Does anyone have a recommendation for a SAST / DAST scanning tool that supports a variety of languages (front end and backend), has minimal false positives, supports automation (via API or other), integrates with IDEs and integrates with GitLab?

3.8k viewscircle icon1 Upvotecircle icon6 Comments
Sort by:
Chief Information Security Officer in Software2 years ago

There are several reputable SAST/DAST tools in the market that cater to a wide variety of languages and offer integration with IDEs and GitLab. It's crucial to understand that no scanning tool will have zero false positives, but some have invested heavily in reducing them. When considering a solution, it's essential to evaluate it based on your specific requirements and conduct a proof of concept. Tools like Snyk, Checkmarx, Fortify, and Veracode are well-regarded in the industry, but the best fit would depend on your organization's specific context and needs. I'd recommend engaging with multiple vendors, assessing their tool's capabilities, and gathering feedback from peers in the industry to make an informed decision.

Lightbulb on1
Director & Founder2 years ago

For SAST tools you can consider Sonarqube and Snyk.
For DAST Beagle Security, Intruder, and Detectify seems to do a good job.

CTO in Software5 years ago

For SAST and IAST, I'd talk to Checkmarx. Then if you want to layer on DAST, talk to Synopsys

CTO in Software5 years ago

DAST - Rapid7 AppSpider
DAST - SonarQube

Chief Security Officer in Software5 years ago

We are in the process of testing GitLab Ultimate. It has security features like SAST/DAST and fuzzing. I have also used Veracode in the past.

Lightbulb on1 circle icon1 Reply
no title2 years ago

Gitlab doesn&#39;t have its own SAST and DAST features but it integrates with other open source tools for SAST and DAST. I tried Gitlab once, I prefer Github security a lot.<br>Recently also gave a talk on devsecops and here are some commercial open source tools I recommended for devsecops roadmap in the talk. <br><br> <br><br>Security check<br><br> <br><br>Tools<br><br>1. Secure Access to Infrastructure <br><br> <br><br>Teleport<br><br>2. SAST<br><br> <br><br>Semgrep<br><br>3. Secret Scanning<br><br> <br><br>Trufflehog<br><br>4. IaC scanning<br><br> <br><br>TerraScan<br><br>5. Dependencies<br><br> <br><br>Dependabot<br><br>6. DAST/ IAST/ API Security Testing<br><br> <br><br>Akto.io<br><br>

Content you might like

Updates should be released daily.6%

Updates should be released weekly61%

Updates should stay monthly.22%

Updates should be pushed quarterly.9%

Other (comment below)

View Results

As vulnerable as tech sector37%

Less vulnerable than tech sector52%

Not vulnerable5%

Don't know3%

View Results