OpenText 主页。
应用程序安全测试

OpenText Static Application Security Testing (Fortify)

以行业领先的准确性,尽早发现并修复安全问题

计算机上的 OpenText Static Application Security Testing 平台仪表板

Gartner® 将 OpenText 评为应用程序安全领域的领导者获取魔力象限报告

在 CI/CD 管道中实现安全自动化

传统的 SAST 工具通常需要调整和专业知识,会产生误报,让团队不堪重负。还有一些软件虽然易于使用,但存在漏洞。OpenText™ Static Application Security Testing (Fortify) (SAST) 使 DevSecOps 具有精确的漏洞检测、广泛的语言支持和无缝的 CI/CD 集成。AI 驱动的见解帮助开发人员高效地确定漏洞的优先级并加以解决,从而降低整个软件开发生命周期 (SDLC) 中的安全风险。

为什么选择 OpenText Static Application Security Testing?

发现其他人忽略的关键漏洞。OpenText SAST 与 GitHub、GitLab、Jenkins、Azure DevOps、VS Code、Eclipse 等集成,能够在保障代码安全的同时,让开发人员保持高效的工作节奏。

  • 1,495+
    评估的漏洞类别
    涵盖 33 种以上语言和超过一百万个独立的 API。
  • 350+
    支持的框架
    提供无与伦比的广度和灵活性,确保在各种开发环境中实现全面的安全保障。
  • 94%
    的 OpenText 用户同意
    OpenText Static Application Security Testing 可帮助他们改进应用程序安全计划。
    看看客户怎么说

用例

OpenText SAST 可为多种开发语言提供全面的安全性,同时与您选择的开发工具集成。利用自定义扫描深度平衡速度和准确性,利用 AI 助手减少误报,并动态扩展。

  • 在编写源代码时进行扫描,以便在代码合并或发布前捕获漏洞。在合并之前,在开发者 IDE 或拉取请求中查找问题。尽早解决问题可大幅降低修复成本,并防止安全债务的累积。

  • 将 SAST 嵌入 DevOps 流程,在每个构建或部署阶段自动阻止或标记不安全代码。这确保了安全性与敏捷开发保持同步,并且不会降低发布速度。

  • 利用基于策略的扫描执行和报告功能,强制执行安全编码实践,并检测违反合规性框架(如 OWASP 十大安全漏洞、NIST、PCI-DSS、ISO 27001 等)的情况,从而降低因不合规而面临审计、罚款或声誉受损的风险。

  • 在传统堆栈和现代架构(如微服务、API、容器)中应用一致的安全扫描。静态分析扩展到了移动平台、REST API 和现代接口。该方案适用于运行混合环境且需要全栈安全防护的企业。

  • 使用集中式仪表板和可自定义的报告来跟踪发现的问题、修复进度和团队绩效,为安全领导者提供所需的可见性,以管理风险并向管理层和开发团队及时传达状况。

  • 提供可操作的指导、IDE 集成以及上下文修复建议,帮助开发人员更快地修复漏洞。减少安全团队与开发团队之间的摩擦,提高修复率,并鼓励安全编码习惯。

    关键功能

    OpenText SAST 通过 AI 驱动的分析、云原生支持和灵活部署提供企业级代码安全性,帮助组织降低风险、简化合规性并大规模构建安全软件。

    与 OpenText Static Application Security Testing 兼容的产品的屏幕截图。

    全面的语言和框架支持

    支持 33 种以上语言、350 多种框架,并检测源代码中超过 200 种类型的机密信息。支持在整个代码库中进行一致且全面的安全测试。

    OpenText Static Application Security Testing 用户界面显示仪表板的屏幕截图。

    灵活的部署选项

    包括诸如基于 SaaS 的 OpenText™ Core Application Security 测试平台、结合了 SaaS 和本地部署功能的私有托管,以及可完全控制应用程序安全测试解决方案的脱离云端模式等选项。

    OpenText Static Application Security Testing 用户界面的屏幕截图。

    集成基础设施即代码 (IaC) 扫描

    在一个平台上提供一流的 IaC 和应用安全扫描,支持 Docker®、Kubernetes® 和无服务器架构,所有功能均由单一核心引擎驱动。

    OpenText Static Application Security Testing 用户界面的屏幕截图,突出显示了发布问题。

    AI 驱动的审计与修复

    借助 OpenText™ Application Security Aviator™,通过 SaaS 和云外访问,加速审计和漏洞检测,并针对 SAST 漏洞提供自动代码修复建议。

    OpenText Static Application Security Testing 用户界面的屏幕截图,突出显示了令牌管理。

    下一代 SAST 引擎

    覆盖 33 种以上语言、1,495 种以上的漏洞类别、350 多种框架和 100 多万个 API。


    全面的语言和框架支持

    OpenText SAST 可为 33 种以上的主要语言及其框架提供准确的支持,并在行业领先的软件安全研究 (SSR) 团队的支持下进行敏捷更新

    SAP ABAP 徽标SAP ABAP
    Action Script 徽标Action Script
    Angular 徽标Angular
    Apex 徽标Apex
    Microsoft ASP 徽标Microsoft ASP
    Bicep logoBicep
    CSharp 徽标CSharp
    C++ 徽标C++
    COBOL 徽标COBOL
    Cold Fusion 徽标Cold Fusion
    Docker 徽标Docker
    Go Lang 徽标Go Lang
    HTML5 徽标HTML5
    Java 徽标Java
    Java Script 徽标Java Script
    JSON logoJSON
    JSP 徽标JSP
    Kotlin logoKotlin
    MXML 徽标MXML
    Net 徽标.Net
    NETCore 徽标.NETCore
    PL/SQL logoPL/SQL
    Python 徽标Python
    Ruby 徽标Ruby
    Scala 徽标Scala
    Swift Trans 徽标Swift Trans
    T-SQL 徽标T-SQL
    Terraform 徽标Terraform
    Type Script 徽标Type Script
    Microsoft Visual Basics 徽标Microsoft Visual Basics
    Visual Basic 徽标Visual Basic
    Windows Mobile 徽标Windows Mobile
    XML 徽标XML
    YAML 徽标YAML

    加速实现 OpenText Static Application Security Testing 的价值

    部署

    OpenText 为 OpenText Static Application Security Testing 提供了部署选择和灵活性。

    专业服务

    OpenText 专业服务将端到端解决方案的实施与全面技术服务相结合,以优化系统。

    合作伙伴

    OpenText 帮助客户找到合适的方案、恰当的支持与理想的结果。

    社区

    探索我们的 OpenText 社区。与个人和企业建立联系,获取洞察和支持。参与讨论。

    OpenText Static Application Security Testing resources

    Location World logo

    OpenText supports high-quality application release with less expense and effort

    Learn more
    SAP logo

    OpenText protects SAP and customers against software-related financial losses

    Learn more
    Callcredit logo

    Callcredit adds OpenText into development lifecycle

    Learn more
    DATEV eg logo

    OpenText helped reduce complexity and improved development collaboration

    Learn more
    Professional services customer story

    Strategic alliance with OpenText lowers TCO while enhancing cyber resilience

    Learn more
    Banking customer story

    Custom software solutions boost health management and ensure data compliance

    Learn more
    High tech customer story

    OpenText delivers effective and streamlined application security

    Learn more

    OpenText Static Application Security Testing (SAST)

    Read the data sheet

    Support and documentation

    View the documentation

    OpenText Static Application Security Testing (SAST)

    Read the data sheet

    Support and documentation

    View the documentation
    • Static application security testing (SAST) analyzes application source code, bytecode, or binaries to detect security vulnerabilities during development. Identifying risks like early in the software development lifecycle (SDLC), makes remediation faster and less expensive.

    • OpenText SAST is a static analysis solution supporting 33+ programming languages and integrating with developer tools, CI/CD pipelines, and ticketing systems. It combines deep static analysis with vulnerability coverage mapped to standards such as OWASP Top 10, CWE, and NIST.

    • SAST helps developers embed security into early software development. OpenText SAST integrates with IDEs (e.g., Visual Studio®, IntelliJ®), build tools (e.g., Maven, Gradle), and CI/CD platforms (e.g., Jenkins™, Azure DevOps®), allowing security scans to run automatically during coding and builds.

    • While SAST primarily analyzes proprietary code, OpenText complements it with Software Composition Analysis (SCA) tools that identify risks in open-source libraries, such as known vulnerabilities, outdated components, and licensing issues.

    • OpenText SAST supports web, mobile, desktop, and cloud-native applications across a wide range of languages including Java, .NET, JavaScript, Python, C/C++, Swift, Kotlin, Go, and more. It also handles infrastructure-as-code (IaC), containers, and APIs.

    • OpenText SAST provides out-of-the-box support for security and compliance frameworks such as OWASP Top 10, PCI DSS, NIST 800-53, and ISO 27001. The platform delivers policy-based scan management, audit-ready reporting, and dashboards that demonstrate risk posture and remediation progress.

    • OpenText Static Application Security Testing offers flexible deployment on-premises for full control and customization, as hosted and managed scanning infrastructure where your team submits code remotely, and as a fully managed experience (OpenText™ Core Application Security).

    • OpenText SAST includes support for popular IDEs like Visual Studio, IntelliJ, and Eclipse®, as well as CI/CD tools such as Jenkins, GitHub Actions®, GitLab CI®, Azure DevOps, and Bamboo™. The platform also integrates with issue tracking systems like Jira®, enabling automatic ticket creation.

      Mobile and tablet devices
      March 11, 2025

      Smarter, faster AppSec

      Turn SAST findings into learning, helping developers quickly remediate vulnerabilities.

      Read the blog
      March 3,2025

      Why SAST false positives are inevitable

      Explore why false positives in SAST tools occur, the trade-offs involved, and how to manage them.

      Read the blog
      Security shield image
      January 17, 2025

      Why SAST + SCA is the key to protecting your organization in 2025

      Software supply chain risk continues to rise—156% year-over-year increase in malicious attacks.

      Read the blog
      Person typing on a laptop
      November 25, 2024

      Customers’ Choice

      OpenText recognized for Application Security Testing on Gartner® Peer Insights™︎.

      Read the blog
      Generative AI image
      October 25, 2024

      Generative AI: A double-edged sword for application security

      IDC predicts that by 2026, 40% of net-new applications will incorporate AI.

      Read the blog
      Person wearing glasses looking at a computer screen
      September 26, 2024

      Auto-remediation: the future of AppSec?

      Read the blog
      June 20,2023

      OpenText named a Leader in Critical Capabilities by Gartner

      OpenText is a Leader in SAST and DAST, and one of the only vendors that moved up in the quadrant.

      Read the blog

      What is static application security testing (SAST)

      Learn more

      Cybersecurity in a Web 3.0 world

      Learn more

      5 reasons why SAST + DAST with OpenText makes sense

      Learn more

      OpenText SAST tools

      View the community page

      What is static application security testing (SAST)

      Learn more

      Cybersecurity in a Web 3.0 world

      Learn more

      5 reasons why SAST + DAST with OpenText makes sense

      Learn more

      OpenText SAST tools

      View the community page

      迈出下一步

      想了解更多信息?OpenText 专家随时为您提供帮助。

      联系我们

      我们能提供什么帮助?