Files
2nd/10_Wiki/Topics/Domain_Programming/DevOps_and_Security/SAST.md
T
Antigravity Agent c24165b8bc refactor(topics): 멀티 에이전트용 지식 재편 — _Common(공통 기본기) + Domain_* 구조
에이전트 8종(대화형/프로그래머 C·S/디자이너/설계자/기획자/QA/PD/PM)에게
[공통 기본 능력 + 롤별 Specialty] 2층으로 지식을 주입하기 위한 재분류.
문서 내용·포맷은 무수정, 폴더 이동만 (6,372개 문서 수 보존 확인).

- Topic_Programming → Domain_Programming (내부 구조 보존)
- Topic_Graphic → Domain_Design
- Topic_Business → Domain_Product
- Topic_General → Domain_General
- _Common 신설: Math(구 Topic_Math_Specialty), Reasoning(구 General/From_Thinking & Reasoning),
  Reasoning_Creativity(구 General/From_창의성), Communication(Poetic_Blog_Writing + From_writing)
- 타 도메인의 From_* 폴더는 유지 (출처 표기일 뿐, 이미 도메인에 맞게 분류된 문서)
- 빈 폴더 정리 (memory/procedures)
- 에이전트→폴더 매핑은 workspace의 .astra/agent-knowledge-map.json (9개 에이전트)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-11 11:05:56 +09:00

4.7 KiB

id, title, category, status, canonical_id, aliases, duplicate_of, source_trust_level, confidence_score, verification_status, tags, raw_sources, last_reinforced, github_commit, tech_stack
id title category status canonical_id aliases duplicate_of source_trust_level confidence_score verification_status tags raw_sources last_reinforced github_commit tech_stack
wiki-2026-0508-sast SAST 10_Wiki/Topics verified self
Static Application Security Testing
static analysis
source code analysis
none A 0.95 applied
security
sast
devsecops
static-analysis
ci-cd
2026-05-10 pending
language framework
multi semgrep-codeql-snyk

SAST

매 한 줄

"매 source 의 reading 없이 의 running". SAST (Static Application Security Testing) 의 source code, bytecode, binary 의 의 inspecting 의 vulnerabilities 의 detecting 의 — 매 runtime 의 없이. 2026 의 dominant tools: Semgrep (rule-based, fast), CodeQL (semantic, deep), Snyk Code (DeepCode AI).

매 핵심

매 SAST 의 기본 mechanics

  • AST/CFG/DFG: source 의 parse → AST → control-flow graph → data-flow graph.
  • Taint analysis: 매 source (user input) → sink (sql query) 의 path 의 trace.
  • Pattern matching: 매 known anti-pattern (e.g., eval(req.body)) 의 detect.
  • Symbolic execution (heavy): 매 path constraints 의 SMT solver 의 — 매 CodeQL.

매 modern tools 의 비교

  • Semgrep (2026): YAML rules, 매 fast (CI-friendly), 매 OSS + Pro (Semgrep Code).
  • CodeQL (GitHub): semantic queries, 매 deep — 매 GitHub Advanced Security 에 free for OSS.
  • Snyk Code: AI-augmented (DeepCode), 매 fast, 매 commercial.
  • SonarQube: code quality + security 의 hybrid.

매 응용

  1. PR-blocking gate (block-on-high).
  2. Pre-commit (fast subset).
  3. Nightly full scan + Jira issue 의 auto-create.

💻 패턴

Semgrep custom rule (taint TS)

rules:
  - id: dangerous-eval-from-request
    languages: [typescript, javascript]
    severity: ERROR
    message: 매 user input 의 eval 의 — RCE 위험
    mode: taint
    pattern-sources:
      - pattern-either:
          - pattern: req.body
          - pattern: req.query
          - pattern: req.params
    pattern-sinks:
      - pattern-either:
          - pattern: eval(...)
          - pattern: new Function(...)

GitHub Actions — Semgrep CI

name: SAST
on: [pull_request]
jobs:
  semgrep:
    runs-on: ubuntu-latest
    container: returntocorp/semgrep
    steps:
      - uses: actions/checkout@v4
      - run: semgrep ci --config=p/owasp-top-ten --config=.semgrep/
        env:
          SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}

CodeQL query 의 hardcoded secret

import javascript

from StringLiteral s
where s.getValue().regexpMatch("AKIA[0-9A-Z]{16}")
select s, "매 hardcoded AWS key 의 detected"

Pre-commit hook — fast subset

#!/usr/bin/env bash
changed=$(git diff --cached --name-only --diff-filter=ACMR | grep -E '\.(ts|tsx|js|py)$')
[ -z "$changed" ] && exit 0
echo "$changed" | xargs semgrep --config=p/security-audit --error

SARIF upload 의 GitHub code scanning 의

- run: semgrep ci --sarif --output=semgrep.sarif || true
- uses: github/codeql-action/upload-sarif@v3
  with: { sarif_file: semgrep.sarif }

Triage — false positive 의 suppress 의

// nosemgrep: dangerous-eval-from-request
// 매 reason: input 의 zod-validated 의 already
const result = eval(safeMath); // ok

매 결정 기준

상황 Tool
OSS project, 매 fast feedback Semgrep (free OSS rules)
GitHub repo, 매 deep semantic CodeQL (GHAS)
polyglot enterprise Snyk Code or SonarQube
custom org rules 의 heavy Semgrep Pro

기본값: Semgrep (PR gate, p/owasp-top-ten) + CodeQL (nightly, scheduled).

🔗 Graph

🤖 LLM 활용

언제: triaging findings, generating fix PRs (Copilot Autofix style), writing custom rules from natural language. 언제 X: trusting AI-only triage 없이 의 human review — 매 false positives 여전히 30-50%.

안티패턴

  • Block-on-everything: medium severity 의 PR block — devs 의 SAST 의 disable 의.
  • No suppression hygiene: nosemgrep 의 reason 없이 spammed.
  • Tool-only: SAST 만 — DAST/SCA 없으면 runtime + dependency 의 blind.
  • Scan once a quarter: 매 finding backlog 의 explode.

🧪 검증 / 중복

  • Verified (Semgrep Registry 2026, GitHub CodeQL docs, OWASP SAST guide).
  • 신뢰도 A.

🕓 Changelog

날짜 변경
2026-05-08 Phase 1
2026-05-10 Manual cleanup — Semgrep/CodeQL 의 modern SAST patterns