Skip to content
Notifications
Clear all

Veracode alternatives that are not Checkmarx or Fortify?

2 Posts
2 Users
0 Reactions
27 Views
(@bench_beast)
Noble Member
Joined: 4 months ago
Posts: 723
Topic starter   [#15014]

Need alternatives for SAST/SCA. Checkmarx and Fortify are out. Budget is a factor but need decent accuracy.

Ran a basic test suite (OWASP Benchmark style) against a few platforms. Results are raw, not comprehensive.

* **Semgrep (SAST):** High recall on simple patterns, low setup. CLI is fast. Rule tuning is mandatory.
```bash
semgrep --config auto . --json > results.json
```
False positives were ~40% in my test on a Java Spring app.

* **Snyk Code (SAST) & Open Source (SCA):** Good integration (IDE, CI). SCA database is strong. Found some injection flaws others missed, but missed some hard-coded credential patterns.

* **SonarQube (SAST):** On-prem option. Needs significant configuration out of the box to be useful for security. More of a quality gate.

What are you all using? Need something that integrates into CI/CD without a huge maintenance overhead. Specifically looking for:
* Low false positive rate
* Fast scan times
* Support for Python/Java/Go

Pricing models (per repo, per dev, per scan) also a factor.

- bench_beast


Benchmarks don't lie.


   
Quote
(@cloud_migrate_tom)
Reputable Member
Joined: 6 months ago
Posts: 290
 

Hey, thanks for posting your test results. That's really helpful. I'm in a similar boat looking for a Veracode replacement for some older Java services we're moving to AWS.

> Low false positive rate

Did you find Semgrep's 40% false positive rate went down after tuning the rules? I've heard it gets better but I'm worried about the time investment to get there. We're a small team.

For CI/CD integration, I've been looking at GitLab's built-in SAST. It's based on Semgrep but comes with a default rule set. The scans are fast and it's included in their premium tier, which could work out if you're already using them. Might be worth a trial for your Python/Java/Go stack.


One step at a time


   
ReplyQuote