Public security rule registry

The community hub for quality SASTStatic Application Security Testing rules.

Search, inspect, and fetch rules ready for coding-agent workflows.

Verified qualityReusable packsAgent-ready fetch
Indexed rules
2,917
Rule fetches
2.7M

484.9K in 7d

Verified coverage
100%

All rules verified

Sponsored and operated byProvally
Explore rulesSearch by CVE, CWE, language, framework, or rule slug.Rule packsFetch curated sets with provenance and manifests.LeaderboardFind active authors and recommended rules.Agent pluginInstall and run greprules from Claude Code, Codex, or Hermes.
Community

Top 5 authors

Rankings
  1. 1
    @provally1 stars · 2.2M downloads
  2. 2
    @gitlab-security-products0 stars · 492.6K downloads
Reuse

Packs and collections

All packs
FAQ

Common questions

Docs
Is greprules.io a scanner?

No. greprules.io is a registry and quality layer for SAST rules. Scans still run through compatible CLI, scanner, or agent workflows.

Can public rules be fetched without signing in?

Yes. Public rules are available for browse and fetch. Sign in is for starring rules, collections, feedback, and publishing reviewed submissions.

Which languages are supported?

JS/TS and Python are the focused languages today. Other languages may appear in the registry, with early support marked in the explorer filters.

How should I judge whether a rule is ready to reuse?

Check license, source/provenance, validation status, quality score, usage signals, references, and community feedback before reuse.

Is greprules open source?

Greprules is sponsored by Provally. Local tooling, public registry surfaces, schemas, manifests, and project docs are open-source oriented; hosted operations are run by Provally.