FortiDevSec for SAST Scans

Static Application Security Testing

FortiDevSec scans source code of an application during development to minimalize zero-day vulnerabilities

sast box

“White box security testing”

sast file

Find Security issues in application source code

sast book

Ensure secure coding guidelines

sast build

No need to build or execute underlying code

sast bug

Catch bugs that are not known elsewhere

sast find

Complements OSS and infrastructure vulnerabilities

infinity loop

Help DevOps secure apps without slowing them down

target

SAST scan runs on every build

developers

Find bugs introduced by Developers

infinity loop

Fix bugs during DevOps process

Supported App Languages

java language

Java

ruby language

Ruby

javascript language

JavaScript

python language

Python

golang language

Gosec

php language

PHP

nodeJS language

NodeJS

c language

C/C++