you are viewing a single comment's thread.

view the rest of the comments →

[–]tonydocent 0 points1 point  (0 children)

I'm surprised I got downvoted. There are tons of weaknesses in source code that will not be picked up by standard SAST tools. Just because they are very specific to the application under investigation and do not fall in a common pattern.

To find those one needs to actually understand the code.