Step 1Choose the scanners
Fit for your stack, open source first where it's good enough.
ATALAIATypeScript and Terraform. Open-source scanners cover most of it.
DEV LEADWe already pay for one. Nobody looks at it.
Leaves the roomSAST, SCA, secrets, IaC, container
Step 2Wire them to the belt
In the PR and in the pipeline, with results where devs already look.
ATALAIAResults go in the PR, where you already look. Not in a separate portal.
DEVELOPERSo I see it before review, not a week after merge.
Leaves the roomResults in the PR, not a portal
Step 3Tune the noise
Suppress what doesn't apply, write rules for what does.
DEVELOPERThere are 4,812 open findings. I stopped reading at twenty.
ATALAIAMost are test files and one rule that doesn't fit your framework. Those go.
ATALAIAThat leaves 74, and every one of them is real.
Leaves the room4,812 findings → 74 that apply
Step 4Decide what blocks
A short, agreed list of findings that stop a build.
DEV LEADWhat actually stops a merge?
ATALAIALive secrets, critical CVEs with a fix, and four rules we agreed. The rest warns.
DEVELOPERA secret caught before merge. That one I like.
Leaves the roomBlock list: 6 rules
- ATALAIA
- PLATFORM
- DEV LEAD
- DEVELOPER