Skip to content

Add Prerequisite/ TECH about Detecting Sensitive Data in SAST #3327

@cpholguera

Description

@cpholguera

We should have a general section that explains how sensitive data is 'used' in SAST.

There's two general solutions: search for sink APIs and figure out if sensitive data goes into them, or define sources (sensitive data) and see where they flow. I would think these static checks just focus on sinks?

Originally posted by @TheDauntless in #3289 (comment)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions