SAST (Static Application Security Testing) Category Direction
<!-- triage-serverless v3 PLEASE DO NOT REMOVE THIS SECTION --> *This page may contain information related to upcoming products, features and functionality. It is important to note that the information presented is for informational purposes only, so please do not rely on the information for purchasing or planning purposes. Just like with all projects, the items mentioned on the page are subject to change or delay, and the development, release, and timing of any products, features, or functionality remain at the sole discretion of GitLab Inc.* <!-- triage-serverless v3 PLEASE DO NOT REMOVE THIS SECTION --> ## SAST ~"group::static analysis" ~"Category:SAST" Static Application Security Testing scans the application source code and binaries to spot potential vulnerabilities before deployment using open source tools that are installed as part of GitLab. Vulnerabilities are shown in-line with every merge request and results are collected and presented as a single report. This category is at the "viable" level of maturity. * [Documentation](https://docs.gitlab.com/ee/user/application_security/sast/) * [Direction](https://about.gitlab.com/direction/secure/static-analysis/sast/) * Priority: high * Current ~"maturity::viable" * PM Owner: @tmccaslin
epic