> For the complete documentation index, see [llms.txt](https://asafahmadov.gitbook.io/devsecops/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://asafahmadov.gitbook.io/devsecops/1.-devsecops-the-big-picture/designing-devsecops-for-plan-code-and-build-sdlc-phases/sast-and-sca-code.md).

# SAST and SCA - CODE

Now let's move on to the coding section of the CI/CD life cycle.

<mark style="background-color:blue;">**Static Application Security Testing (SAST)**</mark> - Examines source code to identify weaknesses that can lead to security vulnerabilities. Think of it as a source code review and testing off the source code itself.

<mark style="background-color:blue;">**Software Composition Analysis (SCA)**</mark> is quite different. This is a process that looks at the open-source components that make up your software and checks all of these components against known vulnerabilities.

#### ⭕ Features of SAST

&#x20;    ▪ Reads source code

&#x20;    ▪ Language-specific scanner

&#x20;    ▪ False positives

&#x20;    ▪ Fast and automated

&#x20;    ▪ Finds weaknesses early&#x20;

{% hint style="info" %}
NIST list of source code security analyzers&#x20;

<https://samate.nist.gov/index.php/Source\\_Code\\_Security\\_Analyzers.html>
{% endhint %}
