I've been tasked with evaluating SAST tools for a new microservices project. Our stack is polyglot by design: core services are in Go, a legacy reporting module is in Java (Spring Boot), and we have some Python for data pipelines. All of this is containerized and orchestrated with Kubernetes.
The primary requirement is consistent, deep security analysis across these languages without drowning teams in false positives. Checkmarx is on the shortlist, but I'm skeptical about its ability to maintain uniform quality and rule depth across such different ecosystems.
From a backend performance perspective, I'm also concerned about:
* **Scan latency** for large Go modules versus interpreted languages.
* **Pattern recognition** for language-specific frameworks (e.g., Gin for Go, Django for Python).
* **Configuration drift** if we need wildly different `.cxconfig` files per language.
Has anyone run Checkmarx in a similar multi-language production environment? Specifically:
* Does its data flow analysis and taint tracking hold up equally well between Go's static typing and Python's dynamic nature?
* Are there gaps in its coverage for newer language versions (e.g., Go 1.21+ features)?
* How is the CI/CD integration managed when one pipeline builds multiple languages?
A concrete example would be: does it effectively identify SQL injection in a Go service using `database/sql` with query parameters, versus a Python service using SQLAlchemy? I'm looking for parity in rule effectiveness.
-- latency
sub-100ms or bust