DryRun Security
DryRun SecurityReviews from AWS customer
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
17 reviews
from
External reviews are not included in the AWS star rating for the product.
Automated Repo Scans That Save Time and Boost Security
What do you like best about the product?
Having automated scans directly in our repos saves so much time and helps make us secure.
What do you dislike about the product?
Personally I have not run into any issues on DRS that I do not like!
What problems is the product solving and how is that benefiting you?
It is helping us solve issues in our org with any issues inside of our code and helping us grabbing all of the issues during the PR. It is super easy to implement in the org making it a no brainer to use.
AppSec signal, not noise: DryRun catches the ‘Greeks in the horse’ PRs before they ship
What do you like best about the product?
DryRun Security gives me high-signal visibility into the changes that actually matter. The out-of-the-box analyzers help me quickly spot unexpected or risky behavior in pull requests without having to manually comb through everything. It’s become a practical way to scale AppSec review when PR volume is high—especially for catching edge cases that could create real operational or compliance impact.
I also appreciate how quickly the team is iterating: they’re regularly adding meaningful functionality, improving false-positive handling, and behaving like thought leaders in the AppSec space rather than “just another scanner.” Their continued momentum toward/through GRC certifications is a strong indicator they’re building for serious organizations, not hobby deployments.
Getting it installed was SO simple. We didn't need to tweak much, but once we started it got even better!
If the citizens of Troy had used DryRun Security, the Greeks never would have made it in.
I also appreciate how quickly the team is iterating: they’re regularly adding meaningful functionality, improving false-positive handling, and behaving like thought leaders in the AppSec space rather than “just another scanner.” Their continued momentum toward/through GRC certifications is a strong indicator they’re building for serious organizations, not hobby deployments.
Getting it installed was SO simple. We didn't need to tweak much, but once we started it got even better!
If the citizens of Troy had used DryRun Security, the Greeks never would have made it in.
What do you dislike about the product?
I don’t have many dislikes. If I had to pick one, it would be that I’d love to see even more investment in the developer experience and day-to-day workflow fit—making it a tool developers want to use, not one that security has to continually champion. It’s already valuable, but increasing developer pull (UX, messaging in PRs, “why it matters” context, smoother adoption) would make it even stickier.
What problems is the product solving and how is that benefiting you?
DryRun Security is solving the “too many PRs, not enough attention” problem—helping us detect the small number of changes that are genuinely risky, unusual, or non-compliant without forcing security or operations to read everything line-by-line. That directly reduces review fatigue and time-to-decision while increasing confidence that we aren’t missing the one PR that could cause a serious incident.
In our environment, it helps surface issues that could impact compliance and reliability—like changes that might enable non-compliant domain behavior or destabilize critical infrastructure dependencies (e.g., DNS-related risks). The practical benefit is fewer blind spots, faster reviews, and a stronger security posture without requiring a larger AppSec team.
In our environment, it helps surface issues that could impact compliance and reliability—like changes that might enable non-compliant domain behavior or destabilize critical infrastructure dependencies (e.g., DNS-related risks). The practical benefit is fewer blind spots, faster reviews, and a stronger security posture without requiring a larger AppSec team.
Deep Scan Delivers Insightful, Low-Noise Findings for Massive Legacy Codebases
What do you like best about the product?
The new Deep Scan feature, which performs a comprehensive review of our application, was incredibly helpful for identifying issues in a legacy application with millions of lines of code. Over the 20+ years of this application's lifespan, we've had several audits and 3rd-party reviews. DryRun's AI had a better grasp of the code's business intent and overall structure than most previous auditors. I expected a firehose of findings, most of which would be false positives or non-issues. However, the report listed 20 or so items to check, only one of which was a complete false positive. We're still tuning the engine for our uses, but the PR reviews have been helpful and insightful.
What do you dislike about the product?
Their UI can be a bit sluggish, especially when there are many linked GitLab repositories. It's pretty clear they've been spending most of their time on the scanning engines, and the UI was a lower priority. However, that seems to be clearing up, as the UI has improved. Ideally, you shouldn't need to use it much once it's up and running; you can just let it work directly with your repo.
What problems is the product solving and how is that benefiting you?
Most static scanners are so full of false positives that they're almost worthless when working with legacy codebases. The rise of AI-driven attacks is chilling, and it's reassuring to have something in place on our side that has been delivering measurable results.
Streamlined Security with Seamless Workflow Integration
What do you like best about the product?
I use DryRun Security to look at my code for security vulnerabilities. It helps me deliver secure code to production, and I love its ease of use as it already plugs into the workflow I am used to. It's fast and lets me keep on working without having to compile my code and wait hours for a scan to finish. DryRun looks at my changes in the PR and determines if we are introducing risks to our application. The initial setup was really easy.
What do you dislike about the product?
There isn't anything to dislike
What problems is the product solving and how is that benefiting you?
I use DryRun Security to identify code vulnerabilities and deliver secure code to production. It's easy to use, integrates well with my workflow, and saves time by analyzing changes in pull requests without lengthy code compilation.
Efficient Code Review with Quick Feature Adaptations
What do you like best about the product?
I use DryRun Security to identify issues for security review or improvement as our engineering team commits a lot of code. It helps me be aware of risky changes to the codebase and assists with code security reviews. My favorite thing about DryRun is that it allows me to focus on other tasks rather than reviewing code changes and PRs all the time. I appreciate that their team is fairly quick to make feature request changes and listens to customer feedback. The initial setup was very easy and smooth, and there's really nothing like it at the moment — it's great.
What do you dislike about the product?
I do somewhat wish there were more customization options for tuning the analyzers, but that seems to be in the works.
What problems is the product solving and how is that benefiting you?
I use DryRun Security to identify risky changes and aid in code security reviews, allowing me to focus on other tasks rather than constantly reviewing code changes.
Effortless SAST with Contextual Insights
What do you like best about the product?
I like DryRun Security for its ease of use, even when managing hundreds of repositories. I appreciate that security findings are surfaced directly to the engineer in the GitHub comment with valuable context. This context is crucial as it helps engineers understand the true root causes and risks, beyond just fixing another bug. Setting it up was as simple as installing a GitHub app.
What do you dislike about the product?
Everything thus far has been working as expected. In terms of improvement, support monolithic repos would be the most helpful thing, but I know that feature is coming soon.
What problems is the product solving and how is that benefiting you?
I use DryRun Security to cover multiple programming languages, ensuring compliance and secure code development. It surfaces security findings directly in GitHub comments, providing essential context, which helps us address vulnerabilities effectively.
Seamless Pipeline Integration with Near Real-Time Vulnerability Feedback
What do you like best about the product?
DryRun Security easily integrates into our existing build pipeline so that scans happen automatically and our developers get near real-time feedback on vulnerabilities in their code.
What do you dislike about the product?
There is nothing that I really dislike about DryRun Security. Even in situations where I've found what I believed to be a bug in the product, they were very quick to investigate and come back to me with a solution.
What problems is the product solving and how is that benefiting you?
We are a small team and performing manual code reviews across all of our new and legacy code is challenging. DryRun acts like a Senior Security Engineer, reading our PRs, understanding the context, finding issues and coming up with a plan of action to address them.
showing 11 - 17