ansede-static
Version updated for https://github.com/mattybellx/Ansede to version v6.5.0.
- This action is used across all versions by 1 repositories.
Action Type
This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary
Ansede is a free static analysis tool that automatically detects authorization bugs like IDOR, missing access controls, and privilege escalation. It performs cross-function analysis to trace data flow from HTTP routes to database queries or other sensitive sinks without relying on network connections or API keys. Ansede is designed to catch these security flaws before attackers do, offering a 100% CVE recall rate across multiple programming languages.
What’s Changed
[6.3.0] — 2026-07-13
Added
- CWE-639 IDOR Detection — World-first among open-source SAST tools. Detects Insecure Direct Object Reference patterns across Express/DAO (JS), Django ORM (Python), Flask-SQLAlchemy (Python), and Spring Boot JPA (Java). Identifies route parameters used in database queries without session/ownership verification.
- Variable propagation in fallback detectors — All three language analyzers
(JS, Python, Java) now trace taint through variable assignments, enabling detection
of patterns like
const x = req.query.file→fs.readFile(x). - Struts2/Spring parameter binding detection — Java fallback now recognizes
implicit taint sources from framework parameter binding (setters,
@RequestParam,@PathVariable) in addition to explicitgetParameter()calls. - Django ORM
.raw()propagation — Multi-hop taint tracing through string concatenation assignments:name = request.GET.get('q')→sql = "SELECT..." + name→Model.objects.raw(sql).
Improved
- Known-vulnerability detection: 88.6% → 91.4% across 4 test applications (NodeGoat, goof, pygoat, dvja) covering 35 CWE instances.
- Production noise: 0.04 findings/kLOC — Verified across 16 real production repositories (366,638 LOC). Scanner correctly identifies well-written production code as clean.
- Python fallback cap — Increased from 20 to 25 with injection CWE prioritization to prevent CWE-89/CWE-78 truncation.
- Java
Runtime.exec()pattern — Now matchesruntime.exec(command)wherecommandis a variable, not just chained.exec(var + "...").
Fixed
- Confidence pipeline bug —
pattern-rustanalysis kind now recognized as structural evidence, preventing false demotion of legitimate findings. - Paren-location bug —
_arg_contains_taintnow correctly locates the opening parenthesis in regex-matched sink patterns across all three language fallbacks. - SQLAlchemy parameterized query FP —
.execute(text(...), {'key': var})now correctly identified as safe (parameterized). - CWE-22 method-call FP —
f.read(),obj.write()patterns no longer flagged as path traversal. - Python CWE-22 secure_filename guard — Files using
werkzeug.utils.secure_filenameare now correctly excluded from path traversal detection.
Performance
- 1,215 tests passing (96.4%)
- CVE recall: 100% (164/164 across 5 languages)
- 16-repo production benchmark: 0.04 findings/kLOC average