ansede-static
Version updated for https://github.com/mattybellx/Ansede to version v6.3.0.
- This action is used across all versions by 1 repositories.
Action Type
This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary
Ansede Static is a comprehensive static analysis tool designed to detect common security flaws such as CWE-639 IDOR. It provides 100% CVE recall across multiple languages and catches authorization flaws that can lead to data breaches. The action automates the scanning of codebases, including generating SARIF reports for GitHub Code Scanning, diff-only scans for pull requests, and interactive HTML reports. It supports offline operation and is fully customizable with built-in rules for specific security vulnerabilities like IDOR.
What’s Changed
[6.3.0] — 2026-07-13
Added
- CWE-639 IDOR Detection — World-first among open-source SAST tools. Detects Insecure Direct Object Reference patterns across Express/DAO (JS), Django ORM (Python), Flask-SQLAlchemy (Python), and Spring Boot JPA (Java). Identifies route parameters used in database queries without session/ownership verification.
- Variable propagation in fallback detectors — All three language analyzers
(JS, Python, Java) now trace taint through variable assignments, enabling detection
of patterns like
const x = req.query.file→fs.readFile(x). - Struts2/Spring parameter binding detection — Java fallback now recognizes
implicit taint sources from framework parameter binding (setters,
@RequestParam,@PathVariable) in addition to explicitgetParameter()calls. - Django ORM
.raw()propagation — Multi-hop taint tracing through string concatenation assignments:name = request.GET.get('q')→sql = "SELECT..." + name→Model.objects.raw(sql).
Improved
- Known-vulnerability detection: 88.6% → 91.4% across 4 test applications (NodeGoat, goof, pygoat, dvja) covering 35 CWE instances.
- Production noise: 0.04 findings/kLOC — Verified across 16 real production repositories (366,638 LOC). Scanner correctly identifies well-written production code as clean.
- Python fallback cap — Increased from 20 to 25 with injection CWE prioritization to prevent CWE-89/CWE-78 truncation.
- Java
Runtime.exec()pattern — Now matchesruntime.exec(command)wherecommandis a variable, not just chained.exec(var + "...").
Fixed
- Confidence pipeline bug —
pattern-rustanalysis kind now recognized as structural evidence, preventing false demotion of legitimate findings. - Paren-location bug —
_arg_contains_taintnow correctly locates the opening parenthesis in regex-matched sink patterns across all three language fallbacks. - SQLAlchemy parameterized query FP —
.execute(text(...), {'key': var})now correctly identified as safe (parameterized). - CWE-22 method-call FP —
f.read(),obj.write()patterns no longer flagged as path traversal. - Python CWE-22 secure_filename guard — Files using
werkzeug.utils.secure_filenameare now correctly excluded from path traversal detection.
Performance
- 1,215 tests passing (96.4%)
- CVE recall: 100% (164/164 across 5 languages)
- 16-repo production benchmark: 0.04 findings/kLOC average