<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Static-Analysis on Vibe Coding</title><link>https://vibecoding.rest/tags/static-analysis/</link><description>Recent content in Static-Analysis on Vibe Coding</description><generator>Hugo</generator><language>en</language><atom:link href="https://vibecoding.rest/tags/static-analysis/index.xml" rel="self" type="application/rss+xml"/><item><title>Trail of Bits Security Skills</title><link>https://vibecoding.rest/skills/trail-of-bits-security/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/skills/trail-of-bits-security/</guid><description>&lt;p&gt;Trail of Bits&amp;rsquo; security skills bring their own audit tooling — static analysis with CodeQL and Semgrep, variant analysis, and vulnerability pattern detection — into Claude Code.&lt;/p&gt;&#10;&lt;h2 id="why-a-skill-for-this"&gt;Why a skill for this&lt;/h2&gt;&#10;&lt;p&gt;Security auditing firms encode years of hard-won pattern knowledge into their tooling configs. Packaging that as a skill means Claude Code inherits Trail of Bits&amp;rsquo; actual audit methodology instead of a generic security pass.&lt;/p&gt;</description></item><item><title>Codacy</title><link>https://vibecoding.rest/tools/codacy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/tools/codacy/</guid><description>&lt;p&gt;Codacy runs static analysis, security scanning, and coverage checks on every commit and pull request, surfacing issues as a quality score and letting teams enforce consistent standards across large codebases.&lt;/p&gt;</description></item><item><title>DeepSource</title><link>https://vibecoding.rest/tools/deepsource/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/tools/deepsource/</guid><description>&lt;p&gt;DeepSource continuously analyzes repositories for bugs, security vulnerabilities, performance issues, and anti-patterns, and can generate automated fix-it patches that developers review and merge directly.&lt;/p&gt;&#10;&lt;h2 id="why-it-stands-out"&gt;Why it stands out&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Autofix patches&lt;/strong&gt; — many detected issues come with a ready-to-merge fix rather than just a flagged line.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Low false-positive focus&lt;/strong&gt; — rules are curated to avoid the noisy, low-value warnings common in generic linters.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Works alongside CI&lt;/strong&gt; — runs as a check on every commit and PR without requiring teams to rewrite existing pipelines.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="good-for"&gt;Good for&lt;/h2&gt;&#10;&lt;p&gt;Teams that want continuous static analysis with actionable, auto-generated fixes rather than just a list of warnings.&lt;/p&gt;</description></item><item><title>CodeScene</title><link>https://vibecoding.rest/tools/codescene/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/tools/codescene/</guid><description>&lt;p&gt;CodeScene analyzes both code structure and version-control history to identify hotspots, code health decline, and knowledge risk (bus factor), and includes automated PR review that flags maintainability regressions in new and AI-generated code.&lt;/p&gt;</description></item><item><title>Sonar</title><link>https://vibecoding.rest/tools/sonar/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/tools/sonar/</guid><description>&lt;p&gt;Sonar has scanned code for bugs, vulnerabilities, and code smells since SonarQube&amp;rsquo;s early days, and now extends that static analysis foundation with AI Code Assurance and AI-powered review features that specifically check AI-generated code against the same quality gates used for human-written code.&lt;/p&gt;</description></item></channel></rss>