Written in Rust, uses tree-sitter for parsing Cross-file taint propagation with BFS (max depth 15) 647 Semgrep rules pre-compiled at build time Supports 28 languages, 20+ frameworks (Spring, Django, Express, etc.) SARIF output for GitHub Security tab integration Sub-500ms for 100k lines
I scanned Spring Boot's own framework source and found 36 cross-file data flows including 8 SQL injection paths. Not toy examples — real multi-hop flows across 5-15 files. It's free and open source. Happy to answer questions about the taint analysis implementation or anything else.