Lesson 20 / 23
Security Scanning in a Pipeline
Add dependency and static-analysis scanning to pipelines and tune severity thresholds so teams do not bypass them.
What gets scanned
Dependency scanning checks third-party packages against known-vulnerability databases. Static analysis (SAST) scans your own code for risky patterns like SQL injection or hardcoded secrets, without running it.
Where it fits in the pipeline
Scans usually run alongside or right after tests — early enough to block a bad merge, before the deploy stage spends time on something that shouldn't ship.
Tune severity, don't ignore it
Blocking on every low-severity finding trains teams to bypass the scanner. Fail the build on critical/high issues, and track lower ones without stopping delivery.