
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s tech blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, distributed training, and data engineering.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Fri, 15 May 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/gitguardian/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive.en</guid>
    <title>Static Analysis / SAST 2026 — Semgrep / CodeQL / Snyk / SonarQube / Aikido / Trivy Deep Dive</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive.en</link>
    <description>Mapping the 2026 code security tooling landscape — Semgrep (the de facto OSS SAST plus Pro engine and Supply Chain), CodeQL (the heart of GitHub Advanced Security, dataflow king), Snyk Code (SAST+SCA after the DeepCode AI integration), SonarQube 11 (how the classic stays alive), Aikido Security (the all-in-one newcomer with AI Autofix), Cycode and GitGuardian (supply chain + secrets), Trivy/Aqua (containers + dependencies), Checkmarx and Veracode (enterprise stalwarts), OWASP ZAP, Bearer, Endor Labs, Socket.dev. SBOM (SPDX/CycloneDX) maturing, reachability analysis, LLM autofix, EU CRA 2024, and the Korea/Japan landscape with KaibAi and FFRI.</description>
    <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>sast</category><category>static-analysis</category><category>semgrep</category><category>codeql</category><category>snyk</category><category>sonarqube</category><category>aikido</category><category>cycode</category><category>gitguardian</category><category>trivy</category><category>checkmarx</category><category>sbom</category><category>devsecops</category><category>2026</category><category>deep-dive</category><category>english</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive.ja</guid>
    <title>静的解析 / SAST 2026 — Semgrep / CodeQL / Snyk / SonarQube / Aikido / Trivy 徹底比較</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive.ja</link>
    <description>2026年のコードセキュリティツール地図を描く — Semgrep(オープンソース SAST のデファクト + Pro engine と Supply Chain)、CodeQL(GitHub Advanced Security の中核、dataflow の王者)、Snyk Code(DeepCode AI 統合後の SAST+SCA)、SonarQube 11(クラシックの生存戦略)、Aikido Security(オールインワン新興 + AI Autofix)、Cycode と GitGuardian(サプライチェーン + シークレット)、Trivy/Aqua(コンテナ + 依存)、Checkmarx と Veracode(エンタープライズ陣営)、OWASP ZAP、Bearer、Endor Labs、Socket.dev。SBOM(SPDX/CycloneDX)成熟、reachability analysis、LLM autofix、EU CRA 2024、そして KaibAi と FFRI など韓国・日本市場まで。</description>
    <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>sast</category><category>static-analysis</category><category>semgrep</category><category>codeql</category><category>snyk</category><category>sonarqube</category><category>aikido</category><category>cycode</category><category>gitguardian</category><category>trivy</category><category>checkmarx</category><category>sbom</category><category>devsecops</category><category>2026</category><category>deep-dive</category><category>日本語</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive</guid>
    <title>정적 분석 / SAST 2026 — Semgrep / CodeQL / Snyk / SonarQube / Aikido / Trivy 심층 비교</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive</link>
    <description>2026년 코드 보안 도구 지도를 그린다 — Semgrep(오픈소스 SAST의 표준 + Pro engine과 Supply Chain), CodeQL(GitHub Advanced Security의 핵심, dataflow 강자), Snyk Code(DeepCode AI 통합 이후의 SAST+SCA), SonarQube 11(클래식이 살아남는 법), Aikido Security(올인원 신예 + AI Autofix), Cycode·GitGuardian(공급망 + 시크릿), Trivy/Aqua(컨테이너 + 디펜던시), Checkmarx·Veracode(엔터프라이즈 진영), OWASP ZAP·Bearer·Endor Labs·Socket.dev. SBOM(SPDX/CycloneDX) 표준화, reachability analysis, LLM autofix, EU CRA 2024, 그리고 KaibAi·FFRI까지.</description>
    <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>sast</category><category>static-analysis</category><category>semgrep</category><category>codeql</category><category>snyk</category><category>sonarqube</category><category>aikido</category><category>cycode</category><category>gitguardian</category><category>trivy</category><category>checkmarx</category><category>sbom</category><category>devsecops</category><category>2026</category><category>deep-dive</category>
  </item>

    </channel>
  </rss>
