Every code scanner I tried wanted to upload my whole codebase to their cloud first.
So I built pathbug. A local first static analysis CLI for JS and TS that flags security, bug, dependency and config issues without a single line of your source ever leaving your machine.
Privacy shouldn't be a paid tier.
Where do you draw the line on sending your code to a third party tool?