ShiftLeft ShiftLeft CORE

Basic Information
Software cost
Free, Paid
Software license
Apache License 2.0, Proprietary
Process Integration
Analysis inputs
Pre-compiled binary, Compilation along with all dependencies, Source code
SCM Integration
AWS CodeCommit, Bazaar, CVS, Fossil, Git, Helix Core, Kiln, Mercurial, Microsoft Team Foundation Server, Subversion
Pre-commit invocation from workstation
CI Integration
Generic command line interface (CLI), Ant, Apycot, Azure DevOps, Bamboo, Bazel, Bitbucket Pipelines, Bitbucket Server, Chef, CircleCI, Codeship, Drone, GitLab CI, Gradle, Hudson, Jenkins, Maven, MSBuild, SBT, Team Foundation Server, TeamCity, Travis CI, Xcodebuild, Zend Server, Ansible, Appveyor, CodEnvy, Puppet, Apache Gump, CruiseControl, Vexor, Concourse-CI, IBM UrbanCode AnthillPro
Able to analyze incremental changes to code (commit, patch, pull request)
Can schedule scans
API method to report results in SARIF format
API method to report results in XML/JSON/CSV format
Supported programming languages
.NET, Angular, C#, Go, Java, JavaScript, JSP, Kotlin, Python, Scala, Terraform, TypeScript, Vue.js
Supported development frameworks
.NET Core, Node.js, React Native, Spring
Claimed Weakness Coverage
Claimed Weakness Coverage information hasn't been collected yet for this analyzer.
Really want it? Let us know.
Checker Customization
Can disable checkers
Can customize checker logic
First-class API to create new checkers
Speed & Scalability
Parallelizes on one host
Parallelizes across more than one host
Scan duration times courtesy of the
OWASP Benchmark v1.2beta
Highest scoring SAST in the industry
Results Quality
Provides explanation of warning
Provides severity of warning
Provides confidence information about warning
Provides code context around warning
Provides control flow context for warning
Provides data flow context for warning
Provides code coverage information per checker
Results suppression even after code changes
Show differences in results set to previous scan
Integration with external remediation bug tracker
Two-way data sync with external remediation bug tracker
Graphical user interface (GUI)
Ability to search results
Results remediation workflow
Hierarchical reporting for multiple projects, teams, departments, etc.
Filter results by compliance standard
CWE All, CWE/SANS Top 25 Most Dangerous Software Errors (2011), OWASP Top Ten (2017)
Centralized reporting
Installation guide or documentation
User/operator guide or documentation
Integration guide or API documentation