
TL;DR
Static application security testing (SAST) tools have been enhanced with large language models (LLMs), but many may not offer true innovation. Checkmarx has developed a new SAST engine that focuses on orchestration, improving the process after initial scanning.
✦ Why It Matters
Engineers can leverage Checkmarx's orchestration-focused SAST engine to improve vulnerability management and remediation efficiency.
Key Takeaways
How It Works
The new SAST engine operates by combining a deterministic rules-based scanner with an LLM and a FAE. The deterministic scanner ensures reliable results, while the LLM provides rapid language coverage.
The FAE filters findings to classify true and false positives, allowing developers to focus on genuine issues.
Related