
Free offline SAST engine for CI/CD: AST and cross-file taint analysis, secret detection with live validation, SCA/CVE, IaC misconfiguration, and web-shell scanning with SARIF output.
Free, fast static application security testing for your terminal & CI/CD.
SAST + taint · secrets with live key validation · SCA/CVEs · IaC · CMS & web-shell/malware —
one self-contained binary, the same engine in your IDE and your build.
Plugin home · CI/CD & SDLC · Direct downloads · Manifest
sast is a tiny launcher. Installing it is instant; the first time you run it,
it downloads a self-contained SAST engine binary that matches your operating
system, verifies its checksum, and caches it. Every run after that is native
speed with no Python dependencies.
pip install sast
sast . # scan the current directory
sast ./src -f sarif -o out # write a SARIF report into ./out
sast . --fail-on high # exit non-zero on high+ findings (CI gating)
sast --help # full engine options
▶ Watch the overview video
·
Read the SDLC walkthrough →
Coverage at a glance: 1,750+ FP-validated rules · native AST + cross-file taint on 16 languages (regex for 40+) · 230+ secret rule packs with live key validation · SCA across 8+ ecosystems + container/OS packages · ~24,000 CMS advisories · web-shell & malware signatures · IaC (Terraform/K8s/Docker/ CloudFormation) · SARIF / JSON / HTML.
Supports Linux, macOS and Windows (x86-64). On Apple Silicon the macOS binary runs under Rosetta.
Pick whichever fits your stack — every method lands the same engine.
| Method | Command |
|---|---|
| pip / pipx (any OS, Python 3.8+) | pip install sast · pipx install sast (recommended — isolated, always on PATH) |
| Homebrew (macOS / Linux) | brew tap vulnz/sast && brew install sast |
| npm (global launcher) | sudo npm install -g sastai |
| Debian / Ubuntu (signed apt repo) | see below — then sudo apt-get install sast |
| Direct binary (Fedora / Arch / Alpine / air-gapped) | curl -sSL https://insom.ai/latest/sast/linux -o /usr/local/bin/sast |
curl -sSL https://insom.ai/apt/public-key.asc | sudo gpg --yes --dearmor \
-o /usr/share/keyrings/insomnia-archive-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/insomnia-archive-keyring.gpg] https://insom.ai/apt stable main" \
| sudo tee /etc/apt/sources.list.d/insomnia.list
sudo apt-get update && sudo apt-get install -y sast
A single self-contained binary — handy for air-gapped boxes and minimal CI images:
curl -sSL https://insom.ai/latest/sast/linux -o /usr/local/bin/sast # Linux x86-64
# curl -sSL https://insom.ai/latest/sast/macos -o /usr/local/bin/sast # macOS
chmod +x /usr/local/bin/sast
sast --version
Windows: download https://insom.ai/latest/sast/windows, or grab any build from the
downloads page. Files + SHA-256 are listed in the
manifest.
pip install sast creates a sast command (Linux/macOS: <prefix>/bin/sast,
Windows: <prefix>\Scripts\sast.exe). For the command to be found, that
directory must be on your PATH. Inside a virtual environment:
python -m venv .venv
# Linux/macOS:
source .venv/bin/activate
# Windows:
.venv\Scripts\activate
pip install sast
If sast is "not recognized" / "command not found" after a
pip install --user, the per-user scripts dir isn't on your PATH. Either
add it, or just run it as a module — this always works regardless of PATH:
python -m sast .
%APPDATA%\Python\Python3XX\Scripts~/.local/binA prebuilt, multi-arch (amd64 + arm64) image ships the engine baked in — nothing to install, ideal for CI/CD. Available on both registries:
dominators/sastghcr.io/vulnz/sastdocker pull dominators/sast:latest # or: ghcr.io/vulnz/sast:latest
Scan local source code — report saved to your folder. Mount your project at
/src; the reports land in ./reports on your machine (not inside the
container, which --rm discards):
docker run --rm -v "$PWD:/src" dominators/sast:latest /src -f html,json,sarif -o /src/reports --fail-on high
# Windows PowerShell
docker run --rm -v "${PWD}:/src" dominators/sast:latest /src -f html,json,sarif -o /src/reports --fail-on high