Skip to content

Conversation

@ahmadnassri
Copy link

in:

  • _data/tools.js
  • pages/Component_Analysis.md
  • pages/Free_for_Open_Source_Application_Security_Tools.md

@github-actions
Copy link

The following issues were identified, when validating against the schema:

Summary (click the triangle/control to the left to expand)
_data/tools.json invalid
data/0/license must be equal to one of the allowed values

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These just don't belong in these lists. A WAF is not a DAST. An SCA tool is not a SAST.

Copy link
Author

@ahmadnassri ahmadnassri Oct 10, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thx, will update with more info to clarify, Socket has SAST support now.

and the "firewall" is actually doing dynamic analysis at run-time of package install to determine malicious ones to block...

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A firewall is not DAST by any definition I've ever seen! DAST involves dynamic testing, which means interacting with the target, typically by sending payloads.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants