Notifications
Clear all
SAST & Dependency Scanning
1
Posts
1
Users
0
Reactions
1
Views
Topic starter
18/07/2026 4:36 pm
Everyone jumps straight to the full scan. That's a mistake. You'll drown in noise, waste cycles, and your team will start ignoring the results before you even start.
Don't scan everything. Start with a baseline. I only scan new commits against the main branch. For dependencies, I run a diff on the lockfile. This cuts initial results by 70-80%. You fix the bleeding edge, not the entire history. Get that process solid, then expand scope. Most tools can do this with a few config lines, but they don't advertise it because they're paid per line of code scanned.