<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									Checkmarx Reviews - Welcome to Stackinsight community. Join the discussion about products and tools for work Forum				            </title>
            <link>https://communities.stackinsight.net/community/cyber-checkmarx/</link>
            <description>Welcome to Stackinsight community. Join the discussion about products and tools for work Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Fri, 24 Jul 2026 20:05:05 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>Checkmarx sign up process - any hidden fees or long-term contracts?</title>
                        <link>https://communities.stackinsight.net/community/cyber-checkmarx/checkmarx-sign-up-process-any-hidden-fees-or-long-term-contracts/</link>
                        <pubDate>Tue, 21 Jul 2026 21:17:18 +0000</pubDate>
                        <description><![CDATA[I&#039;m looking at the Checkmarx platform for our team&#039;s SAST needs, but I&#039;ve been burned before by vendors who advertise flexible pricing only to lock you into an auto-renewing three-year contr...]]></description>
                        <content:encoded><![CDATA[I'm looking at the Checkmarx platform for our team's SAST needs, but I've been burned before by vendors who advertise flexible pricing only to lock you into an auto-renewing three-year contract with hidden support fees after the first year.

Their sales team is pushing for a call to discuss "tailored quotes," which is always a red flag for opaque pricing. Has anyone recently gone through their sign-up process for a team of 25-50 developers? I need to know:

What does the actual onboarding entail after the initial demo? Is there a mandatory professional services package to get started, or can you truly self-service with their documentation?
Once you get a quote, are there any non-negotiable clauses like automatic renewal or price increases beyond a certain percentage year over year?
Beyond the core license cost, what are the actual additional fees? I'm specifically concerned about costs for scaling the number of scans, premium support tiers that become "essential," or fees for integrating with specific CI/CD pipelines.

I'm not interested in sales pitches. I need factual reports from teams who have signed a contract in the last 18 months. What did the final agreement look like compared to the initial quote?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-checkmarx/">Checkmarx Reviews</category>                        <dc:creator>amandaf</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-checkmarx/checkmarx-sign-up-process-any-hidden-fees-or-long-term-contracts/</guid>
                    </item>
				                    <item>
                        <title>Checkmarx vs Snyk Code for Python microservices on AWS</title>
                        <link>https://communities.stackinsight.net/community/cyber-checkmarx/checkmarx-vs-snyk-code-for-python-microservices-on-aws/</link>
                        <pubDate>Tue, 21 Jul 2026 19:58:34 +0000</pubDate>
                        <description><![CDATA[I’m currently evaluating SAST tools for a new set of Python-based microservices running on AWS (mostly Lambda and ECS). The code is a mix of backend logic and data transformation layers, so ...]]></description>
                        <content:encoded><![CDATA[I’m currently evaluating SAST tools for a new set of Python-based microservices running on AWS (mostly Lambda and ECS). The code is a mix of backend logic and data transformation layers, so data handling and external API calls are common. We’re aiming to embed security scanning directly into our CI/CD pipelines (GitHub Actions).

I’ve narrowed it down to two main contenders: Checkmarx and Snyk Code. From a data-engineering-operations lens, I’m looking for concrete differences in how they handle:

* **Pipeline integration ease:** Setup time, configuration as code, and pipeline speed impact.
* **Python-specific analysis:** How well do they understand popular data and web frameworks (FastAPI, SQLAlchemy, boto3, pandas)?
* **Noise-to-signal ratio:** Particularly for data pipelines where certain "risky" patterns (like dynamic SQL) are common but necessary. How good is the triage experience?
* **Remediation guidance:** Are the findings actionable for developers, or just generic warnings?
* **Operational overhead:** Maintenance, cost scaling with codebase growth, and integration with our existing observability stack.

I’ve done some initial tests, but I’d love to hear from teams running similar stacks. A few specific things I’m wrestling with:

* Checkmarx seems to have deeper support for complex, multi-file analysis, but I’ve heard the scans can be slower.
* Snyk Code is praised for developer experience and speed, but does it hold up for intricate service-to-service data flows?

Has anyone directly compared them in a Python microservices context, especially when those services are heavy on ETL-like operations? Any gotchas or deciding factors that became apparent only after long-term use?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-checkmarx/">Checkmarx Reviews</category>                        <dc:creator>data_meets_ops</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-checkmarx/checkmarx-vs-snyk-code-for-python-microservices-on-aws/</guid>
                    </item>
				                    <item>
                        <title>Unpopular opinion: Their support team is slow, but the engineers know their stuff.</title>
                        <link>https://communities.stackinsight.net/community/cyber-checkmarx/unpopular-opinion-their-support-team-is-slow-but-the-engineers-know-their-stuff/</link>
                        <pubDate>Tue, 21 Jul 2026 19:56:48 +0000</pubDate>
                        <description><![CDATA[Everyone&#039;s complaining about ticket response times, and yeah, you&#039;ll wait. The front-line support is a black hole.

But when you finally get escalated to an actual engineer? That&#039;s when you ...]]></description>
                        <content:encoded><![CDATA[Everyone's complaining about ticket response times, and yeah, you'll wait. The front-line support is a black hole.

But when you finally get escalated to an actual engineer? That's when you realize they've seen your specific brand of chaos before. They cut through the marketing-speak and tell you exactly which CWE your custom rule is catching, why the AST parser flagged that particular pattern, and how to actually fix the false positive without just adding a blanket suppression.

It's the classic vendor split: the sales and tier-1 support facade is glacial, but the core product team buried underneath knows the code better than you do. The lock-in is real, but at least the people who built the cage are competent.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-checkmarx/">Checkmarx Reviews</category>                        <dc:creator>henryp</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-checkmarx/unpopular-opinion-their-support-team-is-slow-but-the-engineers-know-their-stuff/</guid>
                    </item>
				                    <item>
                        <title>Has anyone actually achieved the claimed 80% false positive reduction?</title>
                        <link>https://communities.stackinsight.net/community/cyber-checkmarx/has-anyone-actually-achieved-the-claimed-80-false-positive-reduction/</link>
                        <pubDate>Tue, 21 Jul 2026 18:59:12 +0000</pubDate>
                        <description><![CDATA[Hi everyone, I&#039;m pretty new to application security and my team is evaluating Checkmarx. I&#039;ve seen the marketing material about the 80% false positive reduction claim.

In your real-world ex...]]></description>
                        <content:encoded><![CDATA[Hi everyone, I'm pretty new to application security and my team is evaluating Checkmarx. I've seen the marketing material about the 80% false positive reduction claim.

In your real-world experience, is this achievable? What did you have to do to get there? I'm especially curious about the initial setup and tuning process. Was it mostly about tweaking the queries, or did it involve a lot of changes to how your code is structured? Any tips would be really helpful for a beginner like me &#x1f605;]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-checkmarx/">Checkmarx Reviews</category>                        <dc:creator>AndrewH</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-checkmarx/has-anyone-actually-achieved-the-claimed-80-false-positive-reduction/</guid>
                    </item>
				                    <item>
                        <title>How do I convince management the &#039;Unified&#039; platform isn&#039;t actually unified?</title>
                        <link>https://communities.stackinsight.net/community/cyber-checkmarx/how-do-i-convince-management-the-unified-platform-isnt-actually-unified/</link>
                        <pubDate>Tue, 21 Jul 2026 16:30:37 +0000</pubDate>
                        <description><![CDATA[Hey everyone! Been working with Checkmarx for about a year now, and I keep hitting the same wall with our leadership. They bought into the &quot;Unified&quot; platform idea, but in practice, it feels ...]]></description>
                        <content:encoded><![CDATA[Hey everyone! Been working with Checkmarx for about a year now, and I keep hitting the same wall with our leadership. They bought into the "Unified" platform idea, but in practice, it feels like three separate tools duct-taped together.

I need to show them the operational cost. For example, the findings from SAST, DAST, and SCA don't actually talk to each other. We're still manually correlating results and creating separate reports for each team. That's hours every week! Anyone else have a concrete example of this "unification gap" I can use to make my case? The efficiency promise just isn't panning out. &#x1f605;]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-checkmarx/">Checkmarx Reviews</category>                        <dc:creator>Gracy J</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-checkmarx/how-do-i-convince-management-the-unified-platform-isnt-actually-unified/</guid>
                    </item>
				                    <item>
                        <title>Guide: Running Checkmarx on a monorepo without scanning everything each time.</title>
                        <link>https://communities.stackinsight.net/community/cyber-checkmarx/guide-running-checkmarx-on-a-monorepo-without-scanning-everything-each-time/</link>
                        <pubDate>Tue, 21 Jul 2026 15:47:13 +0000</pubDate>
                        <description><![CDATA[Checkmarx scanning a full monorepo takes forever. You don&#039;t need to scan everything on every commit. Here&#039;s how to scope it.

You need to use the `--project-script` flag with Checkmarx CLI (...]]></description>
                        <content:encoded><![CDATA[Checkmarx scanning a full monorepo takes forever. You don't need to scan everything on every commit. Here's how to scope it.

You need to use the `--project-script` flag with Checkmarx CLI (`cx scan`). Create a script that filters which folders to scan based on changed files.

**Example workflow:**
1.  Get list of changed files from Git (e.g., `git diff --name-only HEAD~1`).
2.  Map changed files to your monorepo packages/services.
3.  Build a filtered file/folder list for Checkmarx.

**Basic script example (`filter_changed.py`):**

```python
#!/usr/bin/env python3
import sys
import subprocess
import os

# Get changed files from last commit
changed_files = subprocess.check_output(, text=True).strip().split('n')

# Define monorepo package roots
packages_to_scan = set()
for f in changed_files:
    if f.startswith('packages/lib-auth/'):
        packages_to_scan.add('packages/lib-auth')
    if f.startswith('apps/web-app/'):
        packages_to_scan.add('apps/web-app')
    # Add more mappings

# Output filtered paths, one per line, for Checkmarx
if packages_to_scan:
    for p in packages_to_scan:
        print(p)
else:
    # Fallback: scan everything if no changes matched (or exit)
    print('.')
```

**Run scan:**
```bash
cx scan --project-script "python3 filter_changed.py" ...
```

**Key points:**
*   This script runs *before* the scan starts. Checkmarx only scans the paths printed.
*   Integrate this into your CI. Use the appropriate Git diff command (e.g., against main branch).
*   Maintain the mapping. It's manual but straightforward.
*   Fallback strategy is crucial. Either scan all or skip.

Saves hours. Use it.

- bench_beast]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-checkmarx/">Checkmarx Reviews</category>                        <dc:creator>bench_beast</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-checkmarx/guide-running-checkmarx-on-a-monorepo-without-scanning-everything-each-time/</guid>
                    </item>
				                    <item>
                        <title>ELI5: What exactly is a &#039;preset&#039; and which one should I use?</title>
                        <link>https://communities.stackinsight.net/community/cyber-checkmarx/eli5-what-exactly-is-a-preset-and-which-one-should-i-use/</link>
                        <pubDate>Tue, 21 Jul 2026 13:46:54 +0000</pubDate>
                        <description><![CDATA[Hey everyone! &#x1f44b; I&#039;ve been diving into Checkmarx for our CI/CD pipeline integration this past week, and I&#039;m absolutely loving the concept of baking security right into the DevOps work...]]></description>
                        <content:encoded><![CDATA[Hey everyone! &#x1f44b; I've been diving into Checkmarx for our CI/CD pipeline integration this past week, and I'm absolutely loving the concept of baking security right into the DevOps workflow. It's like having a super-smart, always-vigilant code reviewer who never sleeps. However, I've hit a bit of a conceptual speed bump with the **'preset'** configuration.

From the API and YAML configs I've been tinkering with, I *think* I understand it's essentially a curated collection of rules or queries that the engine runs against the code. It determines *what* to look for. But I'm getting tangled in the practical implications.

Could someone break down, in simple terms:
*   What a preset *is* at its core? Is it like a rulebook, a filter, or a specific "lens" for the scan?
*   How choosing one preset over another changes the actual output and the developer experience?
*   Most importantly, **which one should a team typically start with?** We're a medium-sized web app team (JavaScript/TypeScript frontend, Python/Go backend) just starting our SAST journey.

Here's a snippet from my test config where I'm trying to set it:

```yaml
project-setting:
  preset: "Checkmarx Default"
  engine-configuration: "Default"
```
This seems to run a lot of checks. But I've also seen references to things like `"OWASP Top 10"`, `"PCI DSS"`, and even `"High and Medium Severity"`. The documentation lists them but doesn't quite get into the "why choose."

My hunch is that a more focused preset might mean:
*   **Faster scan times** (fewer rules to run)
*   **Less noise** in the results (more relevant findings)
*   But also, **potential blind spots** if you omit a crucial rule category

Is it a trade-off between comprehensiveness and signal-to-noise ratio? For those of you who have been through this, what's your go-to preset for a balanced, actionable first pass? And when do you branch out to more specific ones?

Happy integrating, Bob]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-checkmarx/">Checkmarx Reviews</category>                        <dc:creator>Bob Wilson</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-checkmarx/eli5-what-exactly-is-a-preset-and-which-one-should-i-use/</guid>
                    </item>
				                    <item>
                        <title>Checkmarx vs Coverity for C++ embedded systems</title>
                        <link>https://communities.stackinsight.net/community/cyber-checkmarx/checkmarx-vs-coverity-for-c-embedded-systems/</link>
                        <pubDate>Tue, 21 Jul 2026 13:07:42 +0000</pubDate>
                        <description><![CDATA[Hey everyone, been diving deep into SAST tools for our team&#039;s upcoming C++ embedded projects (think automotive/industrial). We&#039;re down to two finalists: Checkmarx and Coverity. I know both a...]]></description>
                        <content:encoded><![CDATA[Hey everyone, been diving deep into SAST tools for our team's upcoming C++ embedded projects (think automotive/industrial). We're down to two finalists: Checkmarx and Coverity. I know both are heavyweights, but I'm hoping some of you have real-world experience in a similar context.

Our main priorities are:
* **Accuracy (Precision):** Low false positive rate is critical. We can't afford to chase down hundreds of non-issues on tight hardware schedules.
* **C++ Standards Support:** We're using modern C++ (14/17) alongside some legacy code. Need good support for both.
* **Build Integration:** How well does it play with embedded toolchains (e.g., ARM GCC, Green Hills) and build systems like CMake?
* **Noise vs. Signal:** How "actionable" are the findings? Are they clear enough for engineers who aren't security specialists?

From my initial eval, Coverity seems to have a legendary reputation for depth and accuracy, especially for C/C++. But Checkmarx appears more flexible and modern in its platform approach, and I've heard good things about their query language for customizing rules.

Has anyone run both on similar codebases? I'm particularly curious about the *practical* differences in tuning them for an embedded environment. Was one significantly easier to integrate into a CI pipeline for a firmware project? Any gotchas with memory constraints or specific compiler quirks?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-checkmarx/">Checkmarx Reviews</category>                        <dc:creator>blakev</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-checkmarx/checkmarx-vs-coverity-for-c-embedded-systems/</guid>
                    </item>
				                    <item>
                        <title>Migrated from Fortify to Checkmarx - 6 month deployment report</title>
                        <link>https://communities.stackinsight.net/community/cyber-checkmarx/migrated-from-fortify-to-checkmarx-6-month-deployment-report/</link>
                        <pubDate>Tue, 21 Jul 2026 07:22:38 +0000</pubDate>
                        <description><![CDATA[Hi everyone. We switched from Fortify to Checkmarx about six months ago, mostly because of cost and wanting something more cloud-native friendly. I&#039;m new to cloud ops, so this was a big move...]]></description>
                        <content:encoded><![CDATA[Hi everyone. We switched from Fortify to Checkmarx about six months ago, mostly because of cost and wanting something more cloud-native friendly. I'm new to cloud ops, so this was a big move for our team.

The deployment on AWS using Terraform was okay, but we ran into some IAM and networking issues. The scanning itself is faster, but we're still figuring out the best way to manage the results. The cost is lower, but the learning curve for the policy management felt steep.

Anyone else made this switch? How do you handle the security findings in your CI/CD pipeline now? Also, any tips for keeping the Checkmarx infra costs predictable on AWS?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-checkmarx/">Checkmarx Reviews</category>                        <dc:creator>cloud_ops_learner</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-checkmarx/migrated-from-fortify-to-checkmarx-6-month-deployment-report/</guid>
                    </item>
				                    <item>
                        <title>Just built a comparison matrix: Checkmarx, Coverity, and Klocwork for our C++ code.</title>
                        <link>https://communities.stackinsight.net/community/cyber-checkmarx/just-built-a-comparison-matrix-checkmarx-coverity-and-klocwork-for-our-c-code/</link>
                        <pubDate>Tue, 21 Jul 2026 06:59:15 +0000</pubDate>
                        <description><![CDATA[Just finished a forced march evaluating these three for a large legacy C++ codebase. The marketing sheets all look the same. The actual experience? Not so much.

Checkmarx felt like it was b...]]></description>
                        <content:encoded><![CDATA[Just finished a forced march evaluating these three for a large legacy C++ codebase. The marketing sheets all look the same. The actual experience? Not so much.

Checkmarx felt like it was bolting a SAST tool onto a language it doesn't truly love. The C++ analysis was... superficial. Found the trivial stuff, choked on our templates. Coverity is the thorough, plodding engineer. Deep, accurate, but you'll need a coffee while it runs. Klocwork was the surprise - faster than Coverity, deeper than Checkmarx for our specific use case. But its UI is stuck in 2010. So you pick your poison: slow and accurate, fast and ugly, or the one that looks modern but skims the surface.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-checkmarx/">Checkmarx Reviews</category>                        <dc:creator>crm_hopper</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-checkmarx/just-built-a-comparison-matrix-checkmarx-coverity-and-klocwork-for-our-c-code/</guid>
                    </item>
							        </channel>
        </rss>
		