When does static application security testing require access to source code?
always
only when assessing regulatory compliance
only if following the Agile model
never Explanation: