OpenUltraSAST¶
OpenUltraSAST is an experimental static security analyser. It is meant to be a safety net on
repositories it has never seen. It scans a checkout, or the commits a git push would publish. It
keeps what it can prove apart from what it only suspects. When a scan could not look at
something, it records a degradation. It does not report a clean result.
State as of 2026-10-02 (v2.0.0): the pre-push safety net is NO-GO for rollout. No hook capability is enabled. No independent population (a case set frozen before any scan) has passed the qualification gates (see Evaluation).
Three layers¶
| Layer | What it is | Where |
|---|---|---|
| Scanners | ousast scan (quick, standard, deep) and ousast pre-push: language-scoped pattern rules, a Joern code property graph engine, verification and scoring. Deterministic in quick; no model is needed for a scan. |
Scanning, Architecture |
| The agentic plane on ax | Model-driven work over whole repositories, run as a DAG of tasks on google/ax, one isolated actor per task. What the runs learn is kept in a memory store. Maintainer surface: ousast plane. |
The plane on ax, Memory |
| The decision engine | A learned classifier that weighs every instrument's signals against similar labelled cases from memory. In development, not adopted: no scan, pre-push check or report uses it. Maintainer surface: ousast learn. |
Memory and detection, Decision engine |
A code property graph is a graph of the program's syntax, control flow and data flow. Joern builds it.
How they connect¶
flowchart LR
repo["Repository or push delta"] --> scan["Scanners: quick rules, Joern engine, verify, score"]
scan --> report["Report: findings with evidence, SARIF, score"]
scan -- "alerts on vulnerable and fixed pins" --> plane["Plane on ax: repo-facts, verify a/b/c, agree, features"]
plane -- "remember" --> mem[("Memory store: rows, facts, examples, blobs")]
mem -- "improve --memory: rule-status proposals" --> gate{"Validator and detection gate"}
gate -- "accepted round" --> ledger["Ruleset ledger: rule status"]
ledger --> scan
labels["Labels from ground truth"] --> mem
mem -- "retrieval of similar labelled cases" --> engine["Decision engine: compiled AI classifier"]
engine -. "intended, not adopted: BLOCK / ADVISORY" .-> report
- The scanners produce findings. Inside plane Runs, they also produce the
alertsthat become memory rows. - The plane runs model work per case: verify passes and roles. It also runs model-free
bookkeeping per case: facts, agreement and feature records. Its
remembertask turns a case's artifacts into rows of the memory store. - Memory feeds two consumers:
ousast improve --memoryturns stored rows into rule-status proposals. They pass through the same validator and gate as every other edit.- The decision engine retrieves labelled examples from the same store.
- The decision engine's output (dotted line) is the intended path. Nothing user-facing reads it today.
Where to go next¶
- The current state in one page, every figure with its record: Where we stand. It covers capability against the M4 gates, the step-by-step approach, ax on the server, token economics before and after, and the open items.
- Run a scan: Examples, and the commands in Scanning.
- Understand a finding's evidence and score: Architecture.
- The program analysis under a scan, what each representation can see and what it misses: Detection techniques.
- Operate the plane and its store: ax on this host and RustFS setup.
- Where the plane runs today, and what a separate Kubernetes cluster would take (planned, not done): Deployment.
- Where the model spend goes, per Task at runtime and in the maintainers' own coding sessions, and what is reused instead of paid again: Token ergonomics.
- Trust boundaries and hardening: Threat model.
Every number in these pages is quoted from a committed record. The record's path is given next to the number.