# Security Scanning in a Pipeline — CI/CD Fundamentals: Pipelines, Testing and Deployment

Source: https://www.skillbyai.com/en/cicd/cicd-security-scanning

> Add dependency and static-analysis scanning to pipelines and tune severity thresholds so teams do not bypass them.

## What gets scanned

**Dependency scanning** checks third-party packages against known-vulnerability databases. **Static analysis (SAST)** scans your own code for risky patterns like SQL injection or hardcoded secrets, without running it.

## Where it fits in the pipeline

Scans usually run alongside or right after tests — early enough to block a bad merge, before the deploy stage spends time on something that shouldn't ship.

## Tune severity, don't ignore it

Blocking on every low-severity finding trains teams to bypass the scanner. Fail the build on critical/high issues, and track lower ones without stopping delivery.
