Badges

135 Points
2 Years
Top 5

User Activity

3 months ago
Fortify Static Code Analyzer is actually NOT an SCA (Software Composition Analysis) tool! It competes more with Checkmarx and Veracode
8 months ago
For application security you ideally need SAST, SCA and DAST. You need all three as they essentially measure different things: SAST identifies bad coding practices that potentially could be exploited SCA identifies known vulnerabilities in the libraries and components you…
9 months ago
Clients that have benchmarked our solution against both BlackDuck and Veracode have noted that BlackDuck identifies more vulnerabilities, but also has more false positives. Note that MergeBase is more accurate in identifying more vulnerabilities with less false positives…
9 months ago
MergeBase.com provides the most accurate identification of vulnerabilities across all stages of the application's lifecycle

Answers

3 months ago
Software Composition Analysis (SCA)
9 months ago
Software Composition Analysis (SCA)
9 months ago
Application Security