0.1.41717.5 MB
Apache-2.0
strict
core24
Security scanner for Ansible: malicious code, RCE, secrets, supply chain
Static SAST for Ansible content: playbooks, roles, collections, task files, vars, and inventories.
Detects malicious code, remote code execution, command and template injection, hardcoded credentials, supply-chain risk, unauthorized cloud access, lateral movement, and reverse shells. Every finding ships with remediation guidance and maps to CWE, OWASP Top 10, OWASP ASVS, MITRE ATT&CK, NIST, and CIS.
Over 1,000 rules across 30+ detection categories, auto-discovered from YAML pattern plugins. Outputs SARIF, CycloneDX SBOM, GitLab SAST, JUnit, JSON, HTML, and Markdown.
CI-native and autofix-capable. Releases are Sigstore-signed with SLSA Build Level 3 provenance.
Detects malicious code, remote code execution, command and template injection, hardcoded credentials, supply-chain risk, unauthorized cloud access, lateral movement, and reverse shells. Every finding ships with remediation guidance and maps to CWE, OWASP Top 10, OWASP ASVS, MITRE ATT&CK, NIST, and CIS.
Over 1,000 rules across 30+ detection categories, auto-discovered from YAML pattern plugins. Outputs SARIF, CycloneDX SBOM, GitLab SAST, JUnit, JSON, HTML, and Markdown.
CI-native and autofix-capable. Releases are Sigstore-signed with SLSA Build Level 3 provenance.
Update History
0.1.40 (6) → 0.1.41 (7)25 Aug 2026, 13:45 UTC
0.1.39 (5) → 0.1.40 (6)25 Aug 2026, 02:30 UTC
0.1.38 (4) → 0.1.39 (5)3 Aug 2026, 21:45 UTC
0.1.37 (3) → 0.1.38 (4)1 Aug 2026, 18:30 UTC
0.1.36 (2) → 0.1.37 (3)20 Jul 2026, 20:45 UTC
0.1.36 (2)16 Jul 2026, 17:00 UTC
16 Jul 2026, 16:41 UTC
25 Aug 2026, 13:28 UTC
16 Jul 2026, 17:00 UTC