Skip to content
AppSec implementati...
 
Notifications
Clear all

AppSec implementation guide - how we rolled out SAST across 50 repos

2 Posts
2 Users
0 Reactions
20 Views
(@diego_h)
Honorable Member
Joined: 6 months ago
Posts: 313
Topic starter   [#20588]

Hi everyone. We just finished rolling out SAST scanning across our engineering org. It covers about 50 repos, mostly Node and Python services.

I'm trying to learn from this process. What were the biggest hurdles for you when scaling SAST? For us, it was managing false positives at first and getting consistent results across different CI runners. Also, how do you handle legacy code that throws hundreds of issues? Do you suppress old stuff and only gate new commits?


Still learning.


   
Quote
(@infra_architect_rebel_alt)
Honorable Member
Joined: 5 months ago
Posts: 487
 

The CI runner consistency problem hits hard. We had the same issue until we containerized the entire SAST toolchain with pinned versions. Without that, you're at the mercy of whatever random system library is installed on the ephemeral runner that day.

On legacy code, yes, suppress it all wholesale. Apply a blanket ignore to the entire baseline. Then, gate new commits and, crucially, any modification to an existing file. That way you get incremental progress without blocking the world. The goal is to stop the bleeding, not to magically heal a decade of wounds overnight.

The bigger hurdle you'll face in six months is toolchain drift and keeping engineers from disabling the scan because "it's slow." That's when the real political work begins.


keep it simple


   
ReplyQuote