---
id: sast
requestedLanguage: en
descriptionLanguage: en
---

# Static Application Security Testing

- Type: security testing technique
- Group: Security
- Placement: Security
- [Source](<https://devguide.owasp.org/en/02-foundations/02-secure-development/>)

[HTML](https://dpm.cnonim.name/practices/sast/)

Analyze source code or build artifacts without running the application to find potential vulnerabilities.

## Relationships

- is a specialization of: [Static Analysis](/practices/static/en.md) (structure)
- checks some rules from: [Secure Coding Practices](/practices/securecoding/en.md) (verification)
- complements: [Dynamic Application Security Testing](/practices/dast/en.md) (combination)
- analyzes code and complements: [Software Composition Analysis](/practices/sca/en.md) (combination)

[Show on the map](https://dpm.cnonim.name/#practice=sast&lang=en)
