Static Application Security Testing (SAST) Software Resources
Articles, Discussions, and Reports to expand your knowledge on Static Application Security Testing (SAST) Software
Resource pages are designed to give you a cross-section of information we have on specific categories. You'll find articles from our experts, discussions from users like you, and reports from industry data.
Static Application Security Testing (SAST) Software Articles
What Is Static Code Analysis? Assure Quality With Automation
Finding needles in a haystack.
Nothing defines finding errors in a large codebase than this. When building a software application, finding and eliminating errors can easily take the longest.
by Tanuja Bahirat
2023 Trends in DevSecOps Software
This post is part of G2's 2023 digital trends series. Read more about G2’s perspective on digital transformation trends in an introduction from Emily Malis Greathouse, director, market research, and additional coverage on trends identified by G2’s analysts.
by Adam Crivello
G2 Launches Interactive Application Security Testing (IAST) Software Category
The DevSecOps software space continues to evolve as product development teams work to adopt “secure by default” delivery strategies. In February 2022, G2 launched its Interactive Application Security Testing (IAST) Software category to represent a key testing approach.
by Adam Crivello
What Is SAST? How It Helps Develop Secure Applications
Modern businesses understand the value of data and its security.
by Sagar Joshi
What Is DevSecOps, and How Is It Different from DevOps?
The golden age of DevOps software best practices has settled upon us like a cozy blanket of consistency. Within this utopia of perfect change management and well-oiled industry standards, a natural progression toward airtight cybersecurity called DevSecOps emerged.
by Adam Crivello
SAST vs. DAST: Application Security Testing Explained
As a result of the booming cloud application market, companies are increasingly — and rationally — concerned with the security of their applications and the data associated with them.
by Aaron Walker
Static Application Security Testing (SAST) Software Discussions
0
Question on: Kiuwan Code Security & Insights
What programming languages are supported by Kiuwan?Kiuwan supports more than 30 programming languages.
Please visit Kiuwan Supported Technologies to view the list of languages supported by Kiuwan so far.
For other languages not included, please contact Kiuwan Technical Support.
Show More
Show Less
0
Question on: Kiuwan Code Security & Insights
How does Kiuwan help me to make decisions on how to fix my application?Once you have obtained security and quality metrics and defects of your application, the most probably questions you will have will be some of the following:
- Where should I start to improve?
- How much time does it take me to repair each one of them?
- Which are the optimal path and action plan to reach my quality goals?
- I only have 20 hours to fix errors before the next delivery. What should I fix to aim the best possible quality?
Kiuwan provides a module to create Action Plans, i.e. a concrete and defined set of goals and actions to be performed on your application. Once defined, you will be able to share it (by exporting to PDF or as Jira issues) and track progress based on analysis results.
In order to create an Action Plan, you can follow two different approaches.
Show More
Show Less
0
Question on: Kiuwan Code Security & Insights
Which are the main Indicators provided by Kiuwan? Kiuwan provides indicators for:
Software characteristics
Security, efficiency, maintainability, reliability and portability
Global Indicator
It is calculated as weighted average of the above software characteristics through a complex algorithm that has into account the severity of the defects, the weight of the category in which the defect is, the analyzed code volume and the criticality of the language for Kiuwan user. Kiuwan allows to “customize” this algorithm by modifying its level of demand, the weights of the category and the priority of the rules.
Effort to Target
The amount of work effort needed to reach the defined goal. Objectives are defined at application level. These objectives are configurable. CQM has a repair effort assigned for each one of the more than 4,000 rules it incorporates. The sum of the repair efforts of each defect indicates the time needed to reach the targets.
Risk Index
It is a summary index that concentrates all evidence found in the application source code and could be understood as the risk associated to the software defects found related to defined goals and effort to reach them. See below for further details.
Show More
Show Less
Static Application Security Testing (SAST) Software Reports
Mid-Market Grid® Report for Static Application Security Testing (SAST)
Spring 2026
G2 Report: Grid® Report
Grid® Report for Static Application Security Testing (SAST)
Spring 2026
G2 Report: Grid® Report
Enterprise Grid® Report for Static Application Security Testing (SAST)
Spring 2026
G2 Report: Grid® Report
Momentum Grid® Report for Static Application Security Testing (SAST)
Spring 2026
G2 Report: Momentum Grid® Report
Small-Business Grid® Report for Static Application Security Testing (SAST)
Spring 2026
G2 Report: Grid® Report
Enterprise Grid® Report for Static Application Security Testing (SAST)
Winter 2026
G2 Report: Grid® Report
Small-Business Grid® Report for Static Application Security Testing (SAST)
Winter 2026
G2 Report: Grid® Report
Mid-Market Grid® Report for Static Application Security Testing (SAST)
Winter 2026
G2 Report: Grid® Report
Grid® Report for Static Application Security Testing (SAST)
Winter 2026
G2 Report: Grid® Report
Momentum Grid® Report for Static Application Security Testing (SAST)
Winter 2026
G2 Report: Momentum Grid® Report






