태그: #sast
GPU·LLM·MLOps·쿠버네티스, 그리고 마음가짐에 관한 글 · 3 편
코드 품질 & 정적 분석 2026 완벽 가이드 — SonarQube · CodeClimate · Codacy · DeepSource · Qodo Cover · Snyk Code · Semgrep · ESLint 심층 분석
2026년 5월 기준 코드 품질·정적 분석(SAST) 생태계를 한 글로 정리합니다. SonarQube 10.x·SonarCloud·CodeClimate·Codacy·DeepSource·Qodana·Qodo Cover 같은 플랫폼, Semgrep 1.x·CodeQL·Snyk Code·Veracode·Checkmarx 같은 SAST 엔진, ESLint 9 flat config·Biome·Oxli
2026-05-16 · 36 분 읽기 #code-quality#static-analysis#sonarqube#codeclimate#codacy정적 분석 / SAST 2026 — Semgrep / CodeQL / Snyk / SonarQube / Aikido / Trivy 심층 비교
2026년 코드 보안 도구 지도를 그린다 — Semgrep(오픈소스 SAST의 표준 + Pro engine과 Supply Chain), CodeQL(GitHub Advanced Security의 핵심, dataflow 강자), Snyk Code(DeepCode AI 통합 이후의 SAST+SCA), SonarQube 11(클래식이 살아남는 법), Aikido Security(올인원 신예 + A
2026-05-15 · 40 분 읽기 #security#sast#static-analysis#semgrep#codeqlDevSecOps 완전 가이드 2025: Shift-Left 보안, SAST/DAST/SCA, 컨테이너 보안까지
DevSecOps의 모든 것! Shift-Left 보안 전략, SAST(SonarQube/Semgrep), DAST(ZAP/Burp), SCA(Snyk/Dependabot), 컨테이너 보안(Trivy), 공급망 보안(SBOM/SLSA), Secret 탐지, GitHub Actions 보안 파이프라인.
2026-03-24 · 29 분 읽기 #devsecops#security#shift-left#sast#dast