Matchboxmatchbox
← Back to match

Sighthound

Tree-sitter based static application security scanner with pattern and taint-flow analysis for 10+ languages.

Desktopfreemium

Sighthound is an open-source static code security scanner that uses pattern matching and taint-flow analysis to find vulnerabilities across languages like Python, JavaScript, Java, PHP, and Go. It is built for application security teams and developers who want SARIF/JSON/CSV output for CI pipelines, with a hosted platform available from its maker, Corgea, for teams that want secrets, container, and dependency scanning bundled in with automated fixes.

Categories
SecurityStatic AnalysisDevSecOps

Full match profile

Behind the summary, Matchbox keeps a richer profile of Sighthound - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether Sighthound (or something else) actually fits.