Coverage and concrete signals
For Static code analysis, inspect the concrete scope below instead of relying on a category label. File and line locations, rule identifiers, severity, confidence, and portable SARIF evidence.
- Focus: Insecure APIs, injection paths, hardcoded secrets, and structural review debt in source files.
- Workflow: Workflow: source patterns · insecure APIs · secrets · SARIF
- Coverage and concrete signals: source patterns, insecure APIs, secrets, SARIF
FocusExact file location, rule context, severity, confidence, and remediation guidance.Boundary
Insecure APIs, injection paths, hardcoded secrets, and structural review debt in source files.File and line locations, rule identifiers, severity, confidence, and portable SARIF evidence.Static checks do not observe runtime configuration, production traffic, or exploitability without human review.