sast-scanning - Static Application Security Testing
Perform static analysis on source code to identify security vulnerabilities using tools like Semgrep, CodeQL, and SonarQube.
Tags
Updated: 2026-05-11Capabilities
Typical Inputs
Typical Outputs
What this skill does
- run SAST scan
- apply security rules
- create custom rules
- generate security reports
- configure SAST tools
- integrate with CI/CD
Inputs
- source code
- SAST tool configuration
- custom security rules
- CI/CD pipeline
Outputs
- security reports
- vulnerability findings
- scan results
- quality gate status
Requirements
- source code access
- SAST tool installed
- supported programming language
