Skip to main content

Shift Left Security: SAST, SCA, and Vault

Learn to catch code and dependency flaws early with SAST and SCA, prioritise fixes with CVSS and EPSS, and replace static secrets with Vault.

Prerequisites
~3.5 hours
10 Topics
Hands-on Scenarios

What You'll Learn

Understanding Why Earlier Is Cheaper

The same flaw found twice A developer on the acme-shop payments team writes a search endpoint that builds a SQL query by joining strings with user...

Understanding How SAST Finds Vulnerabilities

Tracing tainted data from source to sink SAST analyses source code without running it.

Running SAST with Semgrep in CI

Running Semgrep locally and reading a finding Semgrep is a fast open-source SAST tool whose rules look like the code they match, which makes them...

Adding SonarQube Quality Gates

Running SonarQube and creating a project SonarQube is a SAST and code quality platform with a dashboard, trend history, and quality gates.

Scanning Dependencies with Dependabot and Snyk

Why dependencies are most of your code The libraries you install are code you did not write, review, or monitor.

Running OWASP Dependency-Check Without a SaaS

When to choose it OWASP Dependency-Check is a free, self-hosted SCA tool.

Skills You'll Master

SASTSCASONARQUBEVAULTSHIFT-LEFT

Curriculum Index10 topics

1

Understanding Why Earlier Is Cheaper

The same flaw found twice A developer on the acme-shop payments team writes a search endpoint that builds a SQL query...

2

Understanding How SAST Finds Vulnerabilities

Tracing tainted data from source to sink SAST analyses source code without running it.

3

Running SAST with Semgrep in CI

Running Semgrep locally and reading a finding Semgrep is a fast open-source SAST tool whose rules look like the code...

4

Adding SonarQube Quality Gates

Running SonarQube and creating a project SonarQube is a SAST and code quality platform with a dashboard, trend history...

5

Scanning Dependencies with Dependabot and Snyk

Why dependencies are most of your code The libraries you install are code you did not write, review, or monitor.

6

Running OWASP Dependency-Check Without a SaaS

When to choose it OWASP Dependency-Check is a free, self-hosted SCA tool.

7

Prioritising Findings with CVSS and EPSS

Reading a CVSS score A scanner on a real project can report hundreds of findings, and you cannot fix them all today.

8

Replacing Static Secrets with Vault Dynamic Credentials

Static versus dynamic secrets A typical database password is created once and copied into CI secrets, .env files...

9

Hands-on Lab: Scan, Fix, and Issue Dynamic Secrets

Before you start You need Docker, Git, and Node.js with npm installed, about 6 GB of free memory for SonarQube, and...

10

Quick Reference and Common Mistakes

Quick reference Common mistakes Blocking every merge on every SAST finding trains developers to bypass the tool.

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

    ₹12L - ₹30L a year

    High Demand
  • Application Security Engineer

    ₹14L - ₹32L a year

    Growing
  • DevOps Engineer

    ₹8L - ₹22L a year

    High Demand
See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

It means moving security checks earlier in the development process, to the editor, the commit, and the pull request, instead of leaving them to a late audit. A flaw caught while the code is fresh is cheaper and quicker to fix than one found after release.

SAST scans the code your team wrote for vulnerable patterns such as SQL injection. SCA scans the third-party libraries you depend on for known CVEs. You need both, because most of the code in a modern application is not code you wrote.

No. CVSS measures how severe a flaw is if exploited, not how likely exploitation is. Combine it with EPSS, which estimates the chance of exploitation in the next 30 days, and with whether the flaw appears on CISA's Known Exploited Vulnerabilities list.

A stored password is shared, long-lived, and hard to rotate. A dynamic credential is created on request, unique to one consumer, and revoked automatically when its lease ends, so a leaked copy stops working quickly.