Veracode delivers great overall SCA value
May 28, 2020
Veracode delivers great overall SCA value

Score 9 out of 10
Vetted Review
Verified User
Modules Used
- Static Analysis (SAST)
- Software Composition Analysis (SCA)
Overall Satisfaction with Veracode
Veracode (& SourceClear) has been used for Static Code Analysis & Software Composition Analysis for some of our products.
Pros
- Software Composition Analysis - found 3rd-party vulnerability issues quickly on each scan
- Static Code Analysis - found specific security issues that detect hidden backdoors and malicious code
- Static Code Analysis works very well for node.js scan.
Cons
- Embedded C++ scan doesn't support ARM platform.
- Enable automatic import for SourceClear found issues for each scan into JIRA (Cloud).
- Identifying 3rd-party vulnerability issues before shipping software to the production site is a huge win for us.
- Resolving potential malicious code found from SCA scan helps tremendously as well.
Veracode has SourceClear now, which is a huge win being able to scan for 3rd-party vulnerability issues.
Veracode has node.js SCA scan that works well for us (that's why we chose Veracode in the first place).
Veracode has node.js SCA scan that works well for us (that's why we chose Veracode in the first place).
Do you think Veracode delivers good value for the price?
Yes
Are you happy with Veracode's feature set?
Yes
Did Veracode live up to sales and marketing promises?
Yes
Did implementation of Veracode go as expected?
Yes
Would you buy Veracode again?
Yes
Comments
Please log in to join the conversation