If you're looking for a Corgea alternative, Snyk is a good option. Snyk is designed to fit into development tools and processes, offering continuous vulnerability scanning and remediation advice. It supports a variety of languages and tools, including Docker and Kubernetes, and offers detailed reporting and unlimited scanning with paid upgrades.
Another good option is Bearer, a Static Application Security Testing (SAST) tool that can be deeply embedded into CI/CD pipelines. It can identify and fix security vulnerabilities in code, with customizable rules and reports. Bearer supports seven programming languages and can integrate with tools like Jira and Slack, providing detailed reports and insights to help developers prioritize and fix security issues.
Checkmarx offers a suite of application security testing tools, including SAST, API Security and DAST. It's intended to be used to centralize and manage application security, so developers and security teams get a consistent experience. Checkmarx has a lot of features and a large user base, so it's good for a wide range of development needs.
If you want a tool that can provide security context as developers write code, check out DryRun Security. This AI-powered tool offers fast and accurate security code reviews through its Security Buddy, which evaluates pull requests with a sophisticated risk assessment model. It supports multiple languages and can be integrated with GitHub, helping developers stay productive and improving the development pipeline.