Try our new research platform with insights from 80,000+ expert users

Coverity vs Synopsys Software Risk Manager comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Coverity
Ranking in Static Application Security Testing (SAST)
4th
Average Rating
7.8
Number of Reviews
40
Ranking in other categories
No ranking in other categories
Synopsys Software Risk Manager
Ranking in Static Application Security Testing (SAST)
31st
Average Rating
0.0
Number of Reviews
1
Ranking in other categories
Software Composition Analysis (SCA) (19th), Application Security Posture Management (ASPM) (4th)
 

Featured Reviews

Archana Verma - PeerSpot reviewer
May 12, 2023
Provides software security and helps find potential security bugs or defects
We use this tool for call scans in order to improve call quality. We implement testing and this tool cleans up our potential feedback. We are a semiconductor company and provide software solutions to our clients. I'm a senior manager.  Coverity has improved our functionality and efficiency. This…
Saravanan_Radhakrishnan - PeerSpot reviewer
Sep 27, 2023
Facilitates continuous assessment of applications, covering both static and dynamic security aspects
The requirements are in such a place where the customers want to do a continuous assessment of their applications. The customers were looking for something around static security and dynamic security, and in all those areas, they were looking for an industry leader with a proven solution.  Synopsys…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It help us identify the latest security vulnerabilities."
"The solution has helped to increase staff productivity and improved our work significantly by approximately 20 percent."
"Coverity integrates with issue-tracking systems like Jira and provides email notifications, alerts, and other features."
"Coverity is easy to set up and has a less lengthy process to find vulnerabilities."
"It is a scalable solution."
"Considering the analysis part and the benchmarking process involving the product that my company carried out, the solution is good for finding bugs and violations"
"It's pretty stable. I rate the stability of Coverity nine out of ten."
"The most valuable feature is the integration with Jenkins."
"The customers were looking for something around static security and dynamic security, and in all those areas, they were looking for an industry leader with a proven solution. Synopsys is a Gartner leader, so I position this particular technology for the technical pre-sales part of it."
 

Cons

"When I put my code into Coverity for scanning, the code information of the product is in the system. The solution could be improved by providing a SBOM, a software bill of material."
"Coverity is not stable."
"We'd like it to be faster."
"The solution's user interface and quality gate could be improved."
"Some features are not performing well, like duplicate detection and switch case situations."
"I had tried integrating the tool with Azure DevOps, but the report I got stated that my team faced many challenges."
"SCM integration is very poor in Coverity."
"We're currently facing a primary challenge with automation using Coverity. Each developer has a license and can perform manual checks, and we also have a nightly build that analyzes the entire software. The main issue is that the tool can't look behind submodules in our code base, so it doesn't see changes stored there."
"The initial setup is a bit challenging because things are not easy. It needs a lot of technology adaptability plus the customer's environment-specific use cases."
 

Pricing and Cost Advice

"The price is competitive with other solutions."
"I would rate the pricing a six out of ten, where one is low, and ten is high price."
"I would rate the tool's pricing a one out of ten."
"Offers varying prices for different companies"
"This is a pretty expensive solution. The overall value of the solution could be improved if the price was reduced. Licensing is done on an annual basis."
"I would rate Coverity's pricing as a nine out of ten. It's already very expensive, and it's a problem for us to get more licenses due to the price. The pricing model has some good aspects - for example, a personal license gives access to all languages without code limitations, which is better than some competitors. However, it's still a lot of money for us to spend."
"The pricing is very reasonable compared to other platforms. It is based on a three year license."
"Coverity is very expensive."
"It is more of an enterprise solution for budget-conscious customers. So, it's moderately priced. It's not for everybody."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
801,394 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
31%
Computer Software Company
15%
Financial Services Firm
7%
Government
4%
Financial Services Firm
16%
Computer Software Company
14%
Manufacturing Company
13%
Insurance Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What do you like most about Coverity?
The solution has improved our code quality and security very well.
What is your experience regarding pricing and costs for Coverity?
The solution's pricing is comparable to other products.
What do you like most about Synopsys Code Dx?
The customers were looking for something around static security and dynamic security, and in all those areas, they were looking for an industry leader with a proven solution. Synopsys is a Gartne...
What is your experience regarding pricing and costs for Synopsys Code Dx?
I would rate the pricing model an eight out of ten, where one is low and ten is high. Because it is more of an enterprise solution for budget-conscious customers. So, it's moderately priced. It's n...
What needs improvement with Synopsys Code Dx?
Code Dx lacks one aspect, the dynamic security part, known as DAST. It's not an on-premise solution; it's in the cloud now. There are compliance standards and data standards where the customer migh...
 

Also Known As

Synopsys Static Analysis
Code Dx
 

Learn More

 

Overview

 

Sample Customers

SAP, Mega International, Thales Alenia Space
Discover why companies like: CGI said, "Synopsys and Software Risk Manager have provided the results we’re looking for".
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Static Application Security Testing (SAST). Updated: September 2024.
801,394 professionals have used our research since 2012.