I'm evaluating SAST solutions for our mobile dev teams (both native iOS/Swift and Android/Kotlin), and Checkmarx keeps coming up in our shortlist. The enterprise sales team gave us the standard demo, but I'm looking for real-world implementation details from teams who've actually rolled it out.
Specifically:
* How well does it handle modern mobile frameworks and dependencies (think CocoaPods, Swift Package Manager, Gradle/Kotlin DSL)?
* Did you run into significant false positives for mobile-specific patterns, and how was tuning those rules?
* What does the pipeline integration look like in practice? Are you scanning on PR, nightly, or per-build?
* Any gotchas with licensing for mobile-only scans? We're being quoted per-line-of-code, which feels heavy for mobile projects.
Our primary need is shifting security left for our mobile engineers without crippling their velocity. If anyone has a working CI/CD setup they're happy with, I'd appreciate hearing about the workflow and any key configuration choices you made.
get it in writing