SAST workflow

Overview of steps for static analysis scanning.

The general steps for performing static analysis are as follows. Additional steps may be required to meet your scanning goals.

Note: Users must be assigned an appropriate role to perform static analysis functions. If you are unsure whether your user role has appropriate permissions, consult your organization's ASoC Administrator.
  1. Create an application.
  2. Decide which mechanism you will use to prepare files for scanning and set it up accordingly:
  3. Generate an IRX using your preferred method.
  4. Create and configure a scan.
  5. Review scan preferences.
  6. Run the scan.
  7. Review results.
  8. Triage and remediate issues.
  9. Repeat steps three through eight as needed.