# Security Scanning in a Pipeline — CI/CD

Source: https://www.geekswithgeeks.com/en/cicd/cicd-security-scanning

> Catching vulnerable dependencies and risky code before they ship.

## What gets scanned

**Dependency scanning** checks third-party packages against known-vulnerability databases. **Static analysis (SAST)** scans your own code for risky patterns like SQL injection or hardcoded secrets, without running it.

## Where it fits in the pipeline

Scans usually run alongside or right after tests — early enough to block a bad merge, before the deploy stage spends time on something that shouldn't ship.

## Tune severity, don't ignore it

Blocking on every low-severity finding trains teams to bypass the scanner. Fail the build on critical/high issues, and track lower ones without stopping delivery.
