01 / Demo 01 / Exact-source evidence
SAST: From Dataflow to Decision
Follow a TypeScript authorization finding from dataflow to decision with source bytes, attack-path context, counter-evidence, and safe-change reasoning.
- Authorization fail-open in real TypeScript
- Dataflow, reachability, and exact source bytes
- Attack path and counter-evidence
- Fail-closed remediation with functional tests
