Skip to content

What is SAST (Static Application Security Testing)?

Last updated

SAST is a category of security testing that analyzes source code, bytecode, or binaries for security vulnerabilities without executing the application. It's also called 'white-box testing' because it has access to the full source code. SonarQube, Checkmarx, and Semgrep are common SAST tools.

Why does SAST (static application security testing) matter for engineering teams?

SAST catches known vulnerability categories (injection flaws, authentication bypasses, insecure deserialization) before code reaches production. It's fast, automatable, and fits naturally into CI pipelines. However, SAST output can be noisy with false positives, and it can't reason about runtime security properties.

How does Argus handle SAST (static application security testing)?

Argus bundles a SAST pre-pass but is not a full SAST product. Its backend image includes staticcheck, ESLint, and Semgrep; they run on the changed files before the LLM review, and up to 10 results per file go into the review prompt for the model to confirm or discard. SAST results are never posted on their own, and the ESLint pass ignores the repo's config. On Deep Review, a finding within 3 lines of a SAST result gets a judge score floor of 75. Files on auth, token, session, and similar paths get a security-focused review pass. Argus does not check dependency versions against vulnerability databases, so keep a dedicated scanner if you need that or custom rule policies.

Run Argus on your own repositories

Open source under AGPL-3.0, with no paid tier and no feature gating.

Self-hosted only: Docker Compose or Fly.io, Postgres with pgvector, a GitHub App and a Clerk app you create, your model keys and an embeddings endpoint.