Skip to main content

Rowan

CI Python 3.10+ License: MIT

Find security issues in your code and AI/ML projects, with evidence you can review.

Rowan reads your project's source code and model files and reports likely vulnerabilities: injection, unsafe deserialization, SSRF, leaked secrets, risky agent tools, unsafe model loading and more. It never runs your code.

Alpha. Treat every finding as a lead to check, not a confirmed bug. A clean report does not prove a project is secure.

Quick start

You need Python 3.10+ and pipx, which installs command-line tools into their own environment (on macOS: brew install pipx, then pipx ensurepath and open a new terminal).

1. Install Rowan:

pipx install "rowan-sast[js-crossfile]"

Already use uv? uv tool install "rowan-sast[js-crossfile]" works too. A plain pip install fails on Homebrew Python by design; see getting started for a virtual-environment install.

2. Install the scan engine (Opengrep) and check it:

rowan install-engine
export PATH="$HOME/.local/bin:$PATH"
rowan self-test

self-test should print [OK] three times.

3. Scan a project:

rowan scan /path/to/your-project

Windows, troubleshooting and more detail: getting started.

Let your coding agent do it

Paste this into Claude Code, Codex, Cursor or any agent that can run terminal commands, with your project open:

Install Rowan and scan this project for security issues.
1. Install it in its own folder (not inside this project) by following
   https://github.com/hedgerow-dev/rowan/blob/main/docs/getting-started.md
2. Run `rowan self-test`. If the engine is not [OK], stop and tell me.
3. Run: rowan scan <this project's absolute path> --no-project-config
   --no-sca --audit -f json -o <a folder outside this project>/rowan-report.json
4. If summary.degraded is true, tell me the scan is incomplete and why.
5. List the High and Critical findings with file:line links. For each one,
   say whether you checked the code or it is still just a lead.
6. Do not change any code in this project.

--no-sca keeps this first scan offline. Drop it to also check your dependencies for known CVEs (this sends package names and versions to OSV).

Common commands

rowan scan PATH                                  # readable report
rowan scan PATH --audit                          # include low-severity findings
rowan scan PATH -f json -o report.json           # save a report (also: html, sarif)
rowan scan PATH --ci --severity high             # CI: exit 1 on high/critical findings
rowan scan PATH --write-baseline base.json       # record today's findings...
rowan scan PATH --ci --baseline base.json        # ...then report only new ones

With --ci, exit code 0 means no findings, 1 means findings, and 2 means the scan was incomplete. Reports can contain source code and secrets: review them before sharing.

What it checks

Area Coverage
Source code Injection, unsafe deserialization, path traversal, SSRF, XSS, secrets
AI/ML apps Model loading, agent tools, LLM output handling, prompt files, MCP config
Dataflow Within-file through Opengrep; cross-file for Python and JS/TS, limited for Go
Dependencies Known CVEs, reachability hints, CycloneDX SBOM and OpenVEX output
Model files Pickle, PyTorch, GGUF, SafeTensors, Keras, ONNX, TensorFlow, numpy, joblib (via Hayward)

Python and JS/TS get the deepest analysis. Java, Kotlin and C# get within-file dataflow. Ruby, PHP and Rust get limited pattern checks. The report lists what it could not analyze.

The rule catalog has 591 rules across 48 YAML files. That is 400 regex rules and 191 taint rules (Opengrep). See the rule catalog.

Privacy

rowan scan never calls an LLM or uploads your code. Its only network calls are dependency lookups (OSV and FIRST EPSS), which --no-sca turns off. The experimental rowan hunt command does send code to the LLM you configure: see the usage guide.

More

License

MIT. Opengrep is a separate LGPL-2.1 engine and is not bundled.

Metadata

Release files for rowan-sast 0.3.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rowan-sast 0.3.3
File Size Uploaded
rowan_sast-0.3.3.tar.gz 1.2 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for rowan-sast 0.3.3
File Interpreter ABI Platform
rowan_sast-0.3.3-py3-none-any.whl Python 3 none any Details

Total release size: 2.1 MB

Release files / rowan_sast-0.3.3.tar.gz

Download URL rowan_sast-0.3.3.tar.gz
Size 1.2 MB
Tags Source
SHA-256 checksum
How to use checksums
57bec0ad5cd91e4bb89661c966eaf808cc3322eae542b9d10ee500bd5e063d29
BLAKE2b-256 checksum
How to use checksums
3b31f6d6c2fc0049e39cc870e83a99dec3ad585fb309e7801843e1cb1eaad499
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release files / rowan_sast-0.3.3-py3-none-any.whl

Download URL rowan_sast-0.3.3-py3-none-any.whl
Size 859.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d9a632906f8132c25e91445f2c6916eb142de0b336e3e5c8afc8146f75785540
BLAKE2b-256 checksum
How to use checksums
21fb441f3e64a2e652f203bd5b7857ef05e6e2a5db61d9e5fe0bc0a64611823b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release history Release notifications | RSS feed

0.3.4

2 release files

This release

0.3.3 This release

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page