Static Application Security Testing (SAST) is used to identify vulnerabilities in custom application code and is often used early in the lifecycle before the application can be run.
Application code dependencies like open source libraries comprise approximately 80-90% of modern application codebases. Organizations that aren’t scanning these dependencies for vulnerabilities aren’t securing their applications.