A quality assurance team wants to enforce corporate coding standards and identify security vulnerabilities in their application's source code before it is compiled and executed.
Which of the following tool types would be MOST appropriate for this task?