Latest updates for Static-Code-Analysis
Fresh curated links around static-code-analysis are collected here so marketers can spot useful updates and turn timely ideas into posts faster.
Recent items include:
- Static Application Security Testing (SAST)
- Code Review From the Terminal and CI, No MCP Client Required
- There are 755 static-analysis tools. Only 42 are open-source security scanners.
Post angles to try
Fresh articles and ideas
Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.
Code Review From the Terminal and CI, No MCP Client Required
A month ago I shipped aicraft-code-review, an MCP server that reviews code locally. This week I added a CLI mode — because not everyone wants to wire up an MCP client just to che...
There are 755 static-analysis tools. Only 42 are open-source security scanners.
If you run a linter on your code today, you have a lot of choices. If you want one that actually looks for security bugs — and is open source — you have far fewer than the ecosyste...
archcheck — на страже архитектуры C++
Открытый чекер архитектуры C++ для CI: циклы, копипаст, распухшие заголовки — в каждом PR. Плюс замер на 484 500 коммитов в поисках архитектурного дрейфа Почему ревью это пропустил...
AI SAST: Code Security for the Agentic SDLC
Endor Labs has launched an AI-powered Static Application Security Testing (SAST) tool for C code that detects more vulnerabilities than traditional scanners without requiring a sof...
Automate Tech Debt Audits with Claude Code
Over the years, we have written about many of the tools we use: Skunk for combining code quality and code coverage data, bundler-audit for security vulnerabilities in your dependen...
Композиционный анализ проектов на C++
Композиционный анализ (Software Composition Analysis, SCA) – это практика автоматического выявления и отслеживания внешних зависимостей проекта с целью мониторинга их известных уяз...
What Is Static Testing: Its Features And Best Practices
Static testing, a non-execution method, reviews code for errors, enhancing quality and preventing issues before execution.
Why DAST Findings Are Hard to Fix and How to Make Them Actionable
Dynamic testing is essential because it uncovers vulnerabilities in running applications. But while SAST gets the attention because it’s shift-left and relatively straightforward t...
Как внедрить требования к безопасной разработке кода: опыт Staffcop
Безопасная разработка для Staffcop (системы расследования инцидентов внутренней инфобезопасности) — это не отдельная проверка перед релизом, а процесс, который команда постепенно в...
Black Duck Extends Scope and Reach of Code Scanning Tool
Black Duck has updated its Coverity static analysis code scanning tool to provide deeper integrations with artificial intelligence (AI) tools along with updates to its user interfa...
Automate Your Tech Debt Audits with Claude Code
Originally appeared on The Rails Tech Debt Blog.Today I’m excited to share a new open source project: A Claude Code skill to assess technical debt in a Ruby on Rails application. I...
Ваш AI-агент не понимает код. Он просто очень уверенно угадывает — поэтому мы создали SLICER
AI-агенты отлично решают локальные задачи, но часто теряют связи между частями большой кодовой базы. Из-за этого изменение одной функции может незаметно сломать frontend, backend-р...
Applying Checkov SAST to Detect Security Issues in Terraform Infrastructure as Code
Introduction Security issues in cloud infrastructure often start as small configuration mistakes. A public network rule, a missing encryption setting, or an overly permissive pol...
Мост между SAST и фаззингом: как из сработки SAST получить подтверждённую уязвимость
Инструменты статического анализа (SAST) лишь подсвечивают вероятные уязвимости, генерируя гипотезы. Динамическое тестирование (DAST) и фаззинг, напротив, выявляют реальные сбои на...
I ran my Solidity scanner on 6 top-audited DeFi protocols. Every 'critical' was a false positive — here's why.
Most Solidity scanners are high-recall, low-precision. They flag 40 things, 38 are noise, and after the third report you stop reading them — so the one real bug ships. Precision, n...
9 Best Agentic Coding CLI Tools for 2026
Compare the 9 best agentic coding CLI tools for 2026 on models, MCP support, open-source licensing, and CI fit, from Claude Code and Gemini CLI to Aider.
Audition is a linter/fixer that gets your code Ractor-ready
Vibe coded a useful thing for Rubyists over the weekend. Audition is a linter/fixer that gets your code Ractor-ready: static analysis powered by Shopify’s rubydex, plus dynamic pro...
What Is Code Review: Top Tools to Elevate Software Quality
Learn what is code review & its importance in software development. Explore the best code review tools available, to enhance your project's quality.
Measuring Test Code Coverage For Non-Ruby Runners
Originally appeared on The Rails Tech Debt Blog.When we think about Ruby code coverage, our go-to gem for this is SimpleCov, which works great when the test suite uses Minitest, RS...
Turn fresh research into a full content calendar
Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.