Skip to content

awslabs/automated-security-helper

View on GitHub ↗Related repositories →

ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.

active 2025-04-012026-08-05 (UTC)

Partial coverage11,369 / 12,256 hourly files (93%) · 2 absent upstream · 884 failed, retryable2025-03-182026-08-10 (UTC)— sampled evenly across the window, so rankings and trends hold; absolute counts scale up.
Events
1.3K
Pushes
551
Pull requests
100
Issues
32
Stars
90
Forks
15

Activity over time

Daily event counts in the loaded window

Line chart, 492 days from 2025-04-01 to 2026-08-05. Pushes: 551 total, peak 31 in a day. Pull requests: 100 total, peak 5 in a day. Issues: 32 total, peak 6 in a day. Comments: 216 total, peak 20 in a day. Stars: 90 total, peak 7 in a day.

  • Pushes
  • Pull requests
  • Issues
  • Comments
  • Stars

Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.

Top contributors

Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity

Recent activity

Latest issues, pull requests and releases

  • Issue comment#367github-actions[bot]2026-06-17 00:57
    ci: bump starlette from 1.3.0 to 1.3.1
  • Issue comment#363github-actions[bot]2026-06-12 00:09
    chore(release): 3.5.3 -> 3.5.4
  • Issue#347rafaelpereyra2026-05-15 00:57
    Suppression with `line_start` but no `line_end` is matched as open-ended, but lint message claims it defaults to `line_start`
  • Issue#347rafaelpereyra2026-05-15 00:57
    Suppression with `line_start` but no `line_end` is matched as open-ended, but lint message claims it defaults to `line_start`
  • Pull request#333awsmadi2026-05-12 00:51
  • Releasegithub-actions[bot]2026-05-11 23:20
    v3.5.1
  • Pull request#328github-actions[bot]2026-05-11 18:02
  • Issue comment#318github-actions[bot]2026-05-11 03:27
    build: update constructs requirement from <11.0.0,>=10.3.0 to >=10.6.0,<11.0.0
  • Issue comment#317github-actions[bot]2026-05-11 03:26
    build: update python-multipart requirement from <0.1,>=0.0.22 to >=0.0.28,<0.1
  • Issue comment#316github-actions[bot]2026-05-11 03:26
    build: update mypy requirement from <2.0.0,>=1.15.0 to >=2.0.0,<3.0.0
  • Pull request#320dependabot[bot]2026-05-11 03:24
  • Pull request#316dependabot[bot]2026-05-11 03:24
  • Issue comment#23awsmadi2026-05-09 09:25
    Support for choosing which files to run against?
  • Issue comment#153awsmadi2026-05-09 09:25
    [Feature Request] Publish ASH container image to a public repository
  • Issue comment#180awsmadi2026-05-09 07:49
    Bug: in v3, yarn audit fails due to missing command
  • Issue#313awsmadi2026-05-08 20:29
    Add support for ASH configuration via pyproject.toml
  • Issue comment#222awsmadi2026-05-05 14:13
    findings not reflected in ASH summary: SARIF contains rules but results is empty (scan shows PASSED with 0 findings)
  • Issue comment#284github-actions[bot]2026-05-04 23:04
    feat(reporters): add gitlab-cyclonedx reporter for GitLab Dependency List
  • Issue#61awsmadi2026-05-04 16:52
    feat(results): adapt standardized JSON output to JUnitXML
  • Issue comment#279github-actions[bot]2026-04-28 23:54
    fix: config file discovery broken since v3.2.7
  • Pull request#264dependabot[bot]2026-04-15 22:40
  • Issue comment#257dependabot[bot]2026-04-14 01:40
    chore(deps): bump pygments from 2.19.2 to 2.20.0
  • Issue comment#263github-actions[bot]2026-04-14 01:34
    V3 2 6
  • Pull request#263rafaelpereyra2026-04-14 01:29
  • Issue comment#262github-actions[bot]2026-04-13 22:14
    fix(cli): exclude internal fields from config init output

Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 90 stars here means stars gained during the window, not the repo's star count.