DEV Community

#sast

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The same detector scores 45.5 or 100 on the OWASP Benchmark. Both are 'true.'

The same detector scores 45.5 or 100 on the OWASP Benchmark. Both are 'true.'

Comments
3 min read
There are 755 static-analysis tools. Only 42 are open-source security scanners.

There are 755 static-analysis tools. Only 42 are open-source security scanners.

Comments
3 min read
CodeQL 2.26.2 trims what counts as safe: fresh alerts incoming

CodeQL 2.26.2 trims what counts as safe: fresh alerts incoming

1
Comments
3 min read
I Built a 100% Offline SAST Scanner That Finds What Semgrep and CodeQL Miss

I Built a 100% Offline SAST Scanner That Finds What Semgrep and CodeQL Miss

Comments
1 min read
Why Your SAST Scanner Misses 86% of Real Vulnerabilities

Why Your SAST Scanner Misses 86% of Real Vulnerabilities

Comments
7 min read
Applying SAST to Any Application with CodeQL

Applying SAST to Any Application with CodeQL

Comments
3 min read
DAST false negatives vs SAST false positives: a real case

DAST false negatives vs SAST false positives: a real case

1
Comments
10 min read
SAST vs SCA: why your CI pipeline needs both

SAST vs SCA: why your CI pipeline needs both

Comments
4 min read
CI/CD Seguro: Dependabot, SAST e DAST no GitHub

CI/CD Seguro: Dependabot, SAST e DAST no GitHub

Comments
10 min read
GitHub Advanced Security vs Kolega: why it is already in our repo is not the same as we are covered

GitHub Advanced Security vs Kolega: why it is already in our repo is not the same as we are covered

Comments
2 min read
Applying SAST Tools to Real Applications — A Hands-On Look at Bandit

Applying SAST Tools to Real Applications — A Hands-On Look at Bandit

Comments 1
4 min read
Semgrep vs Kolega: a great floor, but a floor is not a finish line

Semgrep vs Kolega: a great floor, but a floor is not a finish line

Comments
2 min read
Aikido vs Kolega: the all-in-one platform is wide, but wide is not deep

Aikido vs Kolega: the all-in-one platform is wide, but wide is not deep

Comments
2 min read
Snyk vs Kolega: why pattern matching has a ceiling, and what sits above it

Snyk vs Kolega: why pattern matching has a ceiling, and what sits above it

Comments
2 min read
We benchmarked 24 SAST tools on ~700 real vulnerabilities. The 3 best known ones came last

We benchmarked 24 SAST tools on ~700 real vulnerabilities. The 3 best known ones came last

Comments
1 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.