Static analysis: This is testing that we perform in a non-runtime environment, ideally in the deployment pipeline
— The DevOps Handbook, in “22 Information Security as Everyone’s Job, Every Day”, Gene Kim, Jez Humble, Patrick Debois, John Willis, and Nicole Forsgren