Barriers to Using Static Application Security Testing (SAST) Tools: A Literature Review
A systematic literature review catalogues why developers still underuse SAST tools — false positives, workflow friction, and poor integration — offering a diagnostic checklist for teams trying to improve secure-development adoption.
Summary written by editorial AI · Source link below
arXiv:2609.01669v1 Announce Type: cross Abstract: Developers face a challenging problem with no clear solution. Modern software breaches can wreak havoc on businesses and individuals alike. With code vulnerabilities being a leading cause, securing applications must be a priority for developers. Static Application Security Testing (SAST) has the potential to harden applications by assisting in the identification and resolution of security vulnerabilities. Despite this, many development teams hav
Editorial Analysis
SAST adoption gaps leave code vulnerabilities undetected; understanding and addressing developer friction points is a prerequisite for Secure by Design at scale.
Benchmark your SAST deployment against the identified barrier categories and create a remediation plan for the top three friction points.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the DevSecOps Desk
- Boundary-Mutation Testing for Pattern-Based Secret Detection: A Rule-Level Method and Cross-Scanner Evaluation4d
- PatchBench: Evaluating AI Agents for Vulnerability Patching4d
- Coder's registry infrastructure compromised to push malicious modules4d
- Modelstamp: Pre-Deserialization Verification of Machine-Learning Artifacts and Runtime Environment State5d
- Athena: Vulnerability-Affected Library Identification via Knowledge Graph Completion6d