Ross ROSS = Recommend OSS · open-source software intelligence for agents

Bearer/bearer

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks. observed · 2026-08-28

github.com/Bearer/bearer · homepage · Go · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 87
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 36.0
  • age_days: 1436
  • days_rel: 9
  • days_push: 9
  • n_releases_24m: 15

Full methodology

Adoption not part of the score

2739 stars · 149 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Bearer CLI is an open-source static application security testing (SAST) tool written in Go that scans source code and analyzes data flows to discover, filter, and prioritize security and privacy risks. It includes built-in rules covering the OWASP Top 10 and CWE Top 25, and generates privacy reports useful for GDPR compliance such as PIA, DPIA, and RoPA.

Use cases

  • scan my source code for security vulnerabilities
  • find SQL injection and XSS in my codebase
  • detect hardcoded passwords and weak cryptography
  • generate a privacy report for GDPR compliance
  • detect PII and PHI data flows in my application
  • run SAST scanning in CI/CD pipelines
  • audit code against OWASP Top 10 and CWE Top 25

When to choose

  • you want a developer-friendly SAST scanner for Go, Java, JavaScript, TypeScript, PHP, Python, or Ruby projects
  • you need privacy risk detection and GDPR-oriented reporting alongside security scanning
  • you want a free, installable CLI (script, Homebrew, apt, yum, Docker) for security audits

When to avoid

  • you need languages beyond the open-source set such as C#, Kotlin, Rust, or Swift, which require the commercial Bearer Pro
  • you need dynamic analysis, dependency (SCA) scanning, or runtime security rather than static analysis

Facets

cli-tool · maturity active

security vulnerability-scanning static-site-generator developer-tools security developer-tools privacy legal cli windows cross-platform sast static-analysis appsec devsecops gdpr privacy owasp dataflow-analysis security-audit linux macos docker

5 sources

Member repositories

RepositoryRoleHealth v2
Bearer/bearermain95

For agents

markdown · JSON · MCP: product_card(name="Bearer/bearer")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem