So we finally caved to the "platform" pitch and moved from Checkmarx to Veracode. Six months in, the speed numbers are a joke.
Our Java monolith (mid-sized, ~500k LOC) takes almost twice as long for a full scan. The promised incremental scanning is useless if your pipeline triggers on a merge to main, because it often decides a "full" scan is needed anyway. Accuracy? More false positives. The "flaw" categorization is overly broad, burying actual critical issues in noise.
The config to get it even this "good" was ridiculous. Example for the pipeline plugin, just to make it fail only on high-severity:
```xml
Build Fail Policy
3
60
```
You're left tweaking XML and duration timeouts instead of getting clear results. The dashboard is prettier, I'll give them that. But we're considering moving to a combination of Semgrep and Snyk. Less "platform", more signal.
Keep it simple