Back to browse
GitHub Repository

Variant analysis, open-sourced. Feed a CVE patch, find every structural twin across your codebase. 6-stage pipeline: patch ingestion, LLM signature extraction, embedding search, Joern CPG slicing, LLM feasibility reasoning, SARIF reporting.

5 starsRust

Naptrace – find structural twins of a CVE in your codebase

by kenshi144·Apr 20, 2026·1 point·1 comment

AI Analysis

●●SolidBig BrainNiche Gem

Six-stage pipeline with Joern CPG and LLM reasoning beats simple pattern matching.

Strengths
  • CPG path slicing plus LLM feasibility verdicts reduces false positives significantly
  • Accepts patches from CVE IDs, git commits, diff files, or PR URLs flexibly
  • SARIF reporting integrates with existing security tooling workflows
Weaknesses
  • Security scanning is well-funded with GitHub Advanced Security and Semgrep competing
  • LLM-based reasoning may produce inconsistent results across different vulnerability types
Category
Target Audience

Security engineers, DevSecOps teams

Similar To

Semgrep · CodeQL · GitHub Advanced Security

Similar Projects

Developer Tools●●Solid

Detect Drift in TypeScript codebases

AST-based contracts beat raw code for AI, but codebase analyzers are increasingly crowded.

Niche GemBig Brain
AmiteK
102mo ago