{"id":648,"date":"2026-08-13T06:19:54","date_gmt":"2026-08-13T06:19:54","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=648"},"modified":"2026-08-13T06:19:54","modified_gmt":"2026-08-13T06:19:54","slug":"sast","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/sast\/","title":{"rendered":"SAST Explained: Static Application Security Testing"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: SAST\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">SAST analyses your source code without running it, looking for insecure patterns that could become vulnerabilities once the code ships.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Code security<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Static application security testing reads the code itself, tracing how untrusted input flows through the application to a sensitive operation. It runs before anything is deployed, which makes it the earliest place a security flaw can be caught, and the cheapest place to fix one.<\/p>\n<\/div>\n\n<p>SAST looks at code you wrote. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a> looks at code you imported. Together they cover most of what ends up in a build, which is why compliance frameworks ask about both.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#pipeline\">Where SAST runs<\/a><\/li>\n    <li><a href=\"#finds\">What it finds, and what it misses<\/a><\/li>\n    <li><a href=\"#noise\">Making it usable<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs code security<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"pipeline\">Where SAST runs<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 200\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Security testing across the pipeline: SAST and SCA at commit and build, DAST after deploy, penetration testing on the live system.\">\n  <defs><marker id=\"saA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#b9c0d4\"\/><\/marker><\/defs>\n  <text x=\"20\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">WHEN EACH TEST RUNS<\/text>\n\n  <rect x=\"10\" y=\"44\" width=\"170\" height=\"70\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"95\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#ffffff\">Commit<\/text>\n  <text x=\"95\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#b9c1e6\">SAST + SCA<\/text>\n  <line x1=\"186\" y1=\"79\" x2=\"200\" y2=\"79\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#saA)\"\/>\n\n  <rect x=\"206\" y=\"44\" width=\"170\" height=\"70\" rx=\"14\" fill=\"#c2d9ec\"\/>\n  <text x=\"291\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#25547a\">Build<\/text>\n  <text x=\"291\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#25547a\">SBOM generated<\/text>\n  <line x1=\"382\" y1=\"79\" x2=\"396\" y2=\"79\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#saA)\"\/>\n\n  <rect x=\"402\" y=\"44\" width=\"170\" height=\"70\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"487\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#3a6f5d\">Deployed<\/text>\n  <text x=\"487\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#3a6f5d\">DAST + scanning<\/text>\n  <line x1=\"578\" y1=\"79\" x2=\"592\" y2=\"79\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#saA)\"\/>\n\n  <rect x=\"598\" y=\"44\" width=\"154\" height=\"70\" rx=\"14\" fill=\"#f0e6f3\"\/>\n  <text x=\"675\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#6b4576\">Live<\/text>\n  <text x=\"675\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#6b4576\">Penetration test<\/text>\n\n  <rect x=\"10\" y=\"134\" width=\"742\" height=\"46\" rx=\"12\" fill=\"#f4f5fd\"\/>\n  <text x=\"381\" y=\"153\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">The further right a flaw is found, the more it costs to fix<\/text>\n  <text x=\"381\" y=\"171\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">A SAST finding is a pull request comment. The same flaw found live is an incident.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"finds\" class=\"c-sage\">What it finds, and what it misses<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>SAST finds<\/th><th>SAST misses<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Injection paths where user input reaches a query or command<\/td><td>Authorisation flaws, because intent is not visible in code<\/td><\/tr>\n    <tr><td>Hardcoded secrets and credentials in the repository<\/td><td>Configuration problems in the deployed environment<\/td><\/tr>\n    <tr><td>Unsafe cryptographic and random number usage<\/td><td>Vulnerabilities in third-party dependencies, which is SCA&#8217;s job<\/td><\/tr>\n    <tr><td>Missing output encoding leading to cross-site scripting<\/td><td>Anything that only appears at runtime under real load<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Why it cannot judge authorisation<\/p>\n  <p>A function that returns a record by ID looks identical whether or not the caller was entitled to it. Static analysis sees the code path, not the business rule, which is why broken authorisation is found by testers rather than by scanners.<\/p>\n<\/div>\n\n<h2 id=\"noise\" class=\"c-apri\">Making it usable<\/h2>\n\n<p>SAST fails in practice for one reason: too many findings, too little confidence, so developers stop reading them. Three things keep it alive.<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Run it on the diff<\/p>\n    <p>Scan what changed in the pull request rather than dumping the whole backlog on every build.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Fail on high, log the rest<\/p>\n    <p>Break the build only for high-confidence, high-severity findings. Everything else is a ticket.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Tune once, properly<\/p>\n    <p>Suppress rule families that do not apply to your stack, with a written reason, instead of ignoring the tool.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto runs code security<\/h2>\n\n<p>Osto&#8217;s code security module combines SAST with SCA, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> generation and open-source licence compliance, so findings from your own code and your dependencies arrive in one place rather than from separate tools. Because it sits in the same platform as the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a>, vulnerability testing and compliance modules, a code finding can be read alongside whether the affected path is exposed in production, which changes how urgently it needs fixing.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Catch it in the pull request, not in production<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto combines SAST with SCA, SBOM generation and licence compliance, so code and dependency findings arrive in one place.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">SAST + SCA + SBOM &middot; One toolchain &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does SAST stand for?<\/summary>\n  <p>Static application security testing. It analyses source code without executing it, tracing how untrusted input flows through the application to identify insecure patterns before deployment.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between SAST and DAST?<\/summary>\n  <p>SAST reads the code before it runs and can point at the exact line. DAST tests the running application from the outside and sees what an attacker would see. SAST finds more, earlier; DAST confirms what is actually reachable.<\/p>\n<\/details>\n\n<details>\n  <summary>Is SAST the same as SCA?<\/summary>\n  <p>No. SAST analyses code your team wrote. SCA identifies third-party and open-source dependencies and checks them against known vulnerability databases. Most modern applications are mostly dependencies, so both are needed.<\/p>\n<\/details>\n\n<details>\n  <summary>Do frameworks require SAST?<\/summary>\n  <p>ISO 27001:2022 covers secure coding in Annex A 8.28 and security testing in development in A 8.29. PCI DSS requires secure development practices and code review. Neither mandates a specific tool, but both expect <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-evidence-collection\/\">evidence<\/a> that code is checked before release.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> &middot; DAST &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">Penetration Testing<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; API Security<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>SAST analyses your source code without running it, looking for insecure patterns that could become vulnerabilities once the code ships.\u2026<\/p>\n","protected":false},"author":8,"featured_media":649,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[90,233,232],"class_list":["post-648","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-sast","tag-secure-coding","tag-static-application-security-testing"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/648","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=648"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/648\/revisions"}],"predecessor-version":[{"id":650,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/648\/revisions\/650"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/649"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=648"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=648"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=648"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}