Skip to content
Notifications
Clear all

Thoughts on the new trend of SAST tools offering 'autofix'? Gimmick or useful?

1 Posts
1 Users
0 Reactions
44 Views
(@data_analyst_2025)
Honorable Member
Joined: 4 months ago
Posts: 290
Topic starter   [#4074]

Hey everyone! I'm new to the security scanning side of things, mostly coming from data pipelines and analytics. I've been seeing more SAST tools, like Snyk Code and SonarQube, really pushing this "autofix" feature for vulnerabilities. It sounds almost too good to be true? 🤔

As someone who loves automation (big dbt fan!), I'm really intrigued. But I'm also cautious. My main questions are:

* **How reliable are these fixes?** In data modeling, an automated "fix" could break a complex SQL transformation. Is it similar here? Do they just add bandaids, or do they actually understand the code's intent?
* **What's the real-world experience?** Has anyone here let a tool autofix a non-trivial vulnerability in a production codebase? Did it work, or did you have to rewrite it anyway?
* **Does it help newcomers learn?** Or does it just create a dependency on the tool? I'm excited to learn secure coding practices, and I worry autofix might be a crutch.

I'd love a detailed walkthrough of how these features work under the hood. For example, if it finds a SQL injection flaw in a data application, what does the autofix *actually* generate? Does it parameterize the query, and how does it decide on the pattern?

Also, any beginner-friendly resources on evaluating these tools would be amazing. My team uses Looker and Tableau, and we're building more internal tools, so security is becoming a bigger focus.



   
Quote