Skip to content

Latest commit

 

History

History
26 lines (16 loc) · 825 Bytes

sast.md

File metadata and controls

26 lines (16 loc) · 825 Bytes

Static Application Security Testing

DeveloperTown projects should utilize appropriate static application security testing tools.

Why SAST?

Static application security testing (SAST) tools automatically scan the source code of an application. The goal is to identify vulnerabilities before deployment. SAST tools perform white-box testing, which involves analyzing the code based on inside knowledge of the application.

  • Examine the codebase of an application in one test
  • Test an application before compiling or running the code
  • Identify vulnerabilities early in the software development life cycle (SDLC), which is when vulnerabilities are easiest and cheapest to fix

Language and Tools

  • c#
  • Kotlin
  • Typescript / Javascript
  • Terraform

c#

Kotlin

Typescript / Javascript

Terraform