Free SAST + SCA + secrets container. Scan local code or a remote repo; reports to your host folder.
524
Free, all-in-one static application security testing in a single container - SAST + cross-file taint (16 languages), dependency CVEs (SCA), secrets with live key validation, IaC, CMS & web-shell/malware. No external tools, runs non-root, no telemetry.
docker run --rm -v "$PWD:/src" dominators/sast:latest /src -f html,json,sarif -o /src/reports --fail-on high
Because -v "$PWD:/src" mounts your current directory, the reports land in ./reports on your machine (HTML + JSON + SARIF) - not inside the container (which --rm discards). --fail-on high exits non-zero on high+ findings, so it gates CI.
# Windows PowerShell
docker run --rm -v "${PWD}:/src" dominators/sast:latest /src -f html,json,sarif -o /src/reports --fail-on high
docker run --rm dominators/sast:latest https://github.com/owner/repo --fail-on high
- run: docker run --rm -v "$PWD:/src" dominators/sast:latest /src -f sarif -o /src/out --fail-on high
- uses: github/codeql-action/upload-sarif@v3
with: { sarif_file: out }
latest, 1.8.2 - multi-arch (linux/amd64 + linux/arm64)Also: pip install sast - npm i -g sastai - brew install vulnz/sast/sast - VS Code / JetBrains plugins - GitHub Action. Docs: https://insom.ai/en/sdlc
Content type
Image
Digest
sha256:0d762e15f…
Size
77.7 MB
Last updated
4 months ago
docker pull dominators/sast