Checkmarx Software Composition Analysis Primary Use Case

GG
Sr. Director Global Solutions Development at a energy/utilities company with 10,001+ employees

We use Checkmarx Software Composition Analysis for scanning software for security vulnerabilities.

View full review »
Sujata Sujata Ghadage - PeerSpot reviewer
Sr Manager consultant - Digital assurance Services at ADROSONIC

Checkmarx Software Composition Analysis is a good tool I have used in multiple projects, especially in banking and insurance domains. It is a good tool for static code review and SAST analysis. I want to understand the cost of the other tools in the market compared to Checkmarx Software Composition Analysis because our company needs to make recommendations to our customers. Considering the budget of our company's customers, we need to make recommendations to them.

My company uses the tool to support banking applications by indulging in static code analysis.

View full review »
DS
VP Software Developer/Architect at a financial services firm with 5,001-10,000 employees

We use SCA for security scanning and routing. The replica is really good. It's supposed to measure vulnerabilities.

We use SCA to scan our code for vulnerabilities on a regular basis. Every new release is assessed for vulnerabilities using Checkmarx's SCA tool.

View full review »
Buyer's Guide
Checkmarx Software Composition Analysis
April 2024
Learn what your peers think about Checkmarx Software Composition Analysis. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.
Harsh Soni - PeerSpot reviewer
Cyber Security Engineer at Rah Infotech Pvt Ltd

Basically, I review the code of the developer and find the vulnerability in that, and then I get back to the developer to resolve and remediate the vulnerability on the dashboard. We also review the source code of the developer just as if some developer cracked the code for the kind of product development or production phase, or initial phase. We then review Checkmarx with the support of the developer and get it corrected right away at that time.

View full review »
MH
Penetration Tester & Information Security Expert at a comms service provider with 11-50 employees

I use it to check software library versions for potential vulnerabilities.

View full review »
GG
Sr. Director Global Solutions Development at a energy/utilities company with 10,001+ employees

We use it for scanning .NET and Java applications. We are using its latest version.

View full review »
SN
System Engineer at a manufacturing company with 5,001-10,000 employees

Checkmarx Software Composition Analysis is used for detecting vulnerabilities in the open source software component of a project.

View full review »
Abner Silva - PeerSpot reviewer
Cloud Security Analyst at a agriculture with 1-10 employees

We have the tool integrated into our CI/CD pipeline. 

View full review »
Cuneyt KALPAKOGLU Phd. - PeerSpot reviewer
Founder & Chairman at Endpoint-labs Cyber Security R&D

The purpose of software composition analysis is to identify any open-source components that may contain vulnerabilities. It is especially important because, nowadays, developers often download algorithms from the internet while they are developing software, but these downloaded components need to be scanned for vulnerabilities.

Additionally, developers may not pay close attention to open-source components' legal and licensing aspects, which can cause serious problems. Therefore, it is necessary to use software composition analysis as protection, and Checkmarx's SCA tool is very beneficial for this purpose.

View full review »
SN
System Engineer at a manufacturing company with 5,001-10,000 employees

My customers' main use cases for this solution are based on its open-source library. Another use case is with supply chain attacks because It checks the integrity of the library and not just the hash, checksum, or version.

View full review »
KN
Frontend Developer at a tech services company with 51-200 employees

We use Checkmarx Software Composition Analysis in our development process. We use it when we work with end users for the development of software.

View full review »
Cuneyt KALPAKOGLU Phd. - PeerSpot reviewer
Founder & Chairman at Endpoint-labs Cyber Security R&D

We are an IT security research and development lab. We have around 22 engineers doing research and testing and developing add-ons and complementary solutions. We are the strategic development partner of Checkmarx. We are using the latest version of this solution.

View full review »
Buyer's Guide
Checkmarx Software Composition Analysis
April 2024
Learn what your peers think about Checkmarx Software Composition Analysis. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.