GitHub CodeQLが個人アカウントでは使えなかった話 ― 開発ツールを9本まとめて入れた棚卸しの顛末

🤖 sastIA — SAST auditing with an AI agent pipeline.
VulnHunter methodology (recon → hunt → verify → PoC → report), OpenCode agents running Semgrep, Gitleaks & Bandit. Findings with impact analysis and remediation.
🔗 https://github.com/madpowah/sastIA
#SAST #AppSec #AI #InfoSec
Boards are all asking - If #AI is this good at writing code, why keep buying security tools? The answer is that a frontier model is a reasoning layer, not a replacement for #SAST, #SCA, secrets & supply-chain defense. Interesting insights from @EndorLabs. api.cyfluencer.com/s/ciso-s-gui...