Rowan
Find security issues in your code and AI/ML projects, with evidence you can review.
Rowan reads your project's source code and model files and reports likely vulnerabilities: injection, unsafe deserialization, SSRF, leaked secrets, risky agent tools, unsafe model loading and more. It never runs your code.
Alpha. Treat every finding as a lead to check, not a confirmed bug. A clean report does not prove a project is secure.
Quick start
You need Python 3.10+ and Git.
1. Install Rowan in its own folder, not inside the project you want to scan:
git clone --branch v0.3.0 https://github.com/hedgerow-dev/rowan.git
cd rowan
python3 -m venv .venv
source .venv/bin/activate
python -m pip install ".[js-crossfile]"
2. Install the scan engine (Opengrep) and check it:
rowan install-engine
export PATH="$HOME/.local/bin:$PATH"
rowan self-test
self-test should print [OK] three times.
3. Scan a project:
rowan scan /path/to/your-project
Windows, troubleshooting and more detail: getting started.
Let your coding agent do it
Paste this into Claude Code, Codex, Cursor or any agent that can run terminal commands, with your project open:
Install Rowan and scan this project for security issues.
1. Install it in its own folder (not inside this project) by following
https://github.com/hedgerow-dev/rowan/blob/main/docs/getting-started.md
2. Run `rowan self-test`. If the engine is not [OK], stop and tell me.
3. Run: rowan scan <this project's absolute path> --no-project-config
--no-sca --audit -f json -o <a folder outside this project>/rowan-report.json
4. If summary.degraded is true, tell me the scan is incomplete and why.
5. List the High and Critical findings with file:line links. For each one,
say whether you checked the code or it is still just a lead.
6. Do not change any code in this project.
--no-sca keeps this first scan offline. Drop it to also check your
dependencies for known CVEs (this sends package names and versions to OSV).
Common commands
rowan scan PATH # readable report
rowan scan PATH --audit # include low-severity findings
rowan scan PATH -f json -o report.json # save a report (also: html, sarif)
rowan scan PATH --ci --severity high # CI: exit 1 on high/critical findings
rowan scan PATH --write-baseline base.json # record today's findings...
rowan scan PATH --ci --baseline base.json # ...then report only new ones
With --ci, exit code 0 means no findings, 1 means findings, and 2
means the scan was incomplete. Reports can contain source code and secrets:
review them before sharing.
What it checks
| Area | Coverage |
|---|---|
| Source code | Injection, unsafe deserialization, path traversal, SSRF, XSS, secrets |
| AI/ML apps | Model loading, agent tools, LLM output handling, prompt files, MCP config |
| Dataflow | Within-file through Opengrep; cross-file for Python and JS/TS, limited for Go |
| Dependencies | Known CVEs, reachability hints, CycloneDX SBOM and OpenVEX output |
| Model files | Pickle, PyTorch, GGUF, SafeTensors, Keras, ONNX, TensorFlow, numpy, joblib (via Hayward) |
Python and JS/TS get the deepest analysis. Java, Kotlin and C# get within-file dataflow. Ruby, PHP and Rust get limited pattern checks. The report lists what it could not analyze.
The rule catalog has 590 rules across 48 YAML files. That is 400 regex rules and 190 taint rules (Opengrep). See the rule catalog.
Privacy
rowan scan never calls an LLM or uploads your code. Its only network calls
are dependency lookups (OSV and FIRST EPSS), which --no-sca turns off.
The experimental rowan hunt command does send code to the LLM you configure:
see the usage guide.
More
- Getting started: install, first scan, MCP setup, troubleshooting
- Capabilities: what Rowan finds, how it compares, measured results
- Usage guide: every option, configuration, baselines, CI and GitHub Action
- Contributing and architecture
- Security policy: report a vulnerability in Rowan privately
License
MIT. Opengrep is a separate LGPL-2.1 engine and is not bundled.
Metadata
Release files for rowan-sast 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| rowan_sast-0.3.0.tar.gz | 1.2 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| rowan_sast-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 2.1 MB
Release files / rowan_sast-0.3.0.tar.gz
| Download URL | rowan_sast-0.3.0.tar.gz |
|---|---|
| Size | 1.2 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6d3657cd06de6282745c1c6ec54d5785c24341809d247f79ad3ba9ee1e1a62af
|
|
BLAKE2b-256 checksum How to use checksums |
0aeb421a1cf360fd54c61e2d307a046f63428b965aba00a119147f7220b9d275
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.
Transparency logRelease files / rowan_sast-0.3.0-py3-none-any.whl
| Download URL | rowan_sast-0.3.0-py3-none-any.whl |
|---|---|
| Size | 844.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3b171b2ba92ff71d873ec4b0478712184ca1255a148b67222732532dae59d09e
|
|
BLAKE2b-256 checksum How to use checksums |
8a916db74841e7d2c961aced06c2ab2a0c2086befb7449f63904f827c1c36796
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.
Transparency log