SAST (static code)
CVEs in your code.
Static Application Security Testing: source code analysis without execution. Detection of SQL injection, XSS, path traversal, deserialization. Semgrep (custom rules), CodeQL, Snyk Code. False positives filtered via baseline.