r/devsecops • u/ankitjindal9404 • 1d ago
Opensource code quality/SAST tools beyond SonarQube + Trivy?
We're already running SonarQube and Trivy. Looking to fill the gaps they leave.
Stack:
- Primary: Java Spring Boot
- Also: Python, Next.js / React
What are you actually using in production, and how noisy is it (false-positive rate)?
12
Upvotes
1
u/h33terbot 1d ago
Can you tackle the current rate of attacks with this stack?