Vigilo
Vigilo is a fast, zero-configuration static security scanner for Python, JavaScript, and TypeScript (Node.js & React). It detects exploitable vulnerability patterns (CWEs) in first-party code using AST traversal combined with local data-flow analysis to minimize false positives.
Runs across Linux, macOS, and Windows — either via pip or as a standalone binary with no Python installation required.
Supported Languages
| Language / Framework | Status | File Extensions | Engine |
|---|---|---|---|
| Python | Stable | .py |
Native Python AST + Data Flow |
| JavaScript | New in v0.3.0 | .js, .mjs, .cjs, .jsx |
Tree-Sitter (tree-sitter-javascript) |
| TypeScript / React | New in v0.3.0 | .ts, .tsx |
Tree-Sitter (tree-sitter-typescript) |
See ROADMAP.md for planned languages (Java, HTML, CSS).
Why Vigilo?
- High-Signal over High-Noise: Traditional linters flag safe string constants and standard library calls indiscriminately. Vigilo uses local data-flow analysis to distinguish harmless constants from untrusted dynamic inputs.
- Zero Configuration: Drop it directly into your workflow or CI pipeline with
vigilo scan .orvigilo .. No YAML rule authoring or database setup required. - No Node.js Runtime Required: Multi-language parsing is powered by embeddable Tree-Sitter grammars compiled to native libraries — you do not need Node.js installed to scan JS/TS/React codebases.
- First-Party Code Focus: While tools like
pip-auditscan third-party dependencies for CVEs, Vigilo scans your code for logic and injection flaws.
Installation & Quickstart
Option A: Install via PyPI (Python 3.10+)
pip install vigilo
Option B: Standalone Executable (No Python Required)
Pre-built standalone single-file executables are available for Linux, macOS, and Windows on the Releases Page:
- Linux (x86_64):
vigilo-linux-x86_64 - macOS:
vigilo-macos - Windows (x86_64):
vigilo-windows-x86_64.exe
Verifying Checksums
Every release includes a SHA256SUMS.txt file to verify binary integrity:
# Verify checksum on Linux/macOS
sha256sum -c SHA256SUMS.txt
Note on Antivirus Alerts: Standalone executables are bundled with PyInstaller. Some heuristic antivirus engines or Windows SmartScreen may occasionally flag newly published PyInstaller binaries as unfamiliar. This is a known false positive with packed binaries. You can verify the integrity using the SHA256 checksum or install via
pip install vigiloto run from source.
Usage
Scan the current directory:
vigilo scan .
Or use the shortcut alias:
vigilo .
Generate structured JSON output for CI/CD pipelines:
vigilo scan . --format json
Filter by scan mode (security only, correctness diagnostics only, or all):
# Security scan only (skips correctness diagnostics)
vigilo scan . --security-only
# or:
vigilo scan . --mode security
# Correctness diagnostics only (syntax errors, undefined names, unclosed resources)
vigilo scan . --mode correctness
# or use the dedicated diagnose subcommand:
vigilo diagnose .
# All checks: Security + Correctness (Default)
vigilo scan .
Filter by minimum severity:
vigilo scan . --min-severity high
Exclude specific directories or glob patterns:
vigilo scan . --exclude "tests/*" --exclude "node_modules/*" --exclude "dist/*"
Python API
from vigilo import scan
# Security scan (default)
findings = scan("src/")
# Security + Correctness scan
all_findings = scan("src/", include_correctness=True)
for finding in findings:
print(
f"[{finding.severity.upper()}] {finding.detector.id} {finding.detector.name} ({finding.detector.category})"
)
print(f" Location: {finding.location}")
print(f" Fix: {finding.fix_hint}")
Supported Detectors
Python Security Vulnerabilities
| ID | CWE | Vulnerability | Severity | Target APIs |
|---|---|---|---|---|
VIGILO-001 |
CWE-89 | SQL Injection | HIGH |
db.execute(), cursor.execute(), text(), raw() |
VIGILO-002 |
CWE-78 | OS Command Injection | HIGH |
subprocess.*(shell=True), os.system(), os.popen() |
VIGILO-003 |
CWE-94 | Code Injection | HIGH |
eval(), exec(), compile() |
VIGILO-004 |
CWE-502 | Unsafe Deserialization | HIGH |
pickle.loads(), yaml.load(), marshal.loads() |
VIGILO-005 |
CWE-22 | Path Traversal | HIGH |
open(), os.open(), io.open() |
JavaScript / TypeScript / React Security Detectors (New in v0.3.0)
| ID | CWE | Vulnerability | Severity | Target Patterns / APIs |
|---|---|---|---|---|
VIGILO-JS-001 |
CWE-79 | Cross-Site Scripting (XSS) | HIGH |
innerHTML/outerHTML, document.write(), React dangerouslySetInnerHTML |
VIGILO-JS-002 |
CWE-94 | Code Injection | HIGH |
eval(), new Function(), string-based setTimeout/setInterval |
VIGILO-JS-003 |
CWE-78 | OS Command Injection | HIGH |
child_process.exec(), execSync(), spawn() with shell: true |
VIGILO-JS-004 |
CWE-1321 | Prototype Pollution | HIGH |
__proto__, constructor.prototype direct mutation, unsafe deep merge |
VIGILO-JS-005 |
CWE-798 | Hardcoded Secrets & Credentials | HIGH |
AWS keys, GitHub PATs, Slack tokens, JWTs, DB connection strings |
Python Code Correctness Diagnostics (Included in Default Scan or diagnose)
| ID | Issue | Severity | Description |
|---|---|---|---|
VIGILO-C01 |
Syntax & Indentation Error | HIGH |
Python parse failure or bad indentation |
VIGILO-C02 |
Undefined Name Usage | MEDIUM |
Use of unbound or misspelled variable/name |
VIGILO-C03 |
Unused Import / Variable | LOW |
Unused imported module or assigned local variable |
VIGILO-C04 |
Unclosed File Resource | MEDIUM |
Raw open() call without context manager (with) |
VIGILO-C05 |
Bare Except Clause | MEDIUM |
Blanket except: catch masking critical errors |
CLI Reference
usage: vigilo scan [-h] [--format {text,json}]
[--min-severity {low,medium,high}] [--exclude EXCLUDE]
[--no-color] [--mode {all,security,correctness}]
[--security-only]
[target]
positional arguments:
target Path to directory or file to scan (default: '.')
options:
-h, --help show this help message and exit
--format, -f {text,json}
Output report format (default: 'text')
--min-severity, -s {low,medium,high}
Minimum severity threshold to report (default: 'low')
--exclude, -e EXCLUDE
Exclude files/directories matching glob pattern (repeatable)
--no-color Disable ANSI color codes in output
--mode, -m {all,security,correctness}
Scan mode: 'all' (security + correctness), 'security'
(security only), 'correctness' (diagnostics only) (default: all)
--security-only, -S Shortcut for --mode security (only report security vulnerabilities)
Exit Codes
| Code | Meaning |
|---|---|
0 |
Clean — no vulnerabilities found at or above --min-severity |
1 |
Vulnerabilities detected |
2 |
Execution or path error |
Architecture & Project Documentation
- DECISIONS.md — Architecture Decision Records (ADRs) detailing package design, parser selection, and CLI ergonomics.
- ROADMAP.md — Supported and planned language roadmap (Python, JS, TS, React active; Java, HTML, CSS planned).
- TECH_STACK.md — Detailed runtime and dev dependency matrix with justifications.
- WORKFLOW.md — Development workflow, verification gates, and stage logs.
- TIMELINE.md — Historical milestone release logs and timestamps.
- CHANGELOG.md — Detailed version history adhering to Keep a Changelog.
Contributing
We welcome contributions! Please review our Contributing Guide, Code of Conduct, and Security Policy.
License
Distributed under the MIT License. Copyright (c) 2026 Sanjiv - Vigilo.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file vigilo-0.3.1.tar.gz.
File metadata
- Download URL: vigilo-0.3.1.tar.gz
- Upload date:
- Size: 63.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
22ddd61eeec2e177acde7a28851c6ff6884343346676c3e905f3e7866bf9462d
|
|
| MD5 |
9572493aa8bd8b0d6555069b3cdd5df4
|
|
| BLAKE2b-256 |
81e2de9451a19326afaf7f52d5e00c6f6743ad05e1799650f22afad72a693c44
|
Provenance
The following attestation bundles were made for vigilo-0.3.1.tar.gz:
Publisher:
release.yml on Sanjiv215/VIGILO-Python-Package
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vigilo-0.3.1.tar.gz -
Subject digest:
22ddd61eeec2e177acde7a28851c6ff6884343346676c3e905f3e7866bf9462d - Sigstore transparency entry: 2734744181
- Sigstore integration time:
-
Permalink:
Sanjiv215/VIGILO-Python-Package@581f0b7b69441b12c1d12811a41d1d14e3f2baf1 -
Branch / Tag:
refs/tags/v0.3.1 - Owner: https://github.com/Sanjiv215
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@581f0b7b69441b12c1d12811a41d1d14e3f2baf1 -
Trigger Event:
push
-
Statement type:
File details
Details for the file vigilo-0.3.1-py3-none-any.whl.
File metadata
- Download URL: vigilo-0.3.1-py3-none-any.whl
- Upload date:
- Size: 47.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9a877c6fefda416661236a0d7e252ddf6858851fd1593b0dac4cad94c13ade12
|
|
| MD5 |
429a12102c866321303f0d489e9feb7b
|
|
| BLAKE2b-256 |
29c9315de5e15e13e3149e88f0a87ae10edab47d02487e9524af66e85c717b32
|
Provenance
The following attestation bundles were made for vigilo-0.3.1-py3-none-any.whl:
Publisher:
release.yml on Sanjiv215/VIGILO-Python-Package
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vigilo-0.3.1-py3-none-any.whl -
Subject digest:
9a877c6fefda416661236a0d7e252ddf6858851fd1593b0dac4cad94c13ade12 - Sigstore transparency entry: 2734745358
- Sigstore integration time:
-
Permalink:
Sanjiv215/VIGILO-Python-Package@581f0b7b69441b12c1d12811a41d1d14e3f2baf1 -
Branch / Tag:
refs/tags/v0.3.1 - Owner: https://github.com/Sanjiv215
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@581f0b7b69441b12c1d12811a41d1d14e3f2baf1 -
Trigger Event:
push
-
Statement type: