Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc
-
Updated
Aug 22, 2026 - Scala
Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc
MATE is a suite of tools for interactive program analysis with a focus on hunting for bugs in C and C++ code using Code Property Graphs.
Code Property Graph (CPG) frontend for binary applications and libraries.
Codyze is a static analyzer for Java, C, C++ based on code property graphs
Plume is a code representation benchmarking library with options to extract the AST from Java bytecode and store the result in various graph databases.
Succinct Compositional Program Graph (SCPG) static analysis engine & 14-diagram UML generator in Rust.
The Cloud Property Graph is based on a Code Property Graph and tries to connect static code analysis and Cloud runtime assessment.
A Python implementation of a language-agnostic Code Property Graph
A static analysis tool for Java programs, based on the theory of code property graphs.
Neo4J visualisation tool for the Code Property Graph
Examples of how to use Plume
Static analysis tool that extracts architecture data from Kubernetes repos, builds multi-language code property graphs (Go, Python, TS, Rust), and runs security/architecture queries with taint analysis
chennai (chen N ai) is a hybrid AI agent and a terminal user interface for static analysis, data-flow tracing, and AI-assisted code and security analysis.
A Demo Program of Security Patch Identification with Graph Neural Networks.
Compiler-precise code property graph for C, Python, and TypeScript, navigable over MCP — data- and taint-flow with source→sink witnesses, points-to, and guard/sink structure for security reasoning over source.
Lab 04 Big Data project: incremental Code Property Graph streaming pipeline with Kafka, Neo4j, MongoDB, Spark Structured Streaming, and Jupyter Book evidence.
Ultra-fast open-source code security scanner. Finds vulnerabilities across 8 languages (Rust, Go, Python, JS, TS, Java, C, C++) using SAST + taint analysis + LLM verification — fewer false positives, faster audits. Outputs Sigstore-signed SARIF, SBOM, and OpenVEX bundles for supply-chain compliance.
A fast, keyboard-driven terminal UI for the lachesis code graph. Walk a codebase by subsystem, file, and symbol neighborhood, following real calls and data flow.
Add a description, image, and links to the code-property-graph topic page so that developers can more easily learn about it.
To associate your repository with the code-property-graph topic, visit your repo's landing page and select "manage topics."