Shift Left Security: SAST, SCA, and Vault
Learn to catch code and dependency flaws early with SAST and SCA, prioritise fixes with CVSS and EPSS, and replace static secrets with Vault.
What You'll Learn
Understanding Why Earlier Is Cheaper
The same flaw found twice A developer on the acme-shop payments team writes a search endpoint that builds a SQL query by joining strings with user...
Understanding How SAST Finds Vulnerabilities
Tracing tainted data from source to sink SAST analyses source code without running it.
Running SAST with Semgrep in CI
Running Semgrep locally and reading a finding Semgrep is a fast open-source SAST tool whose rules look like the code they match, which makes them...
Adding SonarQube Quality Gates
Running SonarQube and creating a project SonarQube is a SAST and code quality platform with a dashboard, trend history, and quality gates.
Scanning Dependencies with Dependabot and Snyk
Why dependencies are most of your code The libraries you install are code you did not write, review, or monitor.
Running OWASP Dependency-Check Without a SaaS
When to choose it OWASP Dependency-Check is a free, self-hosted SCA tool.
Skills You'll Master
Curriculum Index10 topics
Understanding Why Earlier Is Cheaper
The same flaw found twice A developer on the acme-shop payments team writes a search endpoint that builds a SQL query...
Understanding How SAST Finds Vulnerabilities
Tracing tainted data from source to sink SAST analyses source code without running it.
Running SAST with Semgrep in CI
Running Semgrep locally and reading a finding Semgrep is a fast open-source SAST tool whose rules look like the code...
Adding SonarQube Quality Gates
Running SonarQube and creating a project SonarQube is a SAST and code quality platform with a dashboard, trend history...
Scanning Dependencies with Dependabot and Snyk
Why dependencies are most of your code The libraries you install are code you did not write, review, or monitor.
Running OWASP Dependency-Check Without a SaaS
When to choose it OWASP Dependency-Check is a free, self-hosted SCA tool.
Prioritising Findings with CVSS and EPSS
Reading a CVSS score A scanner on a real project can report hundreds of findings, and you cannot fix them all today.
Replacing Static Secrets with Vault Dynamic Credentials
Static versus dynamic secrets A typical database password is created once and copied into CI secrets, .env files...
Hands-on Lab: Scan, Fix, and Issue Dynamic Secrets
Before you start You need Docker, Git, and Node.js with npm installed, about 6 GB of free memory for SonarQube, and...
Quick Reference and Common Mistakes
Quick reference Common mistakes Blocking every merge on every SAST finding trains developers to bypass the tool.
Career Impact
Roles that use the skills in this module.
- High Demand
DevSecOps Engineer
₹12L - ₹30L a year
- Growing
Application Security Engineer
₹14L - ₹32L a year
- High Demand
DevOps Engineer
₹8L - ₹22L a year
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
It means moving security checks earlier in the development process, to the editor, the commit, and the pull request, instead of leaving them to a late audit. A flaw caught while the code is fresh is cheaper and quicker to fix than one found after release.
SAST scans the code your team wrote for vulnerable patterns such as SQL injection. SCA scans the third-party libraries you depend on for known CVEs. You need both, because most of the code in a modern application is not code you wrote.
No. CVSS measures how severe a flaw is if exploited, not how likely exploitation is. Combine it with EPSS, which estimates the chance of exploitation in the next 30 days, and with whether the flaw appears on CISA's Known Exploited Vulnerabilities list.
A stored password is shared, long-lived, and hard to rotate. A dynamic credential is created on request, unique to one consumer, and revoked automatically when its lease ends, so a leaked copy stops working quickly.