@scandiumsys/owstra-cli
v1.3.1
Published
Owstra CLI - High-performance SAST & SCA static analysis security scanner
Readme
@scandiumsys/owstra-cli
High-performance structural Static Application Security Testing (SAST) and Software Composition Analysis (SCA) scanner for modern codebases.
owstra is a fast security scanner written in TypeScript using AST-based pattern matching (via web-tree-sitter) to discover vulnerabilities in source code (SAST) and third-party dependencies (SCA).
🚀 Quick Start
Run directly with npx (No installation required)
npx @scandiumsys/owstra-cli scan .Global Installation
# Install globally via npm
npm install -g @scandiumsys/owstra-cli
# Or using pnpm / yarn
pnpm add -g @scandiumsys/owstra-cli
yarn global add @scandiumsys/owstra-cliOnce installed, execute:
owstra scan .💻 Usage & Commands
owstra scan [path] [options]Options
| Flag | Short | Description | Default |
| --- | --- | --- | --- |
| --rules <path> | -r | Path to custom rule file or directory | owstra.yml |
| --strictness <level> | -s | Scan strictness level (low, normal, high) | normal |
| --depth <level> | -d | Scan depth level (normal, all) | normal |
| --version | -V | Output CLI version | |
| --help | -h | Display help output | |
Examples
# Scan current directory with default rules
owstra scan .
# Scan specific folder with high strictness
owstra scan ./src --strictness high
# Scan using custom security rules
owstra scan . -r ./custom-rules/🛡️ Supported Languages & Ecosystems
Owstra provides built-in rules for 15+ programming languages and frameworks:
- JavaScript / TypeScript (Node.js, Express, React, Vue)
- Python (Django, Flask, FastAPI)
- Go (Standard library, Gin, Echo)
- Java & Kotlin (Spring Boot, Android)
- C# / .NET
- PHP (Laravel, WordPress)
- Ruby (Rails)
- Swift & Dart / Flutter
- Terraform / HCL (Infrastructure as Code)
- Dockerfiles & YAML
- Package Dependency Auditing (SCA) (npm, pnpm, yarn, Maven, PyPI, Go modules)
📄 License
MIT © Scandium Systems
