Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

A Google Summer of Code project: creating a benchmarking framework for SAST

Blog post from GitLab

Post Details
Company
Date Published
Author
Michael Henriksen and Martynas Krupskis and Mark Art and Dinesh Bolkensteyn and Isaac Dawson and Julian Thome
Word Count
1,790
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

In summer 2022, GitLab's Vulnerability Research team initiated a Google Summer of Code (GSoC) project aimed at developing a benchmarking framework for Static Application Security Testing (SAST) tools. This framework is designed to evaluate the impact and quality of security analyzers and configuration changes before they are deployed in production environments. The project leverages GitLab's integrated SAST tools, which are encapsulated in Docker images, to translate tool-native vulnerability reports into a standardized format for easier comparison. The benchmarking framework is built to assess the efficacy of these analyzers using a baseline of expected vulnerabilities, allowing for data-driven decision-making and performance monitoring over time. The framework focuses on five key characteristics: relevance, reproducibility, fairness, verifiability, and usability, and aims to be language-agnostic, enabling integration of new SAST tools with minimal configuration. The project establishes baselines for applications written in popular languages and frameworks, such as Java's Spring and Python's Flask, to ensure practical utility. The initiative marks a significant step towards creating a free and open-source software (FOSS) benchmarking framework, encouraging community involvement to expand its scope across more languages and frameworks in the future.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.