Hello PAPA FAM,
I'm currently looking for a reliable open-source tool for both Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST). I would really appreciate any recommendations or insights based on your experience.
The goal is to finalize a tool that’s effective, well-maintained, and ideally easy to integrate into CI/CD pipelines. If you've used any open-source SAST/DAST tools that worked well for you, please share your thoughts — pros, cons, or any lessons learned.
Thanks in advance for your help!