SAST RESULTS REPORTS for Compliance

First of all, thanks for such a quick response.

The reason I’m asking it is because its mentioned in here from one of the SonarSourcer. Athough it does not say anything about sonarcloud. So does sonarcloud have different edition as well or do we get full scanning capabilities and just the reporting thing is different?

And yes we need the visual representation as well. But mainly we want to be sure that the SAST scan isn’t different than from sonarqube enterprise edition.

Am I right that Community Edition has a limited number of vulnerabilities?

We provide a lot of Security Vulnerability and Security Hotspot rules with SonarQube Community Edition (CE). With the Developer Edition and above, you also have access to the Taint Analysis/Injection rules on top of what is provided with CE.