Checkmarx One and SonarQube Cloud are well-known tools in the security and code analysis category. Checkmarx One is considered to have the upper hand due to its comprehensive scanning capabilities and reduction in false positives.
Features: Checkmarx One offers comprehensive code scanning without needing compilation, supports a wide range of languages, and allows for customization. SonarQube Cloud is noted for code smell detection, bugs identification, and seamless integration with version control tools.
Room for Improvement: Checkmarx One could enhance false positive management, increase language support, and improve report detail. SonarQube Cloud could benefit from better initial documentation, report customization, and false positive management.
Ease of Deployment and Customer Service: Checkmarx One supports private, hybrid, and public cloud deployments, offering versatile IT solutions with generally good support. SonarQube Cloud, a public cloud-only service, simplifies deployment and has well-rated support, though service speed could improve.
Pricing and ROI: Checkmarx One may be expensive for smaller teams, but it promises strong ROI with extensive security features. SonarQube Cloud offers competitive pricing with a line-of-code model, making it more accessible for larger codebases, providing value through seamless integration.
It is easily integrable with the CI/CD pipeline and supports multiple projects with its extensive plugin options.
The customer service and support for SonarQube Cloud are responsive and helpful.
There are limitations, and it seems to have fewer capabilities than Veracode.
SonarQube Cloud is a scalable product, and I rate its scalability at seven out of ten.
It is a quite stable solution.
From my team's feedback, it is almost an eight out of ten.
I would like to see SonarQube Cloud provide more detailed solutions for fixing code issues, especially solutions related to CVEs.
SonarQube Cloud could improve its vulnerability detection compared to Veracode.
SonarQube Cloud is roughly equivalent in cost to Veracode, maybe a little cheaper.
It gives precise reports compared to Coverity and has a slightly lower number of false positives.
I find SonarQube Cloud very easy to use and simple to integrate initially.
Checkmarx One is an enterprise cloud-native application security platform focused on providing cross-tool, correlated results to help AppSec and developer teams prioritize where to focus time and resources.
Checkmarx One offers comprehensive application scanning across the SDLC:
Checkmarx One provides everything you need to secure application development from the first line of code through deployment and runtime in the cloud. With an ever-evolving set of AppSec engines, correlation and prioritization features, and AI capabilities, Checkmarx One helps consolidate expanding lists of AppSec tools and make better sense of results. Its capabilities are designed to provide an improved developer experience to build trust with development teams and ensure the success of your AppSec program investment.
SonarQube Cloud offers static code analysis and application security testing, seamlessly integrating into CI/CD pipelines. It's a vital tool for identifying vulnerabilities and ensuring code quality before deployment.
SonarQube Cloud is widely used for its ability to integrate with tools like GitHub, Jenkins, and Bitbucket, providing critical feedback at the pull request level. It's designed to help organizations maintain clean code by acting as a quality gate. This service supports development methodologies including sprints and Kanban for ongoing vulnerability management. While appreciated for its dashboard and integration capabilities, some users find initial setup challenging and note the need for enhanced documentation. The recent addition of mono reports and microservices support offers deeper insights into security and code quality, though container testing limitations and false positives are noted drawbacks. Manual intervention is sometimes required to address detailed reporting, with external tools being necessary for comprehensive analysis. Notifications for larger teams during serious issues and streamlined integration of new features are also areas of improvement.
What are the key features of SonarQube Cloud?In specific industries, SonarQube Cloud finds application in finance and healthcare where code integrity and security are paramount. It allows teams to identify critical vulnerabilities early and ensures that software development aligns with industry regulations and standards. By continuously analyzing code, it aids organizations in deploying secure and reliable applications, fostering trust and compliance.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.