静的解析 - kocya-dev/note GitHub Wiki

Codacy / GHAS CodeQL / Snyk

  • 言語サポート
  • PRチェック、CI/CD組み込みの手間、閲覧性
  • Secrets scanningのような機能の代替手段

https://sourceforge.net/software/compare/Codacy-vs-CodeSonar-vs-Snyk/

Codacy Snyk CodeSonar GitHub Advanced Security ---
言語 大差なし
IaC - Cloud Formation/Terraform/Kubernetes
規格 IEC 61508 (機能安全) - - - 他にはC/C++testなど
ISO 26262 (機能安全) - - - 他にはC/C++testなど
CENELEC EN 50128(ソフトウェア安全) - - - 他にはVisure など
ISO/SAE 21434 (自動車、リスク管理) - - -
DO 178C / DO-330 (機能安全 開発保証レベル) - - -
連携 GitHub
IDE VSCode -
VS - - -
InteliJ - -
Eclipse - -
機能 AI Code Review - -
AI Coding Assistants - - -
AI Tools - - -
Application Security - - -
Automated Testing - - -
Code Coverage - - -
Code Review - - -
Cloud Security Posture Management (CSPM) - -
Container Security - - -
Cybersecurity - - -
DORA Metrics - - -
Dynamic Application Security Testing (DAST) - - -
IT Security - - -
Network Security - - -
Software Bill of Materials (SBOM) - -
Software Composition Analysis (SCA) - - -
Software Development Analytics - - -
Static Application Security Testing (SAST) -
Static Code Analysis
Vulnerability Management - - -
Vulnerability Scanners - - -
静的解析 Analytics / Reporting -
Code Standardization / Validation - -
Multiple Programming Language Support -
Provides Recommendations - -
Standard Security/Industry Libraries - -
Vulnerability Management -