Three tools, three different questions.
Before the acronyms multiply: does the tool look at your code without running it, while it's running, or at the other people's code you depend on?
SAST · static
Reads your code
Without ever running it. Like a proofreader reading the manuscript before it's printed.
DAST · dynamic
Attacks the running app
From the outside, like a real attacker. A burglar testing your locks while you live in the house.
SCA · composition
Audits your dependencies
Third-party libraries you depend on. Checking whether the bricks you bought have a recall.
Needs source?Runs how early?Finds
SASTYesEvery commit/PRInjection patterns, hardcoded secrets
DASTNo — external attackerNeeds a running envMisconfig, auth bypass, real exploits
SCAManifest onlyEvery dependency changeKnown CVEs in libraries
SAST reads, DAST attacks, SCA audits your supply of borrowed code — a mature pipeline runs all three, at different stages.