Static Application Security Testing (SAST)

Share on:

Top > Transversal > DevSecOps > Security and Quality > Static Application Security Testing (SAST)

  • Amazon CodeGuru - Automated code reviews. Initially centred on Java.  πŸŒ
  • Checkmarkx Software Security Platform - An integrated security suite including SAST, SCA, and IAST capabilities.  πŸŒ
  • Codacy - A static code analysis tool that supports more than 30 different languages and file formats.  πŸŒ
  • CodeScan - An end-to-end static code analysis solution built exclusively to maintain quality and security for the Salesforce platform.   πŸŒ
  • DeepCode - DeepCode is an advanced semantic code analyser (automated "code reviews") based on AI technology. It supports Java, JavaScript/TypeScript, and Python.  πŸŒ
  • Fortify Static Code Analyzer - Fortify checks code written in most major languages (Java, C#, JavaScript, Swift, C, etc.) for security vulnerabilities.  πŸŒ
  • Muse - A SAST solution that covers a range of bug categories including performance, reliability, security, and style/standards and is especially focused on finding deep inter-procedural bugs.  πŸŒ
  • NextGen Code Analysis - ShiftLeft NextGen Static Analysis (NG SAST) is a solution based on the notion of a workflow that inserts into pull requests and enables developers to find and fix vulnerabilities without ever leaving their development environment.   πŸŒ
  • Polaris - The Synopsis Polaris Software Integrity Platform is an end-to-end SDLC, DevSecOps solution which includes IDE plug-ins, SAST and IAST tools, and integration with popular CI/CD tools such as Jenkins, GitHub, etc.  πŸŒ
  • Secure Code Warrior - A platform that trains and equips developers to think and act with a security mindset as they build and verify their skills, gain real-time advice and monitor skill development. This is different from the approach taken by SAST tools that apply only after the code is written.   πŸŒ
  • Sigrid - A software assurance platform which uses code analysis based on ISO 25010.  πŸŒ
  • SonarCloud - SonarCloud is SonarQube's SaaS version.  πŸŒ
  • SonarQube - SonarQube checks code written in most major languages for code smells, bugs and security vulnerabilities.  πŸŒ
  • Thunderscan - DefenseCode Thunderscan SAST is a solution that, in addition to static code analysis of the selected code base, it also scans dependencies for known vulnerabilities and associated CVE entries. It has a focus on compliance including PCI-DSS and HIPPA, among others.  πŸŒ
  • Veracode - A platform that includes security feedback in the IDE as well as an end-to-end stack consisting of SAST, DAST, SCA, as well as manual penetration testing capabilities, all in one centralised view.  πŸŒ
  • Xanitizer - A SAST solution that performs security analysis directly on one’s GitHub repository provides the results on GitHub’s ecurity tab.  πŸŒ

Before You Leave

🀘 Subscribe to my 100% spam-free newsletter!

website counters