At Sonar, they have been continuously improving their SAST capabilities by leveraging benchmarks to track progress. They initially stated a detection rate of 80% and a false-positive rate of no more than 20%, but later provided more detailed information for specific cases like the OWASP Benchmark project, where their True-Positive Rate was at 85%. The company's focus has always been on delivering value to developers through their products, rather than solely focusing on benchmark scores. Recently, they received feedback from prospects indicating that not all companies have the resources or time to thoroughly assess SAST solutions, leading them to provide a list of top 3 SAST benchmarks by language, along with the issues expected to be detected in each project (known as Ground Truth), and their own results for these benchmarks.