Thank you for contributing
September 17, 2026 · View on GitHub
We welcome pull requests for static analysis tools that meet the requirements below. Please verify all criteria before submitting a tool. If a tool does not qualify yet, wait until it does rather than opening a pull request or issue.
Requirements
Before submitting, each tool must
- have existed for at least six months
- have at least 20 stars on GitHub
- have more than one human contributor
Bot and automation accounts do not count toward the contributor minimum. The
check excludes GitHub bot accounts, logins ending in [bot], and known automation
accounts such as claude, dependabot, and renovate-bot, even when GitHub lists
them as ordinary users.
These requirements apply to all tools.
The CI bot will politely close pull requests when it verifies that a tool does not meet the criteria. You are welcome to submit a new pull request once all criteria are met. If a check cannot be verified automatically (for example, for a non-GitHub or proprietary tool), it requires manual review rather than automatic closure. Meeting the minimum criteria does not guarantee inclusion.
For tools without a source URL, the bot checks the homepage domain's registration date through RDAP. Domains younger than six months fail the age check but require manual review rather than automatic closure. An older domain does not prove the service's age. If the service previously operated under another domain, please provide evidence of that history. Missing registration data also requires review.
Format
⚠️ The main README.md is just a rendered version of the data. Do not edit it
manually. Leave generated README.md changes out of your pull request, even
if you run make render locally. CI will flag them as a failure in the PR
comment. For changes to the README text or structure, edit
ci/crates/render/templates/README.md instead.
To add a new tool, please create a file in the data/tools directory like
data/tools/<toolname>.yml. Feel free to check out a few other YAML files in
that directory to see how it should look like.
- Use a nonblank tool name of at most 50 UTF-8 bytes (non-ASCII characters can take more than one byte).
- Make each tool description as precise as possible. Please limit the description to 500 characters.
- Add a license. If it's a proprietary tool, use
license: proprietary. - Add at least one tag, and include as many relevant tags as possible. Choose from
data/tags.yml. If a tool does not match any existing tag, feel free to add a new tag but also add it todata/tags.yml. - For AI-related tools, add
ai-generated-codeif the tool analyzes AI-generated code, and adduses-llmif it invokes an LLM or other model while analyzing code.
Finally, create a pull request with all your changes. You can call make render to check for errors before. This is optional, because it will also be
done when creating a pull request.
Related collections
To add or update a link in “More collections”, edit a YAML file in
data/collections/, not the README template. Each file contains name,
homepage, and description:
name: Example collection
homepage: https://example.com/collection
description: A collection of static analysis tools for a specific language.
Collections are listed alphabetically and are separate from individual tool entries.
How to mark a tool as unmaintained/deprecated
Sometimes a tool becomes unmaintained and there's nothing wrong with that.
After all, a tool can still be very valuable to the community - even without
frequent updates.
However, since it is one of the goals of this project to allow people to make an
informed decision on what is the best tool for the job, we are marking
unmaintained or deprecated tools after a while.
Here is a nice
discussion about why we think this is necessary. If you find a tool, which is
unmaintained, please add deprecated: true to the entry in data/tools/ and
create a pull request in which you provide an objective explanation as to why
you think the tool should be marked deprecated. Every deprecation will be
handled on a case-by-case basis.
Thanks for helping out! :tada: