Black Duck Coverity Static Analysis Logo

Black Duck Coverity Static Analysis

by Black Duck Software, Inc.

SAST tool for finding code quality & security defects in large-scale software

Hybrid|SMB, Mid-Market, Enterprise
Visit website
Compare
Compare
0
MCPThe entire cybersecurity market, one prompt awayTry MCP Access

Black Duck Coverity Static Analysis Description

Black Duck Coverity Static Analysis is a static application security testing tool that scans source code to identify code quality and security defects. The tool performs analysis across files and libraries to detect complex issues in software applications. The product supports 22 programming languages including C, C++, C#, Java, JavaScript, Python, Go, PHP, Ruby, Kotlin, Swift, Dart, TypeScript, Fortran, Scala, Visual Basic, Salesforce Apex, NVIDIA CUDA, and others. It also provides support for over 200 frameworks and infrastructure-as-code platforms. Coverity includes built-in compliance reporting capabilities for multiple security and industry standards. These include MISRA, AUTOSAR, ISO 26262, PCI DSS, CERT C/C++/Java, DISA STIG, ISO/IEC TS 17961, OWASP Top 10, OWASP Mobile Top 10, and CWE Top 25. The tool provides reports that categorize issues by type and severity to assist with prioritization and remediation tracking. The static analysis engine is designed to analyze large-scale applications and provides coverage for Common Weakness Enumeration (CWE) categories. The tool aims to help development teams identify security vulnerabilities and code quality issues during the development process.

Black Duck Coverity Static Analysis FAQ

Common questions about Black Duck Coverity Static Analysis including features, pricing, alternatives, and user reviews.

Black Duck Coverity Static Analysis is SAST tool for finding code quality & security defects in large-scale software developed by Black Duck Software, Inc.. It is a Application Security solution designed to help security teams with DEVSECOPS, OWASP, Source Code Analysis.

Have more questions? Browse our categories or search for specific tools.

ALTERNATIVES

Snyk Code Logo

AI-powered SAST tool that finds and auto-fixes code vulnerabilities in real-time

0
SonarSource SonarQube Logo

Code quality and security platform with SAST, SCA, and AI-powered remediation

0
Offensive 360 Secure Code Analysis Logo

SAST tool that analyzes source code for vulnerabilities using virtual compilers

0
Semgrep Code Logo

SAST solution that scans 30+ languages to find and fix code vulnerabilities

0
DeepSource SAST Logo

SAST engine that scans code commits for security vulnerabilities

0

Stay Updated with Mandos Brief

Get strategic cybersecurity insights in your inbox