Source analysis that starts from the code you authorize.

Use Workbench Source analysis to clone an approved repository or upload source. SAST evaluates the pinned source snapshot; it is not a DAST setup screen and does not require a live target.

Choose the source snapshot before analysis starts.

Source analysis accepts a credential-free HTTPS repository URL, a connected repository source, or an upload. Workbench shows Source, Policy, and Review & launch steps so the operator can confirm the source before a run begins.

Workbench Source analysis setup with repository and upload choices

Review source locations, not fabricated runtime proof.

A source-analysis candidate cites the file, line, and snippet that need review. It is validated and traced before storage as a finding, so a language label or heuristic alone is not presented as a confirmed exploit.

Read the SAST language and evidence guide

Workbench findings inventory showing SAST results with source file and line evidence

Three steps from approved scope to a reviewable result.

  1. 1

    Provide an approved repository URL, connected repository, or source archive.

  2. 2

    Confirm the source and policy in Workbench.

  3. 3

    Review file, line, and snippet evidence before remediation.

Request the workspace that keeps assessment and evidence together.