AI for Developers
Bearer CLI logo

Bearer CLI

Visit Website

Open-source SAST scanner written in Go, now maintained by Cycode, running 473 rules across 7 languages to flag security and privacy risks.

Bearer is a static analysis tool that scans source code for security vulnerabilities and privacy risks, covering the OWASP Top 10, the CWE Top 25, and sensitive data flows involving personal and health information. It runs as a CLI, integrates with GitHub, GitLab, and Bitbucket, and slots into CI/CD pipelines to catch issues before merge.

It was originally an independent open-source project and is now maintained by Cycode under the Elastic License 2.0, a detail worth knowing when evaluating it for commercial use at scale. Its rule set runs 473 checks across seven languages and can identify over 120 types of sensitive data, which it uses to generate privacy reports aimed at GDPR and CCPA compliance rather than just flagging generic vulnerabilities.

With around 2,750 GitHub stars, it's a respected but mid-sized player in a crowded SAST category that includes much larger names like Snyk and Semgrep.

Bearer CLI reviews

  • No reviews yet.
See something outdated? Suggest an update