description Checkmarx SAST Overview
help Checkmarx SAST FAQ
Does Checkmarx SAST scan compiled applications or source code?
Checkmarx SAST analyzes source code and related application files without executing the program. That lets teams detect issues such as SQL injection and cross-site scripting during development rather than waiting for a running deployment.
Which programming languages can Checkmarx SAST scan?
Its supported set includes widely used languages and frameworks across Java, JavaScript, C#, Python, PHP, and other ecosystems. Checkmarx publishes an engine-specific compatibility list because language and framework coverage changes between releases.
How is Checkmarx SAST different from Checkmarx SCA?
SAST searches a team's own source code for insecure data flows and coding patterns. Software Composition Analysis, or SCA, inventories third-party packages and flags known vulnerabilities or license risks in those dependencies.
Can Checkmarx SAST block a pull request?
It can be integrated into CI pipelines and source-control workflows so a scan result is evaluated before code is merged. Whether a pull request actually fails depends on the organization's configured severity thresholds and policies.
explore Explore More
Similar to Checkmarx SAST
See all arrow_forwardReviews & Comments
Write a Review
Be the first to review
Share your thoughts with the community and help others make better decisions.