
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s tech blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, distributed training, and data engineering.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Fri, 15 May 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/sonarqube/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive.en</guid>
    <title>Static Analysis / SAST 2026 — Semgrep / CodeQL / Snyk / SonarQube / Aikido / Trivy Deep Dive</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive.en</link>
    <description>Mapping the 2026 code security tooling landscape — Semgrep (the de facto OSS SAST plus Pro engine and Supply Chain), CodeQL (the heart of GitHub Advanced Security, dataflow king), Snyk Code (SAST+SCA after the DeepCode AI integration), SonarQube 11 (how the classic stays alive), Aikido Security (the all-in-one newcomer with AI Autofix), Cycode and GitGuardian (supply chain + secrets), Trivy/Aqua (containers + dependencies), Checkmarx and Veracode (enterprise stalwarts), OWASP ZAP, Bearer, Endor Labs, Socket.dev. SBOM (SPDX/CycloneDX) maturing, reachability analysis, LLM autofix, EU CRA 2024, and the Korea/Japan landscape with KaibAi and FFRI.</description>
    <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>sast</category><category>static-analysis</category><category>semgrep</category><category>codeql</category><category>snyk</category><category>sonarqube</category><category>aikido</category><category>cycode</category><category>gitguardian</category><category>trivy</category><category>checkmarx</category><category>sbom</category><category>devsecops</category><category>2026</category><category>deep-dive</category><category>english</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive.ja</guid>
    <title>静的解析 / SAST 2026 — Semgrep / CodeQL / Snyk / SonarQube / Aikido / Trivy 徹底比較</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive.ja</link>
    <description>2026年のコードセキュリティツール地図を描く — Semgrep(オープンソース SAST のデファクト + Pro engine と Supply Chain)、CodeQL(GitHub Advanced Security の中核、dataflow の王者)、Snyk Code(DeepCode AI 統合後の SAST+SCA)、SonarQube 11(クラシックの生存戦略)、Aikido Security(オールインワン新興 + AI Autofix)、Cycode と GitGuardian(サプライチェーン + シークレット)、Trivy/Aqua(コンテナ + 依存)、Checkmarx と Veracode(エンタープライズ陣営)、OWASP ZAP、Bearer、Endor Labs、Socket.dev。SBOM(SPDX/CycloneDX)成熟、reachability analysis、LLM autofix、EU CRA 2024、そして KaibAi と FFRI など韓国・日本市場まで。</description>
    <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>sast</category><category>static-analysis</category><category>semgrep</category><category>codeql</category><category>snyk</category><category>sonarqube</category><category>aikido</category><category>cycode</category><category>gitguardian</category><category>trivy</category><category>checkmarx</category><category>sbom</category><category>devsecops</category><category>2026</category><category>deep-dive</category><category>日本語</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive</guid>
    <title>정적 분석 / SAST 2026 — Semgrep / CodeQL / Snyk / SonarQube / Aikido / Trivy 심층 비교</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-15-static-analysis-sast-2026-semgrep-codeql-snyk-sonarqube-aikido-trivy-deep-dive</link>
    <description>2026년 코드 보안 도구 지도를 그린다 — Semgrep(오픈소스 SAST의 표준 + Pro engine과 Supply Chain), CodeQL(GitHub Advanced Security의 핵심, dataflow 강자), Snyk Code(DeepCode AI 통합 이후의 SAST+SCA), SonarQube 11(클래식이 살아남는 법), Aikido Security(올인원 신예 + AI Autofix), Cycode·GitGuardian(공급망 + 시크릿), Trivy/Aqua(컨테이너 + 디펜던시), Checkmarx·Veracode(엔터프라이즈 진영), OWASP ZAP·Bearer·Endor Labs·Socket.dev. SBOM(SPDX/CycloneDX) 표준화, reachability analysis, LLM autofix, EU CRA 2024, 그리고 KaibAi·FFRI까지.</description>
    <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>sast</category><category>static-analysis</category><category>semgrep</category><category>codeql</category><category>snyk</category><category>sonarqube</category><category>aikido</category><category>cycode</category><category>gitguardian</category><category>trivy</category><category>checkmarx</category><category>sbom</category><category>devsecops</category><category>2026</category><category>deep-dive</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-code-quality-static-analysis-2026-sonarqube-codeclimate-codacy-deepsource-qodo-cover-snyk-code-semgrep-eslint-deep-dive.en</guid>
    <title>Code Quality &amp; Static Analysis 2026 Deep Dive — SonarQube · CodeClimate · Codacy · DeepSource · Qodo Cover · Snyk Code · Semgrep · ESLint</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-code-quality-static-analysis-2026-sonarqube-codeclimate-codacy-deepsource-qodo-cover-snyk-code-semgrep-eslint-deep-dive.en</link>
    <description>A May 2026 deep dive across the code quality and SAST ecosystem. Covers platforms (SonarQube 10.x, SonarCloud, CodeClimate, Codacy, DeepSource, Qodana, Qodo Cover), SAST engines (Semgrep 1.x, CodeQL, Snyk Code, Veracode, Checkmarx), per-language linters (ESLint 9 flat config, Biome, Oxlint, Ruff, golangci-lint, clippy), AI code review (Copilot Code Review, Greptile, CodeRabbit, Cursor Bugbot), and adoption stories from NAVER, Coupang, Toss, Mercari, LINE Yahoo.</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>code-quality</category><category>static-analysis</category><category>sonarqube</category><category>codeclimate</category><category>codacy</category><category>deepsource</category><category>qodo</category><category>snyk-code</category><category>semgrep</category><category>eslint</category><category>sast</category><category>2026</category><category>deep-dive</category><category>english</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-code-quality-static-analysis-2026-sonarqube-codeclimate-codacy-deepsource-qodo-cover-snyk-code-semgrep-eslint-deep-dive.ja</guid>
    <title>コード品質 &amp; 静的解析 2026 完全ガイド — SonarQube · CodeClimate · Codacy · DeepSource · Qodo Cover · Snyk Code · Semgrep · ESLint 徹底解剖</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-code-quality-static-analysis-2026-sonarqube-codeclimate-codacy-deepsource-qodo-cover-snyk-code-semgrep-eslint-deep-dive.ja</link>
    <description>2026年5月時点のコード品質・静的解析(SAST)エコシステムを一気に整理します。SonarQube 10.x・SonarCloud・CodeClimate・Codacy・DeepSource・Qodana・Qodo Cover といったプラットフォーム、Semgrep 1.x・CodeQL・Snyk Code・Veracode・Checkmarx といった SAST エンジン、ESLint 9 flat config・Biome・Oxlint・Ruff・golangci-lint・clippy といった言語別リンター、AI コードレビュー(Copilot Code Review・Greptile・CodeRabbit・Cursor Bugbot)、そして NAVER・Coupang・Toss・Mercari・LINE ヤフーの事例まで網羅します。</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>code-quality</category><category>static-analysis</category><category>sonarqube</category><category>codeclimate</category><category>codacy</category><category>deepsource</category><category>qodo</category><category>snyk-code</category><category>semgrep</category><category>eslint</category><category>sast</category><category>2026</category><category>deep-dive</category><category>日本語</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-code-quality-static-analysis-2026-sonarqube-codeclimate-codacy-deepsource-qodo-cover-snyk-code-semgrep-eslint-deep-dive</guid>
    <title>코드 품질 &amp; 정적 분석 2026 완벽 가이드 — SonarQube · CodeClimate · Codacy · DeepSource · Qodo Cover · Snyk Code · Semgrep · ESLint 심층 분석</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-code-quality-static-analysis-2026-sonarqube-codeclimate-codacy-deepsource-qodo-cover-snyk-code-semgrep-eslint-deep-dive</link>
    <description>2026년 5월 기준 코드 품질·정적 분석(SAST) 생태계를 한 글로 정리합니다. SonarQube 10.x·SonarCloud·CodeClimate·Codacy·DeepSource·Qodana·Qodo Cover 같은 플랫폼, Semgrep 1.x·CodeQL·Snyk Code·Veracode·Checkmarx 같은 SAST 엔진, ESLint 9 flat config·Biome·Oxlint·Ruff·golangci-lint·clippy 같은 언어별 린터, AI 코드 리뷰(Copilot Code Review·Greptile·CodeRabbit·Cursor Bugbot), 그리고 NAVER·Coupang·Toss·Mercari·LINE Yahoo 사례까지 담았습니다.</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>code-quality</category><category>static-analysis</category><category>sonarqube</category><category>codeclimate</category><category>codacy</category><category>deepsource</category><category>qodo</category><category>snyk-code</category><category>semgrep</category><category>eslint</category><category>sast</category><category>2026</category><category>deep-dive</category>
  </item>

    </channel>
  </rss>
