For application security you ideally need SAST, SCA and DAST. You need all three as they essentially measure different things
SAST identifies bad coding practices that potentially could be exploited
SCA identifies known vulnerabilities in the libraries and components you…
Clients that have benchmarked our solution against both BlackDuck and Veracode have noted that BlackDuck identifies more vulnerabilities, but also has more false positives. Note that MergeBase is more accurate in identifying more vulnerabilities with less false positives…