Onam Security

Static analysis (SAST)

Onam's static analysis runs on the open-source Semgrep engine with three rule sources, and grades every result by how much its rule can prove.

Three rule sources, two kinds of result
Three rule sources, two kinds of result

Languages

LanguageFile extensionsCurated taint rulesPattern rules
Python.pyYes—
JavaScript.js .mjs .jsxYesYes
TypeScript.ts .tsxYes (shared with JavaScript)Yes
Java.javaYesYes
C#.csYesYes
Go.goYesYes
Ruby.rbYes—
C.c .h—Yes
C++.cpp .cxx .cc .hpp .hxx—Yes

Community security packs apply across all of them. PHP, Kotlin, Rust, Swift and Scala are not analysed today.

The three rule sources

  1. Community security packs — OWASP Top 10, a general security audit, secrets and Node.js, pulled from the Semgrep registry. General-purpose packs that mix security with code style are deliberately not used.
  2. Onam curated taint rules — hand-written rules that follow untrusted input (a request parameter, a header, a file) to a dangerous sink (a query, a shell, a file path, an outbound request). Each carries its own CWE, OWASP category and severity, and has tests in the rule repository.
  3. Onam reviewed pattern rules — broader pattern rules, each triaged by hand into security, code-quality, accessibility or not-applicable. Only the security ones run; the rest are dropped before a scan.

Severity follows evidence

Result fromListed asSeverity cap
Community or curated ruleSecurity issueNone — the rule's own severity
Pattern rule triaged as securityHotspot to reviewMedium
Pattern rule not yet triagedHotspot to reviewLow

This is the core design choice: a pattern match cannot show that untrusted input reaches the code it matched, so it is never allowed to outrank a finding that can.

What is skipped

Before scanning, the clone is pruned of node_modules, vendor, build output, static and documentation folders, minified *.min.js files and any file over 512 KB. That keeps third-party code — covered by dependency analysis — out of the static results.

What each finding carries

FieldExample
File and lineapp/db/orders.py, line 88
Rulesql-injection-fstring
Severitycritical, high, medium or low
MessageWhat the rule found
CWE / OWASPCWE-89 · A03 Injection
Confidence and tierSecurity issue or hotspot
Code snippetA few lines of context

Limits worth knowing

  • Analysis is per scan of one branch. There is no incremental or changed-files-only mode.
  • Custom rules cannot be added from the console.
  • If the community packs cannot be loaded for a scan, the scan still runs with Onam's own rules and is flagged as having reduced coverage.