Static Application Security Testing
Security analysis that inspects source code, bytecode, or binaries without executing the target application.
Security Context
Static application security testing examines source code, bytecode, or binaries without executing the target application. In CI it can provide early feedback, while data-flow and taint analyses can model paths from untrusted sources to sensitive sinks. Rule tuning and false-positive management are essential for sustained use.
Analysis Boundary
SAST cannot observe the complete runtime configuration, deployed network exposure, authentication state, or every environment-dependent behavior. It complements rather than replaces dynamic testing.