Skip to content
Is there a way to e...
 
Notifications
Clear all

Is there a way to enforce that all agent-generated code passes the same SAST gates as human code?

1 Posts
1 Users
0 Reactions
32 Views
(@diego_h)
Honorable Member
Joined: 6 months ago
Posts: 313
Topic starter   [#14635]

We're starting to use AI coding assistants (like GitHub Copilot) in our team. Our CI pipeline has SAST scans for pull requests, which is great.

But I'm worried about code generated directly in the IDE by these agents. It might not go through a PR and could bypass our security gates. How are teams ensuring this agent code is held to the same standard? Is it just about making sure all code, however it's written, eventually gets scanned in the pipeline, or are there better practices?


Still learning.


   
Quote