Home / Companies / Sonar / Blog / Post Details
Content Deep Dive

Find Deeply Hidden Security Vulnerabilities with Deeper SAST by Sonar

Blog post from Sonar

Post Details
Company
Date Published
Author
Johannes Dahse
Word Count
1,054
Company Posts That Month
6
Language
English
Hacker News Points
-
Post removed?
No
Summary

Sonar's innovative analysis technology, deeper SAST, detects deeply hidden code vulnerabilities by extending its taint analysis to cover the interaction of first-party code with dependencies. This enables unique insights into security side effects of dependent code and helps find vulnerabilities missed by traditional SAST and SCA tools. Deeper SAST evaluates all security-sensitive interactions between a project's code and its dependent code without any additional configuration or major performance overhead. A real-world example of a critical vulnerability in Jenkins, CVE-2024-23897, demonstrates the importance of deeper SAST for finding hidden vulnerabilities that can have significant consequences if left unaddressed.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.