Try our new research platform with insights from 80,000+ expert users
Archana Verma - PeerSpot reviewer
Security Analyst at Dover Corporation
Real User
Provides software security and helps find potential security bugs or defects
Pros and Cons
  • "Provides software security, and helps to find potential security bugs or defects."
  • "The product lacks sufficient customization options."

What is our primary use case?

We use this tool for call scans in order to improve call quality. We implement testing and this tool cleans up our potential feedback. We are a semiconductor company and provide software solutions to our clients. I'm a senior manager. 

How has it helped my organization?

Coverity has improved our functionality and efficiency.

What is most valuable?

This product provides software security, and helps to find potential security bugs or defects with its checker feature. The solution also enables us to implement secure coding. 

What needs improvement?

We've found that there is a quite high false positive rate. It's a problem because we end up wasting time on something that's not an issue. The tracker reports too many issues that are not relevant. I'd like to see some kind of customization mechanism in the future. 

Buyer's Guide
Coverity
December 2024
Learn what your peers think about Coverity. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.

For how long have I used the solution?

We've been using this solution for over 10 years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable, we have several thousand users. 

How are customer service and support?

The technical support is reasonable. 

How would you rate customer service and support?

Neutral

What other advice do I have?

I rate this solution eight out of 10. 

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Automation Practice Leader at a financial services firm with 10,001+ employees
Real User
Improves security by detecting vulnerabilities in code, but it needs integration with popular development environments
Pros and Cons
  • "Coverity is quite stable and we haven’t had any issues or any downtime."
  • "I would like to see integration with popular IDEs, such as Eclipse."

What is our primary use case?

I am the administrator and I use this solution to do the calibrating and security scanning of the code in my bank. We are trying to find any vulnerabilities in our code and we are integrating the process with our DevOps.

What is most valuable?

The most valuable feature is the ability to find vulnerabilities in our code.

What needs improvement?

I would like to see integration with popular IDEs, such as Eclipse. If Coverity were available as a plugin then developers could use it to find security issues while they are coding because right now, as we are using Coverity, it is a reactive way of finding vulnerabilities. We need to find these kinds of problems during the coding phase, rather than waiting for the code to be analyzed after it is written.

For how long have I used the solution?

I have been working with Coverity for about eight months.

What do I think about the stability of the solution?

Coverity is quite stable and we haven’t had any issues or any downtime.

What do I think about the scalability of the solution?

We did not have to scale drastically on any of our applications, so it would be difficult for me to judge how scalable it is. Because of the price, we only purchased 20 licenses. We do plan on scaling the number of users and increasing our usage.

How are customer service and technical support?

The technical support is quite responsive and most of the time, we received a response really quickly. We have not had any timeline-related issues with them.

Which solution did I use previously and why did I switch?

We did not use another solution before Coverty, although in my previous company, I used Veracode.

We also use SonarQube for code analysis.

Compared to SonarQube, Coverity finds more vulnerabilities. SonarQube is stronger on core quality, such as duplicate lines of code, but the security issues are found by Coverity.

SonarQube is available as a plugin for development environments such as Eclipse, which allows us to find vulnerabilities proactively.

SonarQube was easier to deploy and I did not require assistance from the vendor for installation or configuration.

How was the initial setup?

We found that during installation and configuration, it takes pipelines for continuous integration and continuous deployment. It was a bit challenging because the necessary base integration was not easy to configure.

It took us slightly over a week to deploy, whereas, with SonarQube, we were able to complete it in less than a day. It was due to complexities in Coverity that it took us more than a week. The complexities were related to missing API features and hooks.

What about the implementation team?

I had assistance from the vendor, Synopsys, during the deployment.

What's my experience with pricing, setup cost, and licensing?

Coverity is quite expensive. Generally, for security scanning products, the pricing is very expensive. Some solutions have pricing that is based on the number of millions of lines of code, but Coverity is priced based on the number of users.

I believe that pricing based on the number of lines of codes is cheaper than billing on a per-user basis. If we have 400 or 500 developers and each needs a license then it will be cheaper to have a solution where the cost depends on the size of the code.

What other advice do I have?

We also purchased Black Duck Binary Analysis and the Black Duck Hub from Synopsys.

My advice for anybody who is implementing this solution is to try to best capture security issues while the code is being written, rather than waiting until it is compiling. It’s easier and much more cost-effective to find vulnerabilities at the earlier, code-writing stage.

The other thing to keep in mind is that you should not rely on one approach to code security. You need to make sure that binary security is also in place, which is not done using Coverity. Any company that wants to secure its environment will need multiple levels of security scanning, and only one of these is handled by Coverity. The second one, binary scanning, can be done by using Black Duck or Veracode. This continues onto other security concerns, such as network scanning.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Coverity
December 2024
Learn what your peers think about Coverity. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
reviewer1610562 - PeerSpot reviewer
Director at a healthcare company with 10,001+ employees
Real User
Top 5
Useful in areas like code quality and secure code analysis but needs to offer easy integration capabilities
Pros and Cons
  • "The tool as it is can be used for code quality improvement."
  • "I had tried integrating the tool with Azure DevOps, but the report I got stated that my team faced many challenges."

What is our primary use case?

I use my company's solution for code quality and secure code analysis.

What is most valuable?

The tool as it is can be used for code quality improvement. Whatever rules are in the tool are useful.

What needs improvement?

I don't use it directly on a day-to-day basis.

I expect the product to offer ease of integration with the built pipelines. I had tried integrating the tool with Azure DevOps, but the report I got stated that my team faced many challenges. I do not know the exact details.

For how long have I used the solution?

I have been using Coverity for a few years.

Which solution did I use previously and why did I switch?

I use Coverity simultaneously with Fortify but for different purposes.

What's my experience with pricing, setup cost, and licensing?

I don't deal with the pricing.

What other advice do I have?

I am satisfied with the product.

The tool is used for specific use cases like embedded systems.

I would not recommend the tool for web application technologies, Java, or cloud-native technologies since the tool is meant for embedded codes.

I rate the tool a six out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
App Security at FineLabs
Real User
Top 20
Helps to check source code against quality gates before deployment
Pros and Cons
  • "What I find most effective about Coverity is its low rate of false positives. I've seen other platforms with many false positives, but with Coverity, most vulnerabilities it identifies are genuine. This allows me to focus on real issues."
  • "The solution needs to improve its false positives."

What is our primary use case?

We've integrated Coverity into our CI/CD pipeline to check our source code against quality gates before deployment. It alerts us to issues so we can halt the pipeline, fix critical problems, and then run it again.

What is most valuable?

What I find most effective about Coverity is its low rate of false positives. I've seen other platforms with many false positives, but with Coverity, most vulnerabilities it identifies are genuine. This allows me to focus on real issues.

As for code remediation, although I can fix issues myself as a security engineer, the tool provides helpful remediation guidance for each vulnerability. It lists how to fix each issue, which I find useful. The solution has increased our development speed.  

What needs improvement?

The solution needs to improve its false positives. 

For how long have I used the solution?

I have been using the product for one and a half years. 

What do I think about the scalability of the solution?

I rate the tool's scalability a nine out of ten. We have 20-25 users who use it daily. 

How was the initial setup?

I rate the solution's deployment ease a nine out of ten, and it can be completed in a few minutes. 

What's my experience with pricing, setup cost, and licensing?

The solution's pricing is comparable to other products. 

What other advice do I have?

I rate the overall solution a nine out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Real User
Top 20
Performs static application security testing on various code bases, including Java, PHP, and HTML
Pros and Cons
  • "The product has been beneficial in logging functionality, allowing me to categorize vulnerabilities based on severity. This aids in providing updated reports on subsequent scans."
  • "The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming."
  • "The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming."

What is our primary use case?

My primary use case is performing static application security testing on various code bases, including Java, PHP, and HTML. I use it to create review reports of assets and categorize the issues based on severity.

What is most valuable?

The product has been beneficial in logging functionality, allowing me to categorize vulnerabilities based on severity. This aids in providing updated reports on subsequent scans.

What needs improvement?

The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming.

For how long have I used the solution?

I have been using Coverity for about two to three months, between June 2023 and August 2023.

What do I think about the stability of the solution?

There were occasional issues with lag during the initial setup and scans, especially in a cloud environment.

How are customer service and support?

Due to the subscription-based model, I had to contact customer service, mainly to add new users. Response times varied, sometimes taking more than a week.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I had experience with SonarQube as an alternative. Coverity excelled in code scanning because it did not require installation prerequisites. Its reports are also clear and informational. It provides us with a better idea of troubleshooting vulnerabilities.

How was the initial setup?

The initial setup was elaborate and somewhat complicated. The information from the Synopsys website was more than enough. First-time users will struggle with many tools, packages, and libraries. Deployment took 30 minutes to complete. Two to three resources were involved in the process.

What about the implementation team?

An integrator helped with the tool's deployment. 

What other advice do I have?

I rate the solution a nine out of ten. 

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Yantao Zhao - PeerSpot reviewer
Software Integration Engineer at Thales
Real User
Top 5
Powerful capabilities, reliable, and good support
Pros and Cons
  • "The most valuable feature of Coverity is the wrapper. We use the wrapper to build the C++ component, then we use the other code analysis to analyze the code to the build object, and then send back the result to the SonarQube server. Additionally, it is a powerful capabilities solution."
  • "Coverity could improve the ease of use. Sometimes things become difficult and you need to follow the guides from the website but the guides could be better."

What is our primary use case?

We use Coverity because we have a SonarQube server and we have a lot of software components that use different languages, such as Java, C, C++, and above. For C and C++ components we use Coverity.

What is most valuable?

The most valuable feature of Coverity is the wrapper. We use the wrapper to build the C++ component, then we use the other code analysis to analyze the code to the build object, and then send back the result to the SonarQube server. Additionally, it is a powerful capabilities solution.

What needs improvement?

Coverity could improve the ease of use. Sometimes things become difficult and you need to follow the guides from the website but the guides could be better.

For how long have I used the solution?

I have been using Coverity for approximately four years.

What do I think about the stability of the solution?

Coverity is stable.

What do I think about the scalability of the solution?

The scalability of Coverity is good. We have more than around 15 software components and other components involved.

We have 20 developers that are using the solution in my organization.

How are customer service and support?

We had support from Coverity for the first six months of usage but later we did not.

I rate the support from Coverity a four out of five.

Which solution did I use previously and why did I switch?

We have used other solutions, such as SonarQube.

How was the initial setup?

In the beginning, it takes two weeks to learn how to set up Coverity, but later the maintenance work is very easy. The beginning involves soft code, that we need to set up before using SonarQube, we have created SonarQube property itself for every component and inside we need to copy different options for Coverity. We had global Coverity roles or vendors we had to allow it to work with global rules and according to the component itself and the setup. The full implementation process can take approximately one month to complete.

What about the implementation team?

We have two teams to set up the server and install Coverity. I set up the project in Coverity and the different roles in the soft code. The developers use Coverity in their daily work.

What other advice do I have?

My advice to other is the first few steps of using Coverity takes time. It's better to have an experienced user to support it. For new users, it will be hard for them to set it up. If they can get someone to support it directly at the beginning it would be better because for me it's very hard at the beginning for a few weeks.

And on a scale from one to 10, how would you rate Coverity?

I rate Coverity an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Sr. Manager/Sr. Architect at Cognizant
Real User
It has the lowest false positives with customizable triage options
Pros and Cons
  • "It has the lowest false positives."
  • "Reporting engine needs to be more robust."

What is our primary use case?

We did a comprehensive evaluation on a number of critical parameters in the environment that we are in. Other popular tools that we evaluated failed to meet our expectations.

How has it helped my organization?

  • Ease of development teams to adopt.
  • Faster scanning
  • Lowest false positives
  • No unnecessary bloating of a huge defect list.

These have helped us to focus on the things which need attention.

What is most valuable?

  • Lowest false positive rate
  • Faster scanning time
  • Inline context-sensitive help and other supportive artifacts which help developers.
  • Customizable triage options
  • Integrations with CI/CD tools, etc.

What needs improvement?

  • Reporting engine needs to be more robust.
  • Custom reporting is a must have.
  • Perhaps, the availability of connectors to popular open source BI tools, such as BIRT, JasperReports, or Pentaho may add value.

For how long have I used the solution?

Less than one year.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Roshan Fanse - PeerSpot reviewer
Lead Database security at a consultancy with 201-500 employees
Real User
Top 10
A comprehensive solution for SaaS support providing detailed report and security advisor

What is our primary use case?

We use the solution for SaaS support.

What is most valuable?

The most valuable feature is the security advisor. It also provides a very detailed report.

What needs improvement?

Triage history has many bugs and needs to be improved. There could be a subsection. The solution could provide a graphical representation like other tools.

We have OS 2021, which is not the latest one. It should be updated regularly.


For how long have I used the solution?

I have been using Coverity for almost a year.

What do I think about the stability of the solution?

The product is stable.

I rate the solution’s stability a nine out of ten.

What do I think about the scalability of the solution?

Our organization has 20-30 users using this solution.

I rate the solution’s scalability an eight out of ten.



How are customer service and support?

Technical support has expert hours and is available anytime. Also, we don't need to raise a ticket now because we have direct support from Coverity.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We are exploring Black Duck, which has more precise things. Coverity has a clear view. The report is very much clear rather than confusing like other tools. It also has a PDF option, and it gives precise information.

How was the initial setup?

The initial setup is simple.

What's my experience with pricing, setup cost, and licensing?

The solution has higher pricing. The price should be based on the user count. Suppose there is a ten-user license per pack. However, this could be adjusted to five users if needed.



What other advice do I have?

Overall, I rate the solution an eight out of ten.



Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2024
Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros sharing their opinions.