DryRun Security Reviews (20)

Reviews

DryRun Security Reviews (20)

4.9
20 reviews

What do users say?

Generated using AI from real user reviews
Users consistently praise the product for its ease of use and automated scans, which streamline security processes and integrate seamlessly into existing workflows. The ability to receive actionable feedback directly in pull requests enhances developer efficiency and helps maintain secure code practices. A common limitation noted is the sluggish UI, particularly when managing multiple repositories.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Josh S.
JS
Josh S.
CEO / CISO
Small-Business (50 or fewer emp.)
"Seamless Pipeline Integration with Near Real-Time Vulnerability Feedback"
5/5
What do you like best about DryRun Security?

DryRun Security easily integrates into our existing build pipeline so that scans happen automatically and our developers get near real-time feedback on vulnerabilities in their code. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

There is nothing that I really dislike about DryRun Security. Even in situations where I've found what I believed to be a bug in the product, they were very quick to investigate and come back to me with a solution. Review collected by and hosted on G2.com.

John P.
JP
John P.
SecOps Engineer
Small-Business (50 or fewer emp.)
"DryRun Supercharges AppSec with Context-Aware, Actionable PR Feedback"
4.5/5
What do you like best about DryRun Security?

DryRun has been a strong force multiplier for our AppSec process. It analyzes changes in context (not just pattern matching), flags issues early in pull requests, and delivers feedback in a way engineers can act on quickly. We’ve seen fewer false positives vs. legacy SAST approaches, which makes it easier to build trust with dev teams. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

Full-repo scanning is an area I’d like to see expanded. I know it’s already on the roadmap, and I’m looking forward to deeper whole-repository coverage in addition to PR/change-based analysis. Review collected by and hosted on G2.com.

Justin L.
JL
Justin L.
"Streamlined Security with Seamless Workflow Integration"
5/5
What do you like best about DryRun Security?

I use DryRun Security to look at my code for security vulnerabilities. It helps me deliver secure code to production, and I love its ease of use as it already plugs into the workflow I am used to. It's fast and lets me keep on working without having to compile my code and wait hours for a scan to finish. DryRun looks at my changes in the PR and determines if we are introducing risks to our application. The initial setup was really easy. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

There isn't anything to dislike Review collected by and hosted on G2.com.

John P.
JP
John P.
Director Of Engineering
Information Technology and Services
Small-Business (50 or fewer emp.)
"Fast, Context-Aware Security Feedback Right in GitHub Pull Requests"
5/5
What do you like best about DryRun Security?

DryRun Security runs and provides feedback where we do our work: GitHub. Feedback is provided quickly within the context of the Pull request. This helps our team mitigate vulnerabilities before they are deployed.Vulnerabilities are reported in a context-aware manner, which reduces the number of false positives. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

Pricing requires contacting the team, and I typically prefer transparent pricing models. With that being said, the team is incredibly helpful, and quick to turn around price quotes. Review collected by and hosted on G2.com.

Adam D.
AD
Adam D.
"Effortless SAST with Contextual Insights"
5/5
What do you like best about DryRun Security?

I like DryRun Security for its ease of use, even when managing hundreds of repositories. I appreciate that security findings are surfaced directly to the engineer in the GitHub comment with valuable context. This context is crucial as it helps engineers understand the true root causes and risks, beyond just fixing another bug. Setting it up was as simple as installing a GitHub app. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

Everything thus far has been working as expected. In terms of improvement, support monolithic repos would be the most helpful thing, but I know that feature is coming soon. Review collected by and hosted on G2.com.

Patrick M.
PM
Patrick M.
VP, Security
Mid-Market (51-1000 emp.)
"DryRun Security Delivers Rich Code Security Context and Intelligence"
5/5
What do you like best about DryRun Security?

DryRun security gives us a ton of context and intelligence around our code security that typical scanners don't give us. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

Nothing comes to mind. We use this for internal security and customer security facing reports. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Verified User in Computer Software
Mid-Market (51-1000 emp.)
"DryRun Keeps AI Code Fast and Secure with Pre-Merge Reviews"
5/5
What do you like best about DryRun Security?

DryRun helps us keep up with the pace of AI code generation while ensuring that any code our developers check in goes through a security review before it’s merged. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

To get the most out of this product, as with any product, you need to devote time to working with it. The out-of-the-box policies are solid, but with a bit more time we could write more natural-language code policies tailored to specific use cases. Review collected by and hosted on G2.com.

Verified User in Retail
UR
Verified User in Retail
Mid-Market (51-1000 emp.)
"Good Use Case for AI"
5/5
What do you like best about DryRun Security?

Since its agentic and doesn't depend on rules, theres good coverage across any language, framework, or tool out of the box. It's been particularly helpful providing feedback to engineers on changes to infra level concerns like terraform or helm. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

No major downsides, just needs some refinement as it grows. Slack alerts can be a bit noisy, for example. Thus far the team has sought feedback frequently and eventually comes up with solutions. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
AC
Verified User in Computer & Network Security
Small-Business (50 or fewer emp.)
"DryRun Surfaces Actionable Security Issues with Helpful PR Context"
5/5
What do you like best about DryRun Security?

DryRun is better than any static code analyzer we’ve used. It consistently surfaces real security concerns in PRs, provides helpful context, and makes the findings actionable. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

The scans can be a little slower compared to a static analyzer which is expected and acceptable. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
Small-Business (50 or fewer emp.)
"Automated Repo Scans That Save Time and Boost Security"
5/5
What do you like best about DryRun Security?

Having automated scans directly in our repos saves so much time and helps make us secure. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

Personally I have not run into any issues on DRS that I do not like! Review collected by and hosted on G2.com.