MITRE's rows here are Manual Static Analysis - Source Code and Automated Static Analysis - Source Code, on its SOAR scale. High is "a method that succeeds frequently and does not result in many false reports"; Moderate may miss coverage or give incorrect reports. Every rating "assumes the use of best-of-breed tools, analysts, and methods". On CWE-89, automated analysis can't reach 100% accuracy and coverage, and manual analysis "might not achieve desired code coverage within limited time constraints". Narrative rows, such as CWE-327's Automated Analysis (Moderate), aren't compared.
OWASP's Code Review Guide v2.0 (July 2017), section 5.2: "SAST tools are great for coverage and setting a minimum baseline", but tools "always need human verification". Table 5 credits scanners with less manual effort, every instance found, source-to-sink analysis and exact code snippets; if a manual review gives you less locational detail, challenge it.
CERT-In's Guidelines for Secure Application Design, Development, Implementation and Operations, section 5.1: source code reviews "encompass both manual and automated reviews." SSDF PW.8.1 asks whether to test executable code "to find vulnerabilities not identified by previous reviews, analysis, or testing".