Search code examples
securitytestingsonarqubebdd

Can we use sonarQube to completely replace the custom-build security testing scenarios?


I see that sonarQube can be used for measuring code quality and for finding security vulnerabilities. I am having hard time deciding whether to replace the custom-build BDD security testing scenarios with sonarQube testing for my backend services. BDD testing usually takes longer than the sonarQube analysis. I would appreciate your suggestions on this.

Thanks


Solution

  • These two things are complementary. I wouldn't stop either in favor of the other.