Breaking Down Python Security: Lessons From Building a Modern SAST Scanner
Talk presented by: Maikel Mardjan
During PyCon NL 2026, at 12:05 in Spark

Python powers web applications, automation platforms, and many new AI systems, yet detecting Python-specific weaknesses remains harder than it should be.

Static Application Security Testing (SAST) is a proven way to identify weaknesses in Python code, but existing tools often struggle with usability and precision.

In 2025, after evaluating the strengths and limitations of existing Python SAST tools, I set out to build a new open source Python SAST scanner focused on usability, reliability, and a zero-configuration workflow.

This talk explores the architectural decisions behind building a modern Python SAST scanner. We’ll look at how Python code can be analysed using abstract syntax trees (ASTs), how security rules can detect weaknesses, and the trade-offs between coverage, accuracy, and trustworthy results.

You’ll see examples of vulnerabilities in Python code, together with demonstrations of how static analysis can detect or fail to detect them before deployment.

Practical information
When: October 15th 2026
A map showing where the Jaarbeurs Utrecht is located
Where: Jaarbeurs Utrecht
Jaarbeursplein 6
3521 AL Utrecht
The Netherlands
More info
Follow us: