SAST, DAST and SCA findings sit in separate scanners, so per-application risk is impossible to see whole. Developers get noise from three directions and fix little of it.
"For each application, what's the real security picture once SAST, DAST and SCA are seen together?"
Per-app findings hub
Duplicate findings
To first outcomes