Badges

40 Points
5 Years

User Activity

Over 3 years ago
Fortify Static Code Analyzer is actually NOT an SCA (Software Composition Analysis) tool! It competes more with Checkmarx and Veracode
Almost 4 years ago
For application security you ideally need SAST, SCA and DAST. You need all three as they essentially measure different things SAST identifies bad coding practices that potentially could be exploited SCA identifies known vulnerabilities in the libraries and components you…
Almost 4 years ago
Clients that have benchmarked our solution against both BlackDuck and Veracode have noted that BlackDuck identifies more vulnerabilities, but also has more false positives. Note that MergeBase is more accurate in identifying more vulnerabilities with less false positives…
Almost 4 years ago
MergeBase.com provides the most accurate identification of vulnerabilities across all stages of the application's lifecycle

Answers

Over 3 years ago
Software Composition Analysis (SCA)
Almost 4 years ago
Application Security Tools
Almost 4 years ago
Application Security Tools
Almost 4 years ago
Application Security Tools