{
  "id": 1892040,
  "title": "There are 755 static-analysis tools. Only 42 are open-source security scanners.",
  "url": "https://urgent.news/2026/08/19/there-are-755-static-analysis-tools-only-42-are-open-source-security",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-19T08:02:37.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/hamelin123/there-are-755-static-analysis-tools-only-42-are-open-source-security-scanners-3256"
  },
  "original_language": "en",
  "account": "There are 755 static analysis tools in the catalog, but only 42 of them are open-source security scanners. This disparity is surprising, given that 86% of the tools are open source. The 42 security scanners are distributed across 21 programming languages, with Python, Go, Java, and JavaScript having the most. Languages like SQL, Shell, PowerShell, Dart, Elixir, Lua, R, Groovy, Clojure, and Haskell do not have any open-source security scanners. This gap exists despite these languages being crucial for CI, production systems, and SQL injection attacks. The data used for this study is publicly available in a single JSON file on a MIT-repo, and the methodology for the analysis is also open-source for reproducibility.",
  "summary": "If you run a linter on your code today, you have a lot of choices. If you want one that actually looks for security bugs — and is open source — you have far fewer than the ecosystem's size suggests. We parsed the public analysis-tools.dev catalog (MIT-licensed, 755 tools) to get an actual count instead of a vibe. Here's what fell out. TL;DR Of 755 static-analysis tools in the catalog, 86% are…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}