Vulnerabilities and scanning

SAST (Static Application Security Testing)

Static Application Security Testing analyzes source code, bytecode, or binaries without executing them. SAST tools detect vulnerabilities by pattern matching, AST parsing, and dataflow analysis. SAST runs early in the development lifecycle, often in the editor or as a pre-commit check, so issues can be fixed before code is merged. Deva includes a SAST engine with YAML rules in the Semgrep format.