src2sink
Back in February, in my deep dive comparing SAST with Claude Code Security, I described something in theoretical terms: a metabase of versioned, validated facts about an organisation’s source code, built so that cross-repository taint analysis becomes possible. Sources in one repo, sinks in another, internal libraries acting as transparent…




















