--- id: P-REINFORCE-AUTO-205541 category: "10_Wiki/๐Ÿ’ก Topics/AI" confidence_score: 0.90 tags: [auto-reinforced] last_reinforced: 2026-04-20 github_commit: "[P-Reinforce] Continuous Worker - SAST" --- # [[SAST|SAST]] ## ๐Ÿ“Œ ํ•œ ์ค„ ํ†ต์ฐฐ (The Karpathy Summary) > SAST(Static Application Security Testing, ์ •์  ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ ํ…Œ์ŠคํŠธ)๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์‹คํ–‰ํ•˜์ง€ ์•Š๊ณ  ์†Œ์Šค ์ฝ”๋“œ, ๋ฐ”์ดํŠธ์ฝ”๋“œ ๋˜๋Š” ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ์ •์ ์œผ๋กœ ๋ถ„์„ํ•˜์—ฌ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์ฐพ์•„๋‚ด๋Š” ํ™”์ดํŠธ๋ฐ•์Šค ํ…Œ์ŠคํŠธ ๊ธฐ๋ฒ•์ž…๋‹ˆ๋‹ค [1-3]. ๊ฐœ๋ฐœ ์ดˆ๊ธฐ ๋‹จ๊ณ„์ธ IDE๋‚˜ CI/CD ํŒŒ์ดํ”„๋ผ์ธ์— ํ†ตํ•ฉ๋˜์–ด ๊ฒฐํ•จ์„ ์‚ฌ์ „์— ํ•ด๊ฒฐํ•˜๋Š” '์‹œํ”„ํŠธ ๋ ˆํ”„ํŠธ(Shift-left)' ๋ณด์•ˆ ์ ‘๊ทผ๋ฒ•์˜ ํ•ต์‹ฌ์ ์ธ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค [4-7]. ์ตœ๊ทผ์—๋Š” ๋†’์€ ์˜คํƒ๋ฅ (False Positive)๊ณผ ๋ฌธ๋งฅ ํŒŒ์•…์˜ ํ•œ๊ณ„๋ฅผ ๊ทน๋ณตํ•˜๊ธฐ ์œ„ํ•ด ๋จธ์‹ ๋Ÿฌ๋‹(ML)๊ณผ ๋Œ€๊ทœ๋ชจ ์–ธ์–ด ๋ชจ๋ธ(LLM)์„ ๊ฒฐํ•ฉํ•œ AI ๊ธฐ๋ฐ˜ SAST๋กœ ์ง„ํ™”ํ•˜์—ฌ ๋”์šฑ ์ •ํ™•ํ•œ ํƒ์ง€์™€ ์ž๋™ ์ˆ˜์ •(Auto-fix) ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค [8-10]. ## ๐Ÿ“– ๊ตฌ์กฐํ™”๋œ ์ง€์‹ (Synthesized Content) ๋ณธ๋ฌธ ๊ตฌ์กฐํ™” ์ž‘์—… ์ค‘... ## โš ๏ธ ๋ชจ์ˆœ ๋ฐ ์—…๋ฐ์ดํŠธ (Contradictions & RL Update) - **๊ณผ๊ฑฐ ๋ฐ์ดํ„ฐ์™€์˜ ์ถฉ๋Œ:** ์ž๋™ํ™” ์—”์ง„์— ์˜ํ•ด ๋งคํ•‘๋œ ์ง€์‹์œผ๋กœ, ์ถ”ํ›„ ์ •๋ฐ€ ๊ฒ€์ฆ ํ•„์š”. - **์ •์ฑ… ๋ณ€ํ™”:** AI ๋ถ„์•ผ์˜ ์ž๋™ ์ž์‚ฐํ™” ์ˆ˜ํ–‰. ## ๐Ÿ”— ์ง€์‹ ์—ฐ๊ฒฐ (Graph) - **Related Topics:** [[DAST (แ„ƒแ…ฉแ†ผแ„Œแ…ฅแ†จ แ„‹แ…ขแ„‘แ…ณแ†ฏแ„…แ…ตแ„แ…ฆแ„‹แ…ตแ„‰แ…งแ†ซ แ„‡แ…ฉแ„‹แ…กแ†ซ แ„แ…ฆแ„‰แ…ณแ„แ…ณ)|DAST]], [[SCA (แ„‰แ…ฉแ„‘แ…ณแ„แ…ณแ„‹แ…ฐแ„‹แ…ฅ แ„€แ…ฎแ„‰แ…ฅแ†ผ แ„‡แ…ฎแ†ซแ„‰แ…ฅแ†จ)|SCA]], IAST, [[แ„‰แ…ตแ„‘แ…ณแ„แ…ณ แ„…แ…ฆแ„‘แ…ณแ„แ…ณ (Shift-Left)|Shift-Left]], False Positives - **Projects/Contexts:** CI/CD Pipeline Integration, Snyk Code, [[Corgea|Corgea]], Checkmarx, [[SonarQube|SonarQube]] - **Contradictions/Notes:** ์ž๋™ํ™”๋œ SAST ๋„๊ตฌ๋Š” ์ฝ”๋“œ ๊ธฐ๋ฐ˜์˜ ํŒจํ„ด ๋งค์นญ์— ๋น ๋ฅด๊ณ  ์ผ๊ด€๋˜์ง€๋งŒ, ๋ณต์žกํ•œ ๋น„์ฆˆ๋‹ˆ์Šค ๋กœ์ง๊ณผ ์•„ํ‚คํ…์ฒ˜ ํŠธ๋ ˆ์ด๋“œ์˜คํ”„๋ฅผ ์ดํ•ดํ•˜์ง€ ๋ชปํ•˜๋ฏ€๋กœ, ์™„๋ฒฝํ•œ ๋ณด์•ˆ๊ณผ ์ฝ”๋“œ ํ’ˆ์งˆ ํ™•๋ณด๋ฅผ ์œ„ํ•ด์„œ๋Š” ์ธ๊ฐ„ ๊ฐœ๋ฐœ์ž๊ฐ€ ์ง์ ‘ ์ˆ˜ํ–‰ํ•˜๋Š” ์ˆ˜๋™ ์ฝ”๋“œ ๋ฆฌ๋ทฐ(Manual Code Review)๋ฅผ ๋ฐ˜๋“œ์‹œ ๋ณ‘ํ–‰ํ•ด์•ผ ํ•œ๋‹ค๊ณ  ๊ฐ•์กฐ๋ฉ๋‹ˆ๋‹ค [16, 26-28]. --- *Last updated: 2026-04-19* - Raw Source: 00_Raw/2026-04-20/SAST.md ---