My team recently released a public preview for DevSkim, an open-source IDE plugin that flags security issues as you type them. Think "spell-check for security bugs". It doesn't provide the same level of depth as "real" static analyzers (it's just using regular expressions), but we think it serves an important need.
DevSkim includes inline guidance (why the code is vulnerable) and for some rules, a one-click "fix it for me" feature. It's available as a plugin for Visual Studio, VS Code, and Sublime Text.
I don't want to make this answer a feature list -- there is more information on our project page. We have plans to extend to additional IDEs, and of course to extend the ruleset. We welcome feedback and contributions.
与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…