Add static application security testing to CI/CD
Implement SAST scanning. Setup tools (Semgrep, SonarQube), configure rules, integrate with CI/CD, fix critical findings.
Security scanning