * [AST Metrics v0.42.1](https://github.com/ast-metrics/ast-metrics) – AST Metrics is a multi-language code quality analyzer that measures complexity, architecture, coupling, test quality, and bus factor, flagging only PR regressions deterministically. * [Qodana v2026.2.0](https://github.com/JetBrains/qodana-action) – Code quality monitoring tool that identifies and suggests fixes for bugs, security vulnerabilities, and code duplications. * [SonarJS 13.7.0.44407](https://github.com/SonarSource/SonarJS) – Static code analyzer for JavaScript, TypeScript, and CSS providing code quality, security rules, and metrics.