When does static application security testing require access to source code?
always
never Explanation:
only when assessing regulatory compliance
only if following the Agile model