Try our new research platform with insights from 80,000+ expert users

Coverity vs Snyk comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Customer Service

Sentiment score
7.0
Coverity's customer service is generally responsive and professional, but some users encounter communication delays and inconsistent expertise.
No sentiment score available
 

Room For Improvement

Sentiment score
3.7
Coverity users seek improved UI, better IDE integrations, reduced false positives, expanded language support, and enhanced reporting features.
No sentiment score available
The Coverity license fee is very high, making it tricky for individual developers.
 

Scalability Issues

Sentiment score
7.1
Coverity is praised for scalability, although some face cost issues; it efficiently serves both small and large organizations.
No sentiment score available
 

Setup Cost

Sentiment score
3.0
Coverity's pricing is perceived as expensive and complex, despite providing multi-language access without code limitations.
No sentiment score available
Coverity is considered expensive compared to other tools like SonarQube, which is much cheaper.
 

Stability Issues

Sentiment score
8.5
Coverity is praised for its stability and reliability, with users rating its performance highly and noting minimal configurations needed.
No sentiment score available
 

Valuable Features

Sentiment score
8.2
Coverity enhances code quality with low false positives, security analysis, customizable options, and seamless integration into development workflows.
No sentiment score available
The most valuable feature of Coverity is its interprocedural analysis.
 

Categories and Ranking

Coverity
Average Rating
7.8
Reviews Sentiment
6.5
Number of Reviews
41
Ranking in other categories
Static Application Security Testing (SAST) (4th)
Snyk
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
43
Ranking in other categories
Application Security Tools (4th), Container Security (7th), Software Composition Analysis (SCA) (3rd), Software Development Analytics (2nd), DevSecOps (1st)
 

Mindshare comparison

Coverity and Snyk aren’t in the same category and serve different purposes. Coverity is designed for Static Application Security Testing (SAST) and holds a mindshare of 8.4%, up 7.2% compared to last year.
Snyk, on the other hand, focuses on Application Security Tools, holds 7.6% mindshare, down 8.5% since last year.
Static Application Security Testing (SAST)
Application Security Tools
 

Featured Reviews

Md. Shahriar Hussain - PeerSpot reviewer
Offers impressive reporting features with user-friendliness and high scalability
The solution can be easily setup but requires heavy integration due to the multiple types of port and programming languages involved. Comparing the resource requirements of the solution I would say it can be installed effortlessly. I would rate the initial setup an eight out of ten. A professional needs some pre-acquired knowledge to manage Coverity's deployment process, but the local solution partners provide support well enough for trouble-free deployment. The overall deployment process of Coverity took around two and a half hours in our organization. The deployment duration depends upon the operating system and resources including high-end RAM and CPU processors.
Jayashree Acharyya - PeerSpot reviewer
Used for image scanning and identifying vulnerabilities, but its integration with other services could be improved
The solution has improved or streamlined our process a lot for securing container images. We wanted to make sure we are deploying the secure Docker images. Snyk allowed us to check whether it is following our standard of docker images or not. We use Azure DevOps as our platform, and Snyk's integration with Azure DevOps was okay. However, Snyk's integration with JFrog Artifactory didn't go well. We use JFrog Artifactory to store the artifacts we download. We wanted to integrate Snyk with JFrog Artifactory to scan the binary artifacts we downloaded, but that broke our JFrog Artifactory for some reason. Instead of using it there, we are calling it directly from the pipeline. Snyk's automation features significantly reduced remediation times a couple of times. Sometimes, our developers scan the code from the environment and find some Java vulnerabilities. We fixed those vulnerabilities in the lower environment itself. The solution does not require any maintenance. The accuracy of Snyk's vulnerability detection is pretty good compared to other tools. I rate the solution's vulnerability detection feature an eight out of ten. I would recommend Snyk to other users because it is easy to implement and integrate with Azure DevOps and GitHub. Overall, I rate the solution a seven out of ten.
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
816,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
32%
Computer Software Company
15%
Financial Services Firm
8%
Government
4%
Financial Services Firm
15%
Computer Software Company
15%
Manufacturing Company
9%
Insurance Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What do you like most about Coverity?
The solution has improved our code quality and security very well.
How does Snyk compare with SonarQube?
Snyk does a great job identifying and reducing vulnerabilities. This solution is fully automated and monitors 24/7 to find any issues reported on the internet. It will store dependencies that you a...
What do you like most about Snyk?
The most effective feature in securing project dependencies stems from its ability to highlight security vulnerabilities.
What needs improvement with Snyk?
I'm not responsible for the tool. As far as I know, there are no major concerns or features that we lack. We had some issues integrating into our pipeline, however, they were resolved.
 

Comparisons

 

Also Known As

Synopsys Static Analysis
No data available
 

Learn More

 

Overview

 

Sample Customers

SAP, Mega International, Thales Alenia Space
StartApp, Segment, Skyscanner, DigitalOcean, Comic Relief
Find out what your peers are saying about Coverity vs. Snyk and other solutions. Updated: September 2022.
816,406 professionals have used our research since 2012.