An Empirical Analysis of Security Testing Maturity With Sast In Open-Source Healthcare Software
This study investigates the maturity of Static Application Security Testing (SAST) adoption in high-reputation, open-source soft- ware projects within the healthcare domain. We propose a DevSecOps- aligned maturity classification model and evaluate the presence, depth and automation of SAST within CI/CD pipelines. Results indicate lim- ited adoption: despite healthcare being a high-risk and highly regulated domain, only a fraction of repositories demonstrated advanced secu- rity integration. The findings highlight security gaps and reinforce the need for improved continuous testing practices in digital health software ecosystems.
