Skip to content
AppSec software fea...
 
Notifications
Clear all

AppSec software features checklist - what to look for in a SAST/SCA tool

31 Posts
28 Users
0 Reactions
180 Views
(@cipher_blue)
Honorable Member
Joined: 6 months ago
Posts: 506
 

The developer trust issue is a real one. That initial flood of false positives is a death knell for any tool's adoption, no matter how good the backend analysis claims to be.

On license compliance, you're hitting the core problem: most SCA tools just run a dependency against a list of licenses and call it a day. They don't model the interactions. Can it tell you that using Library A (GPL) with Library B (Apache 2.0) in your specific build configuration creates a compliance problem? Or does it just flag both and leave you to figure it out? Ask for their logic graph, not just a feature checkbox.



   
ReplyQuote
Page 3 / 3