FortiDevSec for SAST Scans
Static Application Security Testing
FortiDevSec scans source code of an application during development to minimalize zero-day vulnerabilities

“White box security testing”

Find Security issues in application source code

Ensure secure coding guidelines

No need to build or execute underlying code

Catch bugs that are not known elsewhere

Complements OSS and infrastructure vulnerabilities

Help DevOps secure apps without slowing them down

SAST scan runs on every build

Find bugs introduced by Developers

Fix bugs during DevOps process
Supported App Languages
Java
Ruby
JavaScript
Python
Gosec
PHP
NodeJS
C/C++