I have integrated SonarQube and Checkmarx SAST and SCA into the Azure DevOps build pipeline. I am able to see both the SonarQube and Checkmarx reports without any issues.
I have the following questions. Could someone please clarify:
- What is the difference between SonarQube and Checkmarx CxSAST?
- What is the common thing between these two?
- In which situations are SonarQube and Checkmarx preferred?