Sign inSign up

dominators/sast

By dominators

•Updated 4 months ago

Free SAST + SCA + secrets container. Scan local code or a remote repo; reports to your host folder.

Image
0

524

dominators/sast repository overview

⁠Insomnia SAST

Free, all-in-one static application security testing in a single container - SAST + cross-file taint (16 languages), dependency CVEs (SCA), secrets with live key validation, IaC, CMS & web-shell/malware. No external tools, runs non-root, no telemetry.

⁠Quick start - scan local source, report saved to YOUR folder

docker run --rm -v "$PWD:/src" dominators/sast:latest /src -f html,json,sarif -o /src/reports --fail-on high

Because -v "$PWD:/src" mounts your current directory, the reports land in ./reports on your machine (HTML + JSON + SARIF) - not inside the container (which --rm discards). --fail-on high exits non-zero on high+ findings, so it gates CI.

# Windows PowerShell
docker run --rm -v "${PWD}:/src" dominators/sast:latest /src -f html,json,sarif -o /src/reports --fail-on high

⁠Scan a remote repository (no clone, no mount)

docker run --rm dominators/sast:latest https://github.com/owner/repo --fail-on high

⁠CI (GitHub Actions)

- run: docker run --rm -v "$PWD:/src" dominators/sast:latest /src -f sarif -o /src/out --fail-on high
- uses: github/codeql-action/upload-sarif@v3
  with: { sarif_file: out }

⁠Tags

  • latest, 1.8.2 - multi-arch (linux/amd64 + linux/arm64)

Also: pip install sast - npm i -g sastai - brew install vulnz/sast/sast - VS Code / JetBrains plugins - GitHub Action. Docs: https://insom.ai/en/sdlc⁠

Tag summary

Content type

Image

Digest

sha256:0d762e15f…

Size

77.7 MB

Last updated

4 months ago

docker pull dominators/sast