Code Security
Static analysis, dependency, and secret scanning on repositories you authorize, ranked by reachability and linked to what the web scanner observes.
A dependency you never call is not equal to one on a request path, and severity reflects that.
Credentials are masked, reveal is audited, and Sightrove never tests them against a live service.
Nothing is committed or merged without your explicit action.
Terraform, Docker, and Kubernetes are checked for unsafe storage, groups, and encryption.
A runtime finding links to the code that caused it and can raise its severity.
Static analysis stays static. Public secrets are reported, never exercised.