A pattern rule flags every call to eval, every string that looks like SQL, every file that mentions a password.
Some of those are real. Most are not, and the scanner cannot tell which, so it calls all of them high. The developer opens the report, sees the noise, and closes it — along with the one finding that was a genuine injection path from a request parameter to a database query.
When every match is an alert
A scanner that gives a regex hit the same severity as a proven injection teaches the team to ignore both. The fix is not fewer rules — it is being honest about what each rule can prove.
The mechanism, not the marketing
- 1
The scanner makes a shallow clone of the branch you chose and skips what is not your code: dependency and vendor folders, build output, minified files and anything over half a megabyte.
- 2
Files are routed by extension. Python, JavaScript, TypeScript, Java, C#, Go, C, C++ and Ruby go to static analysis on the open-source Semgrep engine; Terraform, YAML, JSON and Dockerfiles go to the IaC checker in the same job.
- 3
Three rule sources run together. Community security packs cover the OWASP Top 10, a general security audit, secrets and Node.js. Onam-curated taint rules follow untrusted input to a dangerous sink in Python, JavaScript/TypeScript, Java, C#, Go and Ruby. Onam-reviewed pattern rules add breadth, each one triaged by hand — rules judged code-quality or accessibility are dropped, not shown.
- 4
Severity follows evidence. Taint and AST findings keep the severity their rule asserts. A pattern match is capped at medium, or low if its rule has not been reviewed, and is listed as a hotspot rather than a security issue. Several pattern rules firing on the same line are collapsed into one.
- 5
Secret detection runs in the same pass: the community secrets pack plus Onam's own patterns for cloud keys, private-key blocks, GitHub, Slack and Stripe tokens, Google credentials, hard-coded JWTs and generic secret assignments.
- 6
Each finding is stored with its file, line, rule, message, CWE, OWASP category, confidence and a short code snippet, and appears in the scan view, the project view and the platform-wide alerts list.
Specific outputs, measurable outcomes
How Static Analysis (SAST) fits together
Questions we get a lot
Ready to see Static Analysis (SAST) on your code?
Give us a repository and we will scan it with you, then go through the security issues and the hotspots together.