Code scanning you can trust

Built for developers and backed by security teams, Coverity® Static Analysis provides unparalleled code scanning to help you deliver high-quality software that meets security, functional safety, and industry standards.

Uncover complex defects

Find and fix code quality and security issues across files and libraries.

Ensure compliance

Track and prioritize issues by security, functional safety, and industry standards.

Scan with confidence

Analyze large-scale applications with high accuracy.

Compliance simplified, intelligence empowered

Built-in reports identify issue types and severity level across standards to improve remediation efforts. This compliance intelligence is embedded in ContextAI™, enriching the security intelligence behind our AppSec solutions.

 

Improve code quality and security

Coverity provides in-depth support for 22 programming languages, more than 200 frameworks, and many popular infrastructure-as-code platforms. Learn about CWE coverage.

c-c---logo
c-plus-logo
salesforce-logo
scala-logo
Fortran
Java-Logo
PHP-Logo
Python-Logo

Build high-quality software, faster

The Code Sight™ IDE Plug-in helps developers find and fix code quality defects, security vulnerabilities, and hardcoded secrets as they code with real-time results, issue summaries, and code fixes for faster remediation.

Automate within developer workflows

Integrate your existing tools

IDE, SCM, and CI integrations help you find and fix defects within dev workflows.

Automate code scanning

Trigger scans on code commits and pull requests to uncover issues early.

Scale static analysis scanning

Expand to cover your full portfolio of applications and the teams that support them.
“Using Coverity has helped enhance our mandate to ensure code quality and security as well as to enforce coding standards”
Nicolas Leclercq
Product Security Officer for Software Engineering, Thales Alenia Space

Trusted analysis for complex software

Discover how Coverity customers reduce risk, ensure application resiliency, and rapidly deliver new functionality to market.

Black Duck Coverity® is an enterprise-grade static analysis solution that finds and fixes security vulnerabilities and code quality defects before your software ships. Built for developers and backed by security teams, Coverity scans source code without executing it — analyzing entire codebases across files and libraries to uncover complex defects that span multiple components.

Coverity builds an in-depth structural model of each application, combining insights into dependencies, compilers, and language semantics to achieve a depth of analysis that competitors cannot approach. It supports 22 programming languages, more than 250 frameworks, and a wide range of infrastructure-as-code platforms — with particular strength in C and C++ analysis for safety-critical and embedded software development. Black Duck has been recognized as a Gartner Magic Quadrant Leader for Application Security Testing for eight consecutive years, and is a leader in Gartner’s inaugural Magic Quadrant for Software Supply Chain Security.