Static analysis (SAST)
Onam's static analysis runs on the open-source Semgrep engine with three rule sources, and grades every result by how much its rule can prove.
Languages
| Language | File extensions | Curated taint rules | Pattern rules |
|---|---|---|---|
| Python | .py | Yes | — |
| JavaScript | .js .mjs .jsx | Yes | Yes |
| TypeScript | .ts .tsx | Yes (shared with JavaScript) | Yes |
| Java | .java | Yes | Yes |
| C# | .cs | Yes | Yes |
| Go | .go | Yes | Yes |
| Ruby | .rb | Yes | — |
| C | .c .h | — | Yes |
| C++ | .cpp .cxx .cc .hpp .hxx | — | Yes |
Community security packs apply across all of them. PHP, Kotlin, Rust, Swift and Scala are not analysed today.
The three rule sources
- Community security packs — OWASP Top 10, a general security audit, secrets and Node.js, pulled from the Semgrep registry. General-purpose packs that mix security with code style are deliberately not used.
- Onam curated taint rules — hand-written rules that follow untrusted input (a request parameter, a header, a file) to a dangerous sink (a query, a shell, a file path, an outbound request). Each carries its own CWE, OWASP category and severity, and has tests in the rule repository.
- Onam reviewed pattern rules — broader pattern rules, each triaged by hand into security, code-quality, accessibility or not-applicable. Only the security ones run; the rest are dropped before a scan.
Severity follows evidence
| Result from | Listed as | Severity cap |
|---|---|---|
| Community or curated rule | Security issue | None — the rule's own severity |
| Pattern rule triaged as security | Hotspot to review | Medium |
| Pattern rule not yet triaged | Hotspot to review | Low |
This is the core design choice: a pattern match cannot show that untrusted input reaches the code it matched, so it is never allowed to outrank a finding that can.
What is skipped
Before scanning, the clone is pruned of node_modules, vendor, build output, static and documentation folders, minified *.min.js files and any file over 512 KB. That keeps third-party code — covered by dependency analysis — out of the static results.
What each finding carries
| Field | Example |
|---|---|
| File and line | app/db/orders.py, line 88 |
| Rule | sql-injection-fstring |
| Severity | critical, high, medium or low |
| Message | What the rule found |
| CWE / OWASP | CWE-89 · A03 Injection |
| Confidence and tier | Security issue or hotspot |
| Code snippet | A few lines of context |
Limits worth knowing
- Analysis is per scan of one branch. There is no incremental or changed-files-only mode.
- Custom rules cannot be added from the console.
- If the community packs cannot be loaded for a scan, the scan still runs with Onam's own rules and is flagged as having reduced coverage.