Blog

Security writing from Corgea

Engineering-focused posts on code security, remediation workflows, and product updates.

Showing 20 of 59 posts

Changelog - May 13, 2026

This week's Corgea changelog highlights Harness Code integration, sharper secret scanning, and stronger endpoint discovery in the scanning engine.

Corgea Security Team Corgea Security Team
May 13, 2026 • Product
ChangelogProduct

SonarQube vs Snyk: Full Comparison + Why Teams Are Choosing Corgea

Compare SonarQube and Snyk side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.

Corgea Security Team Corgea Security Team
May 9, 2026 • Comparison
SonarQubeSnykCorgea

Snyk vs Checkmarx: Full Comparison + Why Teams Are Choosing Corgea

Compare Snyk and Checkmarx side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.

Corgea Security Team Corgea Security Team
May 5, 2026 • Comparison
SnykCheckmarxCorgea

SonarQube vs Checkmarx: Full Comparison + Why Teams Are Choosing Corgea

Compare SonarQube and Checkmarx side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.

Corgea Security Team Corgea Security Team
May 5, 2026 • Comparison
SonarQubeCheckmarxCorgea

SonarQube vs Veracode: Full Comparison + Why Teams Are Choosing Corgea

Compare SonarQube and Veracode side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.

Corgea Security Team Corgea Security Team
May 5, 2026 • Comparison
SonarQubeVeracodeCorgea

Mythos: Given Enough Inference, All Bugs Are Shallow

Anthropic's Mythos showed that given enough inference, all bugs are shallow. But who pays for the inference? We benchmarked Claude Opus 4.6 against Corgea v1 and v2 to show why purpose-built scanner architecture beats raw model capability on precision, recall, cost, and speed.

Ahmad Ahmad
Apr 14, 2026 • Product

Snyk vs Semgrep: Full Comparison + Why Teams Are Choosing Corgea

Compare Snyk and Semgrep side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.

Corgea Security Team Corgea Security Team
Apr 11, 2026 • Comparison
SnykSemgrepCorgea

Corgea Reporting: Security and Developer Insights in One View

Track code, dependency, code quality, IaC, scan activity, aging, and developer insights in one place. Filter reporting by project, tags, and time to see trends clearly.

Corgea Security Team Corgea Security Team
Mar 6, 2026 • Product

New Integration: Bitbucket

Connect Corgea to Bitbucket in a day with an API-native integration—no CI/CD setup. Scan repos, get PR feedback, use Corgea Agent in Bitbucket, and open fix pull requests automa...

Corgea Security Team Corgea Security Team
Feb 26, 2026 • Product

New in Corgea: Container Scanning + IaC Scanning

Scan container images for known CVEs and catch IaC misconfigurations before deploy. Corgea adds container/image scanning and Infrastructure as Code scanning for AppSec and devel...

Corgea Security Team Corgea Security Team
Feb 25, 2026 • Product

New Feature: Corgea Agent

Corgea Agent brings security into pull requests so developers can triage findings without leaving their workflow. Security teams get auditable feedback history and insights in t...

Corgea Security Team Corgea Security Team
Feb 24, 2026 • Product

New Product: Code Quality

Code Quality in Corgea finds high-confidence code quality issues using multi-file context and CWE-based categorization, with optional automated fixes. Try it now or book a demo.

Corgea Security Team Corgea Security Team
Feb 23, 2026 • Product

AI Application Security: How AI Is Transforming AppSec in 2026

Codebases are growing faster than security headcount, scanner output is a firehose of noise, and developers treat security findings like spam. AI application security is the fir...

Corgea Security Team Corgea Security Team
Feb 17, 2026 • Product

Best Java Static Code Analyzer: Top Tools Ranked

Best Java static analyzer tools ranked for security and CI/CD, comparison table, pitfalls, configs, and a worked example.

Corgea Security Team Corgea Security Team
Feb 4, 2026 • Product

Here's what happening the last 72-hours: 700+ Packages Compromised from Shai-Hulud 2.0 Worm (November 25, 2025)

Critical npm worm compromises 700+ packages including Zapier, PostHog, and Postman. 25,000+ GitHub repos infected, exposing 775+ tokens. Immediate mitigation steps inside.

Corgea Security Team Corgea Security Team
Nov 25, 2025 • Product

Sha1-Hulud: The Second Wave of npm Supply-Chain Attacks

Researchers uncovered a fast-moving npm supply-chain worm named Shai-Hulud. The malware injected malicious JavaScript (bundle.js) into popular packages.

Corgea Security Team Corgea Security Team
Nov 24, 2025 • Product

Introducing Smarter Auto-Fixing for SAST Findings

Corgea’s improved auto-fixing now delivers self-healing fixes, stronger quality checks, and 8% higher accuracy. Supports HTML, JSP, and integrates with Checkmarx, Fortify, Semgr...

Corgea Security Team Corgea Security Team
Oct 23, 2025 • Product

Introducing Extended APIs: Enhanced Security Management for Developers

Discover Corgea's new Extended APIs for scans, issues, blocking rules, and scan operations. Automate security workflows, integrate with CI/CD pipelines, and build custom securit...

Corgea Security Team Corgea Security Team
Oct 22, 2025 • Product

Introducing Corgea Dependency Scanning

Stay ahead of open-source risks with Corgea’s new Dependency Scanning. Automatically detect vulnerabilities, enforce licenses, and apply grouped fix versions across multiple eco...

Corgea Security Team Corgea Security Team
Oct 21, 2025 • Product

Announcing Reachability Analysis: Endpoint-Aware SAST in Corgea

Corgea’s new Reachability Analysis connects SAST findings to real web endpoints, showing which vulnerabilities are actually reachable from your API surface. Automatically maps e...

Corgea Security Team Corgea Security Team
Oct 20, 2025 • Product