#sast
Tagged “sast”
5 articlesThe next scanner in your pipeline is an autonomous agent. Ask where it runs.
A devops.com opinion piece argues CI/CD security testing is going autonomous: proof-based agents that chain vulnerabilities the way an attacker would. The real design fight is whether those agents run inside your trust boundary or ship your source and secrets to somebody else's.
Aug 16, 2026 · Tomás VegaSecurity & supply chainA devops.com walkthrough stacks four open-source security gates into GitHub Actions
devops.com published a build-it-yourself piece that stitches npm audit, Snyk, Trivy, CodeQL and OWASP ZAP into a single GitHub Actions pipeline. It is a decent map of what teams can gate on without an enterprise SKU, but stacking five scanners has an operational cost the article does not spend on.
Aug 16, 2026 · Maya OkonkwoSecurityCodeQL 2.26.2 trims what counts as safe: fresh alerts incoming
GitHub's static analysis engine adds Swift 6.3.3 and Kotlin 2.4.10 support in CodeQL 2.26.2, and quietly removes a batch of sanitizers that used to make path injection and URL redirection findings disappear.
Aug 10, 2026 · Tomás VegaCode quality & testingGitLab Duo Security Review Flow goes after the logic bugs SAST leaves on the floor
GitLab moved Security Review Flow into public beta on the Duo Agent Platform. You add it to a merge request like a human reviewer, and it focuses on authorization and business-logic bugs that pattern-based scanners typically miss.
Jul 17, 2026 · Priya NairSecurity & supply chainCheckmarx's pitch on its new SAST engine: the classifier in front of the queue is the product
Checkmarx unveiled a SAST engine that pairs a deterministic rules scanner with a security-trained LLM and a Findings Analysis Engine that triages true vs. false positives before developers see them. The CI/CD-relevant story is less the model and more the triage layer in front of the merge queue.
Jun 21, 2026 · Tomás Vega