Sast Configurator

当需要为应用代码搭建自动化漏洞静态扫描(SAST)、落地 DevSecOps 或在 CI/CD 中接入安全门禁时使用;产出 Semgrep/SonarQube/CodeQL 的配置、自定义规则与流水线集成方案;不适用于运行时动态测试(DAST)、依赖组件漏洞审计(用 dependency-auditor)或纯人工代码评审;触发词:SAST、静态应用安全测试、static analysis、Semgrep、SonarQube、CodeQL、代码漏洞扫描、安全门禁、DevSecOps

findscripter Updated

File contents

findscripter/everything-skills/tree/main/08-security/sast-configurator commit 464972dd1d

Frequently asked questions

npx skillmds@latest add findscripter/sast-configurator