What are some good open-source SAST tools to use alongside Semgrep and Trivy?

0
9
Asked By TechieNinja92 On

I'm curious if there are any other solid open-source SAST tools that I could add to my workflow, particularly to complement Semgrep and Trivy. Any recommendations?

5 Answers

Answered By CodeExplorer77 On

Have you tried DefectDojo? It’s a great tool for vulnerability management that you can integrate into your setup without much hassle.

Answered By RiskAnalyzer45 On

Just a heads up, most open-source SAST tools tend to excel in specific areas but can fall short in others. Many organizations use them for early warning signs and then turn to more comprehensive tools like Checkmarx for deeper analysis when the prioritization of findings becomes crucial.

Answered By SecuritySavant88 On

Definitely check out the AppThreat tools. They have a family of services that can help with various aspects of security.

Answered By DevOpsGuru21 On

If you're focused on container security, I recommend looking into Echo vulnerability-free container images. They work really well with Trivy and Grype, even though they're paid—they can significantly reduce vulnerability noise and alert fatigue.

Answered By DevSecOpsWiz On

It really helps to know what stack you're working with. Using too many tools can just slow things down and create more noise. That said, I've had good experiences with Datadog's Guarddog for supply chain analysis, along with OPA for guardrails.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.