sast-scanning - Static Application Security Testing
Identify security vulnerabilities in source code through static analysis
Tags
Updated: 2026-05-11Capabilities
Typical Inputs
Typical Outputs
What this skill does
- scan source code with Semgrep
- analyze code with CodeQL
- run SonarQube security checks
- execute Bandit Python scans
- perform Brakeman Ruby scans
- run ESLint security checks
- configure scan rules
- generate vulnerability reports
- setup CI/CD integration
- apply quality gates
Inputs
- Source code repository
- Semgrep rules
- CodeQL queries
- SonarQube configuration
- CI/CD pipeline
Outputs
- Vulnerability reports
- JSON scan results
- SARIF format results
- Quality gate status
- Security findings
Requirements
- Source code access
- CI/CD pipeline
- SAST tool installation
