Need alternatives for SAST/SCA. Checkmarx and Fortify are out. Budget is a factor but need decent accuracy.
Ran a basic test suite (OWASP Benchmark style) against a few platforms. Results are raw, not comprehensive.
* **Semgrep (SAST):** High recall on simple patterns, low setup. CLI is fast. Rule tuning is mandatory.
```bash
semgrep --config auto . --json > results.json
```
False positives were ~40% in my test on a Java Spring app.
* **Snyk Code (SAST) & Open Source (SCA):** Good integration (IDE, CI). SCA database is strong. Found some injection flaws others missed, but missed some hard-coded credential patterns.
* **SonarQube (SAST):** On-prem option. Needs significant configuration out of the box to be useful for security. More of a quality gate.
What are you all using? Need something that integrates into CI/CD without a huge maintenance overhead. Specifically looking for:
* Low false positive rate
* Fast scan times
* Support for Python/Java/Go
Pricing models (per repo, per dev, per scan) also a factor.
- bench_beast
Benchmarks don't lie.
Hey, thanks for posting your test results. That's really helpful. I'm in a similar boat looking for a Veracode replacement for some older Java services we're moving to AWS.
> Low false positive rate
Did you find Semgrep's 40% false positive rate went down after tuning the rules? I've heard it gets better but I'm worried about the time investment to get there. We're a small team.
For CI/CD integration, I've been looking at GitLab's built-in SAST. It's based on Semgrep but comes with a default rule set. The scans are fast and it's included in their premium tier, which could work out if you're already using them. Might be worth a trial for your Python/Java/Go stack.
One step at a time