Craft
ps
Tutorials
Presentations
Cheat Sheets
Quizzes
Interview Prep
Topics
Roadmap
About
Search
⌘K
Presentations
/
DevSecOps — The Complete Study Deck
/
SAST reads your code without ever running it
Slide 10 of 38
Sand & Signal
Open full tutorial
SAST reads your code without ever running it
Explains data-flow (taint) analysis, walks a Semgrep example, and names SAST's real limitations.
Raw HTML
← Previous
SAST, DAST, SCA: three different questions
Next →
DAST attacks the running app like a real attacker would