Skip to content

Include a section on SAST #88

Description

@jgadsden

Describe what change you would like :
It would be good to have a section on static analysis in the implementation section, and add open-source community edition semgrep to the new section

Context :
Section: 05-implementation/

semgrep: https://semgrep.dev/docs/getting-started/quickstart-oss/

Activity

  1. changed the title [-]Iinclude a section on SAST[/-] [+]Include a section on SAST[/+] on Apr 29, 2025
  2. added this to the Version 4.1.9 milestone on May 13, 2025
  3. github-actions commented on Jan 3, 2026

    @github-actions

    This issue is stale because it has been open for 6 months with no activity.

  4. github-actions commented on Sep 9, 2026

    @github-actions

    This issue is stale because it has been open for 6 months with no activity.

  5. dannydj commented on Sep 9, 2026

    @dannydj

    Hi, I'd be interested in contributing to this issue if it's still relevant for the Developer Guide.
    I'm a software engineer with experience in Java, web/mobile applications, and enterprise financial systems. As part of my development work, I've also been involved in static analysis and remediation of application security findings.
    I'd be happy to work on a concise, developer-oriented introduction to SAST, following the Developer Guide structure and contribution guidelines.
    If this issue is still available, could it be assigned to me?

    AI disclosure: I used generative AI to help refine the wording of this comment. The professional experience, interest, and intent described above are my own.

  6. jgadsden commented on Sep 10, 2026

    @jgadsden
    ContributorAuthor

    Thank you for the AI disclosure - it is good to be open 👍🏾
    yes, please go ahead and create this page or section on SAST
    Please ensure that the content is your own words and not AI generated (we can all do that :) ) and follow the contributor's guidelines

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions