Solution
Coverity
Static Application Security Testing Solution (SAST)
Coverity
Coverity is a comprehensive static application security testing (SAST) tool that supports a wide range of security analysis areas across 21 languages and 70+ frameworks, enabling developers to accurately find critical flaws and potential security vulnerabilities inherent in their code.
Key Features
-
Industry-leading static analysis capabilities
- Integrated analysis of code defects, coding rules, HIS Metrics, and vulnerabilities
- Identify and analyze all dependencies without building code
- Any issues can be fixed before the build-test phase
-
IDE Integration CodeSight Plugin
- Provides analysis while coding by providing IDE plugin CodeSight for Visual Studio, Eclipse, Intelli J, etc.
-
SDLC Integration
- Supports IDE, SCM, CI/CD, and ALM integration functions
- Supports Windows, Linux, Mac OS X, Solaris, AIX, etc.
- Support for other build automation solutions via Rest API
- Supports various compilers such as ARM C/C++, Clang, GNU GCC/G++, Intel C++, etc.
Special Features
-
Comprehensive security policy compliance management
- Comprehensive security vulnerability analysis support for all common security standards
- OWASPTop-10
- CWE/SANS Top-25
- PCI DSS
- OWASP Mobile Top-10
- iOS(Swift)
- Android(Java, Kotlin)
- MISRA
- AUTOSAR
- CERT C/C++
- ISO/IEC TS 17961
-
Support for multiple languages and frameworks
- Supports 21 languages including C/C++, C#, Java, JavaScript, Kotlin, Swift, Go, Python, Ruby, PHP, etc.
- Supports over 70 frameworks including Vue, Angular, React, Spring, Django, Ruby on Rails, ASP.NET, etc.
- Support for framework-specific checkers such as Android, Angular, MySQL, and React
-
Supports IDE, CI/CD, and issue tracker integration
- Integrated support for SCM such as SVN, CVS, and Git
- Supports IDE/CI integration such as Android Studio, Eclipse, IntelliJ IDEA, MS Visual Studio, Jenkins, etc.
- Support for issue trackers such as Jira, Bugzilla, etc. ALM support
-
Support for multiple platforms and compilers
- Supports Windows, Linux, Mac OS X, Solaris, AIX, etc.
- Supports various compilers such as ARM C/C++, Clang, GNU GCC/G++, Intel C++, etc.
-
Black Duck Linkage
- Producing the best inspection results by linking with Blackduck, the world's No. 1 open source inspection tool
-
Support for large-scale projects
- Support for over 10 million issues, thousands of developers and projects
-
On-Premise and Cloud Support
- Support for testing in On-Premise and Cloud environments