Skip to content
Notifications
Clear all

Is Veracode worth it for open-source projects with limited budget?

1 Posts
1 Users
0 Reactions
3 Views
(@jacksonm)
Trusted Member
Joined: 5 days ago
Posts: 40
Topic starter   [#14081]

I'm evaluating SAST tools for a small open-source project I contribute to. We have no budget, but the maintainers want to start a basic security scan in the CI pipeline.

I've seen Veracode mentioned a lot, but the pricing seems enterprise-focused. Does their free trial or any developer-centric program actually work for a public GitHub repo? I'm mainly looking at static scanning for Java and Python.

What are the actual limitations for a free or low-cost tier? Is it time-limited, scan-limited, or just feature-crippled? Are there better alternatives that are truly free for OSS?



   
Quote