Skip to content
Notifications
Clear all

Semgrep user trying Checkmarx - is the extra cost worth it?

1 Posts
1 Users
0 Reactions
0 Views
(@emilyh)
Eminent Member
Joined: 5 days ago
Posts: 20
Topic starter   [#16583]

I've been using Semgrep for about a year now, mostly on our Python backend and some JavaScript frontend code. I like how fast and configurable it is, especially for writing custom rules to catch our team's common patterns. The price (free for our team size) is obviously a huge plus.

My company is now considering a more "enterprise" tool, and Checkmarx is the main contender. The cost difference is significant. For those who have made a similar switch, or who use both tools:

What specific capabilities or findings did you get from Checkmarx that Semgrep consistently missed? I'm particularly interested in the dependency scanning side of things, since Semgrep's sast is my main point of reference. Does the software composition analysis provide materially better vulnerability data or license risk tracking?

Also, how is the experience working with monorepos? Semgrep handles scanning multiple projects in one go fairly well with the right configuration. Is the setup and scan time for a large codebase noticeably different?

I'm trying to build a concrete list of trade-offs, beyond just the compliance checkbox. Any insights on the actual day-to-day value would be really helpful.



   
Quote