पाठ 22 / 25
Security Testing
SAST, DAST, SCA and pentests.
Layers of automated and manual testing
SAST (static analysis, such as Semgrep or CodeQL) finds risky code patterns before running it. SCA finds vulnerable dependencies. DAST (dynamic testing, such as OWASP ZAP) probes a running application for issues like missing headers and injection. Secret scanning catches leaked credentials. Automated tests for authorisation rules catch access control regressions. Periodic penetration tests and bug bounty programmes find business-logic flaws automation misses. Test only systems you own or are authorised to test.
Security as a habit
Testing, review, error handling and a checklist make security part of everyday engineering.
Security checks in a pipeline
An example stage list.
on every pull request:
- SAST (Semgrep / CodeQL) on changed code
- dependency scan (npm audit / pip-audit / Trivy)
- secret scan (gitleaks)
- unit + authorisation tests (user A cannot read user B's data)
nightly / pre-release:
- DAST baseline scan (OWASP ZAP) against staging
- container image scan; IaC scan
periodically:
- penetration test; threat model review for new featuresTriage findings, do not just collect them
Assign owners and deadlines by severity; a growing pile of ignored findings is a risk in itself.
त्वरित जाँच: What does DAST test?
- Only passwords
- Source code without running it
- Only dependencies
- A running application, from the outside
Answer
A running application, from the outside — Dynamic application security testing.