DAST+SASTinonePRcheck
confirmedbybothengines
Fendix runs DAST probes on every scan. Only findings where the runtime probe and the static analysis independently agree make it to your PR — so the queue stays small and every alert means something. Run the same engine on every commit: a diff-aware scan of just the staged files finishes in ~18ms, or wire it as a pre-commit hook with one command.