Glossary

A practical glossary of security and integration terms used throughout the XEIZE documentation.

This page is a quick reference to security and integration terms used in the XEIZE documentation. Each entry gives you the essential meaning for discussions with engineers and explains why it matters when reading the documentation.

SAST

SAST finds risky patterns by statically analyzing code and configuration files without running them. When reviewing a finding, focus on the flow through the code that led to it.

SCA

SCA analyzes the libraries and package versions a project depends on, rather than the code you wrote. When reviewing results, check whether each version was identified from a lockfile, a build artifact, or a container image.

IaC

IaC refers to files that declare infrastructure as code, such as Terraform files, CloudFormation templates, and Kubernetes manifests. If you change a setting in a management console but leave the code unchanged, the issue can return on the next deployment.

AST

An AST is a tree that represents the syntactic structure of code. XEIZE uses it to interpret context more precisely than a plain text search and to distinguish uses of the same word that have different meanings in code.

SBOM

An SBOM lists the software components in a project or image. SCA can use it to identify packages and versions. Depending on when it was produced, what it covers, and how it was generated, an SBOM may contain incomplete or outdated information. An SBOM alone does not establish that every component in the actual deployment has been identified.

Allow-list

An allow-list accepts only values that have been explicitly permitted. In security documentation, it usually means restricting an input so that users cannot supply arbitrary values.

Secret rotation

Secret rotation replaces a password, token, or key with a new value and makes the old value unusable. It also includes updating the services that use the secret. If a secret has been exposed, removing it from the repository is not enough: revoke the exposed value through the service that issued it.

PR

PR stands for pull request: a request to merge code changes after review and automated checks. GitLab uses the similar concept of a merge request, or MR.

Runner

A runner is the machine or execution environment that runs pipeline jobs in systems such as GitHub Actions and GitLab CI. Required permissions and network access can differ between self-hosted and shared runners.