Checkmarx Software Composition Analysis Valuable Features

GG
Sr. Director Global Solutions Development at a energy/utilities company with 10,001+ employees

The most valuable feature of Checkmarx Software Composition Analysis is the comprehensive security scan.

View full review »
Sujata Sujata Ghadage - PeerSpot reviewer
Sr Manager consultant - Digital assurance Services at ADROSONIC

The most valuable feature of the solution stems from the rules it offers. I also like the coverage it provides while having to deal with fewer false positives.

View full review »
DS
VP Software Developer/Architect at a financial services firm with 5,001-10,000 employees

In my experience, a valuable feature is configurability. Moreover, it is easy to understand security results and to scan for vulnerabilities, and also we can access databases to load our information for presentation purposes.  So, basically, database configuration on the back end. We use in-house installation.

View full review »
Buyer's Guide
Checkmarx Software Composition Analysis
March 2024
Learn what your peers think about Checkmarx Software Composition Analysis. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
765,234 professionals have used our research since 2012.
Harsh Soni - PeerSpot reviewer
Cyber Security Engineer at Rah Infotech Pvt Ltd

The integration part is easy. It will also be compatible with a developer because a lot of tools are needed to write code, just like in Java. And then, users have the Eclipse software tool that writes code in Java, while Checkmarx also supports integration with Eclipse. So it becomes much easier for developers to find the vulnerabilities and see if they are correct or if they need to be correct. Checkmarx will highlight those lines and words which will be vulnerable on that code. They will highlight, and they will prompt, but we have to correct it.

View full review »
MH
Penetration Tester & Information Security Expert at a comms service provider with 11-50 employees

I appreciate the user-friendly interface. The GUI is excellent, providing detailed information on outdated versions, including version numbers and the flow of library calls. This allows me to plan and prioritize library changes based on potential vulnerabilities, even if the affected library is indirectly used in my project. The tool offers specific guidance on addressing these issues.       

View full review »
Cuneyt KALPAKOGLU Phd. - PeerSpot reviewer
Founder & Chairman at Endpoint-labs Cyber Security R&D

The most valuable feature is that it can ensure the security of the software when downloading open-source components from the internet. It is the first and foremost benefit. Secondly, even though these components may be shared or free, there can still be license issues, and young developers may not pay attention to this aspect, which can be very dangerous and lead to serious penalties in the future.

View full review »
GG
Sr. Director Global Solutions Development at a energy/utilities company with 10,001+ employees

One of the strong points of this solution is that it allows you to incorporate it into a CICB pipeline. It has the ability to do incremental scans. If you scan a very large application, it might take two hours to do the initial scan. The subsequent scans, as people are making changes to the app, scan the Delta and are very fast. That's a really nice implementation. The way they have incorporated the functionality of the incremental scans is something to be aware of. It is quite good.

It has been very solid. We haven't really had any issues, and it does what it advertises to do very nicely.

View full review »
SN
System Engineer at a manufacturing company with 5,001-10,000 employees

What's most valuable in Checkmarx Software Composition Analysis is that it provides security from the start. In the traditional approach, an enterprise or company validates the solution before launching to a production environment, but in the modern approach, security must be checked and provided from the beginning and from the design, and this is where Checkmarx Software Composition Analysis comes in. The solution helps you make sure that every open-source application that you use is secure, and that there's no vulnerability inside that open-source application.

View full review »
SN
System Engineer at a manufacturing company with 5,001-10,000 employees

Checkmarx unifies all the features in its service.

View full review »
KN
Frontend Developer at a tech services company with 51-200 employees

What I found most valuable in Checkmarx Software Composition Analysis is its ability to identify vulnerabilities in components, especially if some critical issues exist.

View full review »
Cuneyt KALPAKOGLU Phd. - PeerSpot reviewer
Founder & Chairman at Endpoint-labs Cyber Security R&D

It is very easy and user friendly. It never requires any kind of technical support. You can do everything on your own.

View full review »
Buyer's Guide
Checkmarx Software Composition Analysis
March 2024
Learn what your peers think about Checkmarx Software Composition Analysis. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
765,234 professionals have used our research since 2012.