Local SAST for Developers and CI
Developer-first static application security testing that scans source locally, emits SARIF for GitHub code scanning, and gives coding agents deterministic fix context.
radar scan . --quickSAST without another source upload
Run security checks in the developer workspace or GitHub Actions runner. Radar focuses on merge-blocking findings such as injection, unsafe auth, path traversal, secrets, and risky APIs.
- Local scan engine
- No hosted project setup
- Severity thresholds
- File-level evidence
Evidence to inspect
Use “Local SAST for Developers and CI” as the scope for this decision: verify the input, finding detail, workflow handoff, and product boundary before you install or buy.
Run this check locally
Built for the review loop
The same scanner supports local CLI review, agent repair prompts, and CI gates, so findings keep the same shape before and after a pull request exists.
radar scan . --quick
radar prompt . --diff --copy
radar scan . --format sarif --fail-on highPrimary sources
Validate the workflow on your own code.
Apply this page’s evidence to one real repository. For “Local SAST for Developers and CI”, confirm which finding is produced, whether the proposed next step is reproducible, and where local scanning, reports, agents, or CI should stop or expand.