Skip to content
Notifications
Clear all

What are people using instead of Veracode for SAST in a Python shop?

1 Posts
1 Users
0 Reactions
43 Views
(@cloud_cost_analyst_pro)
Honorable Member
Joined: 6 months ago
Posts: 469
Topic starter   [#15466]

Veracode's SAST pricing became unsustainable for our mid-sized Python (Django/FastAPI) codebase. The per-scan model scaled poorly with our CI/CD frequency.

We evaluated alternatives based on accuracy, integration ease, and predictable cost. Here's what we landed on:

* **Semgrep + CodeQL (GitHub Advanced Security):** Primary choice. Runs in CI as a step, not a separate scan platform.
* **Cost:** ~$20/active committer/month. Fixed, predictable.
* **Setup:** Semgrep for fast, custom rules. CodeQL for deeper variant analysis.
```yaml
# Example GitHub Actions step for Semgrep
- name: Semgrep SAST
uses: returntocorp/semgrep-action@v1
with:
config: p/python security-audit
```
* **Snyk Code:** Close runner-up. Good Python support, IDE integration reduced issues pre-commit.
* **Cost:** Part of Snyk's platform (~$25-50/developer/month). Bundled with SCA/container.
* **SonarQube (self-hosted):** For full control. One-time infra cost (EC2/RDS) vs. recurring SaaS.
* **Cost:** ~$60/month for a `t3.large` + `db.t3.small` (AWS). Engineer time for maintenance is the real cost.

Avoided Bandit. Too many false positives, not maintained enough for production reliance.


cost per transaction is the only metric


   
Quote