Skip to main content

Static Analysis & Scanning

How automated tools inspect code without running it.

  • Static Analysis & Scanning5 min read

    SAST vs DAST: What's the Difference?

    SAST scans source code without running the app; DAST tests a live application by sending real inputs. Both are necessary — they catch different vulnerability classes at different lifecycle stages.

  • Static Analysis & Scanning4 min read

    What is a Linter?

    A linter is a static analysis tool that flags programming errors, style violations, and suspicious constructs in source code — typically enforcing a team's coding standards automatically.

  • Static Analysis & Scanning5 min read

    What is an Abstract Syntax Tree (AST)?

    An abstract syntax tree (AST) is a tree representation of source code structure that enables static analysis tools, compilers, and linters to understand and transform code programmatically.

  • Static Analysis & Scanning5 min read

    What is Dynamic Analysis?

    Dynamic analysis tests software by executing it and observing its runtime behavior — finding bugs, performance issues, and security vulnerabilities invisible to static inspection.

  • Static Analysis & Scanning5 min read

    What is Fuzzing?

    Fuzzing automatically generates large volumes of unexpected inputs to find crashes, security vulnerabilities, and edge-case bugs that manual testing and static analysis miss.

  • Static Analysis & Scanning4 min read

    What is Hybrid Code Analysis?

    Hybrid code analysis combines static and dynamic techniques to find vulnerabilities that neither approach catches alone — improving precision and reducing false positives.

  • Static Analysis & Scanning4 min read

    What is Reachability Analysis?

    Reachability analysis determines whether a vulnerable code path or dependency can actually be reached in a running application — reducing false positives by separating theoretical from exploitable vulnerabilities.

  • Static Analysis & Scanning4 min read

    What is SARIF?

    SARIF (Static Analysis Results Interchange Format) is an open standard for representing static analysis output — enabling tools, CI systems, and dashboards to exchange findings in a common format.

  • Static Analysis & Scanning5 min read

    What is SAST (Static Application Security Testing)?

    SAST is a static analysis technique that scans source code for security vulnerabilities without running the application — catching issues like injection flaws and hardcoded secrets early.

  • Static Analysis & Scanning5 min read

    What is SCA (Software Composition Analysis)?

    SCA identifies open-source dependencies in your codebase and checks them for known CVEs, license risks, and supply chain vulnerabilities — covering the code you did not write.

  • Static Analysis & Scanning5 min read

    What is Static Code Analysis?

    Static code analysis examines source code without executing it to find bugs, vulnerabilities, and quality issues — the foundation of automated code review pipelines.

  • Static Analysis & Scanning5 min read

    What is Taint Analysis?

    Taint analysis tracks how untrusted user input flows through a program to identify injection vulnerabilities — the foundational technique behind most SAST security scanners.

Start free

Build what you're proud to ship.

Bring a Codebase Architect to your AI-native engineering workflow.

Start free

Hyrax is free to start. Full product, $30 starter credit, $10/month of credits. No credit card.