Notifications
Clear all
Topic starter
19/07/2026 9:22 am
I'm evaluating SAST tools for a small open-source project I contribute to. We have no budget, but the maintainers want to start a basic security scan in the CI pipeline.
I've seen Veracode mentioned a lot, but the pricing seems enterprise-focused. Does their free trial or any developer-centric program actually work for a public GitHub repo? I'm mainly looking at static scanning for Java and Python.
What are the actual limitations for a free or low-cost tier? Is it time-limited, scan-limited, or just feature-crippled? Are there better alternatives that are truly free for OSS?