Does anyone have a recommendation for a SAST / DAST scanning tool that supports a variety of languages (front end and backend), has minimal false positives, supports automation (via API or other), integrates with IDEs and integrates with GitLab?

Security We are in the process of testing GitLab Ultimate. It has security features like SAST/DAST and fuzzing. I have also used Veracode in the past.

3 comments

https://www.pulse.qa

Pulse User

We are in the process of testing GitLab Ultimate. It has security features like SAST/DAST and fuzzing. I have also used Veracode in the past.

Pulse User

DAST - Rapid7 AppSpider DAST - SonarQube

Pulse User

For SAST and IAST, I'd talk to Checkmarx. Then if you want to layer on DAST, talk to Synopsys