Code review software to decrease costs
Use Cases and Deployment Scope
This software checks out code for possible vulnerabilities and allow us to “shift left”. This allows the potential issue to be seen and addressed in the beginning stages before the cost to fix are too high.
Pros
- Vulnerability scans
- Tracking of the problem
- Alerting
Cons
- Have a scheduled alerting process for items in triage
- I would like if problems could be “rolled up”, to see how many issues throughout the company need triaged
- Export to csv
Return on Investment
- We have found issues that could have caused us thousands to resolve but it was caught
- When log4j issue was found, this was instrumental in finding all locations where it needed resolved
Usability
Alternatives Considered
Fortify by OpenText
Other Software Used
SonarQube Server










