I use the solution for static analysis.
Angestellter at a computer software company with 11-50 employees
A scalable and easy-to-use solution that can be easily deployed
Pros and Cons
- "The product is easy to use."
- "Sometimes it's a bit hard to figure out how to use the product’s UI."
What is our primary use case?
What is most valuable?
The product has good API documentation. I’m quite happy with it. The product is easy to use.
What needs improvement?
Sometimes it's a bit hard to figure out how to use the product’s UI.
For how long have I used the solution?
I have been using the solution for some years.
Buyer's Guide
Coverity
December 2024
Learn what your peers think about Coverity. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
What do I think about the stability of the solution?
I have not faced any issues with the product’s stability.
What do I think about the scalability of the solution?
The solution is scalable. Four people in my organization use the solution.
How was the initial setup?
The initial setup is easy.
What other advice do I have?
I am using the latest version of the product. I have also used Clang Static Analyzer. People planning to use the solution should try the open-source version first to understand how it works. We must have the paid version of the product to get all the resources and documentation. Overall, I rate the product an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Vice President at a tech vendor with 1,001-5,000 employees
Static analysis solution that exposes existing and future vulnerabilities
Pros and Cons
- "The ability to scan code gives us details of existing and potential vulnerabilities. What really matters for us is to ensure that we are able to catch vulnerabilities ahead of time."
- "When I put my code into Coverity for scanning, the code information of the product is in the system. The solution could be improved by providing a SBOM, a software bill of material."
What is our primary use case?
We use this solution to scan our products. We've integrated with our build system and it automatically completes the scanning.
What is most valuable?
The ability to scan code gives us details of existing and potential vulnerabilities. What really matters for us is to ensure that we are able to catch vulnerabilities ahead of time.
What needs improvement?
When I put my code into Coverity for scanning, the code information of the product is in the system. The solution could be improved by providing a SBOM, a software bill of material. They could also integrate a software composition analysis scan. This would make my job a bit easier.
There is scope for Coverity to look beyond static analysis. Most of people that I have spoken to use Coverity from a pure static analysis perspective. However, we also need to be able to view dynamic pages and APIs using dynamic scanning and SES scans. Currently we would need to use another solution to be able to do this.
For how long have I used the solution?
I have been using this solution for 10 years.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
From a support perspective, they are pretty responsive. I would rate them a five out of five.
What was our ROI?
The the last ten years, our company has derived value from using this solution. We continuously evaluate our tech stack and if a better solution came along, we would consider it if it provided more value.
What's my experience with pricing, setup cost, and licensing?
This is a pretty expensive solution. The overall value of the solution could be improved if the price was reduced. Licensing is done on an annual basis.
There are other new tools like Veracode, Java Icon and Javascript which are better than Coverity when it comes to visualization. Their cost is significantly lower compared to Synopsys.
What other advice do I have?
Coverity is really good with CC+ and legacy technologies. However, there are other products that are probably as good or even better than Coverity when it comes to Java or cloud applications.
If someone were to ask me what tool I would recommend, my answer would depend on what technology they're using and what their use case is. My advice would be based on how they're going to use the product and what they're expecting from the tool.
I would rate this solution an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Coverity
December 2024
Learn what your peers think about Coverity. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
Stable solution with good technical support service
Pros and Cons
- "It is a scalable solution."
- "Sometimes, vulnerabilities remain unidentified even after setting up the rules."
What is our primary use case?
We use the solution to scan the static code and identify vulnerabilities. We can verify the rules and scripting during various applications' implementation processes.
What is most valuable?
The solution has a low false positive rate compared to other vendors. Also, it can scan complex codes. In addition, it has the best features for trial analysis, integration, and language support.
What needs improvement?
Sometimes, vulnerabilities are not identified even after setting up the automated scanning rules. They should include a feature combining automated scanning tools with manual code reviews for better output.
For how long have I used the solution?
I have been using the solution for five years.
What do I think about the stability of the solution?
I rate the solution's stability a nine out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. We can quickly scan around 100 DLS using it. I rate its scalability a nine.
How are customer service and support?
I interact with the solution's technical support team in terms of tuning the tool and improvements. They acknowledge the emails and respond to them quickly.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution integrates well with different tools. Thus, its setup process is relatively straightforward.
What's my experience with pricing, setup cost, and licensing?
The solution is affordable. I rate its pricing a six out of ten.
What other advice do I have?
I recommend the solution to others and rate it a ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Works
It gives advice and training on how to resolve the most common quality issues, but the REST implementation is sub-par
What is our primary use case?
- Raising the level of code quality, security, and robustness in the codebase
- Tracking and addressing code quality issues.
How has it helped my organization?
Coverity provides developers with a good, best practice, coding advice, and tracks risks of poor coding quality. Coverity reports have urged developers to improve the quality of their code.
What is most valuable?
- I like that it gives advice and training on how to resolve the most common quality issues.
- Links to more details on each issue and the background and risks.
What needs improvement?
- Ability to follow source file s-links into the target location for issuing assignments through GIT. Our current build environment uses symbolic links into the git repo and Coverity does not follow the link into the actual location of the source file to determine the git author.
- Single API for all interactions. I am not a fan of using both SOAP and REST APIs and Coverity offers a mix of functionality depending on the interface used. I would greatly prefer a full REST API with improved documentation for all actions including issuing assignments, streaming, and project creation.
For how long have I used the solution?
One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Consaltant at a tech consulting company with 501-1,000 employees
An easy-to-set-up solution used to find vulnerabilities in C++ codes, but its user interface could be improved
Pros and Cons
- "Coverity is easy to set up and has a less lengthy process to find vulnerabilities."
- "The solution's user interface and quality gate could be improved."
What is our primary use case?
We are working on medical devices, and the code base is written in C++. We use Coverity to find the vulnerability in those C++ codes.
What is most valuable?
Coverity is easy to set up and has a less lengthy process to find vulnerabilities.
What needs improvement?
The solution's user interface and quality gate could be improved.
For how long have I used the solution?
I have been using Coverity for four months.
What do I think about the stability of the solution?
Coverity has good stability.
I rate Coverity more than eight out of ten for stability.
What do I think about the scalability of the solution?
Around 20 to 25 developers use Coverity in our organization.
I rate Coverity a seven to eight out of ten for scalability.
Which solution did I use previously and why did I switch?
We use SonarQube for Java-based projects and Coverity for C and C++-based projects.
How was the initial setup?
The solution’s initial setup is simple.
What other advice do I have?
Overall, I rate Coverity a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Software Developer at Altair
Scalable, good for cluster structures, and has helpful technical support
Pros and Cons
- "Coverity is scalable."
- "Coverity is not stable."
What is our primary use case?
We are using GK and the latest version for port deployment.
For how long have I used the solution?
I have been using Coverity for three and a half years.
What do I think about the stability of the solution?
Coverity is not stable but it is sufficient for our organization's requirements.
What do I think about the scalability of the solution?
Coverity is scalable.
How are customer service and support?
We contacted technical support to help us clean up an issue we had.
What other advice do I have?
If they have a cluster structure, then definitely they should use Coverity. I would rate Coverity a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sr. QA Engineer at a computer software company with 1-10 employees
Good tech support but it doesn't report errors like it should
Pros and Cons
- "I encountered a bug with Coverity, and I opened a ticket. Support provided me with a workaround. So it's working at the moment, or at least it seems to be."
- "Coverity is far from perfection, and I'm not 100 percent sure it's helping me find what I need to find in my role. We need exactly what we are looking for, i.e. security errors and vulnerabilities. It doesn't seem to be reporting while we are changing our code."
What is our primary use case?
We use Coverity for static analysis of our code.
What needs improvement?
Coverity is far from perfection, and I'm not 100 percent sure it's helping me find what I need to find in my role. We need exactly what we are looking for, i.e. security errors and vulnerabilities. It doesn't seem to be reporting while we are changing our code. So either we are perfect, or the tool is missing something.
For how long have I used the solution?
I've been using Coverity for a couple of years.
What do I think about the scalability of the solution?
I haven't had much experience trying to scale up Coverity. Only three people at our company work with it.
How are customer service and support?
I encountered a bug with Coverity, and I opened a ticket. Support provided me with a workaround. So it's working at the moment, or at least it seems to be. They are on par with other tech support in terms of knowledge. However, their style of communication could use some improvement.
How was the initial setup?
Setting up Coverity is highly complex. The upgrade procedure is also pretty tough. We've had trouble with it on at least one occasion. When I went ahead with it, it destroyed the installation. I couldn't go back. So it's challenging to understand from the documentation. It seems like they tried to cover all possible topics in their manuals, so they ended up scratching the surface of everything in the world except for the particular practical items that I needed.
What's my experience with pricing, setup cost, and licensing?
Coverity is very expensive.
What other advice do I have?
I rate Coverity five out of 10, but it's tough for me to judge because we decided to purchase it based on one requirement that no other static analysis tool could satisfy. For that reason, we haven't tried anything else. So, let's make an analogy. Let's say I used Sony TVs my entire life, and someone comes up and says, "Hey, there is a new brand of TVs. What do you think of them? Do you think they are good?" How would I know? By comparison, SonarQube seems to be more feature-rich for a standard programming language, and it works with more continuous integration tools.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director at a manufacturing company with 10,001+ employees
Stable, scalable, and provides reports about a lot of potential defects
Pros and Cons
- "It provides reports about a lot of potential defects."
- "Its price can be improved. Price is always an issue with Synopsys."
What is our primary use case?
We use it in our company during product development.
What is most valuable?
It provides reports about a lot of potential defects.
What needs improvement?
Its price can be improved. Price is always an issue with Synopsys.
For how long have I used the solution?
I have been using Coverity for about three or four years.
What do I think about the stability of the solution?
It has good stability.
What do I think about the scalability of the solution?
Its scalability is good.
How are customer service and technical support?
They are professional and very responsible. They have a local FAE.
How was the initial setup?
It is not straightforward, but it is also not too complex. The learning curve needed for installing Coverity is okay.
What's my experience with pricing, setup cost, and licensing?
It is expensive.
What other advice do I have?
I would recommend this solution if you can afford it. If you have enough budget, it is one of the best solutions right now. There may be other cheaper solutions, but you get what you pay for.
We have been using Coverity for several years. We would not have continued using it if it was not a good solution. We always have some minor questions or improvements for them, and they always give us a relatively fast response.
I would rate Coverity a nine out of ten. Only its price should be improved.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Static Application Security Testing (SAST)Popular Comparisons
SonarQube Server (formerly SonarQube)
Veracode
GitLab
Checkmarx One
OWASP Zap
SonarQube Cloud (formerly SonarCloud)
Fortify on Demand
Acunetix
PortSwigger Burp Suite Professional
HCL AppScan
Qualys Web Application Scanning
Klocwork
Invicti
Parasoft SOAtest
Kiuwan
Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the difference between Coverity and SonarQube?
- What is the biggest difference between Coverity and SonarQube?
- How would you decide between Coverity and Sonarqube?
- What Application Security Solution Do You Use That Is DevOps Friendly?
- Which is the most comprehensive open source Web Security Testing tool?
- What is the best Application Security Testing platform?
- When evaluating Application Security Testing, what aspect do you think is the most important to look for?
- SAST vs. DAST: Which is better for application security testing?
- What tools do you rely on for building a DevSecOps pipeline?
- What does the Log4j/Log4Shell vulnerability mean for your company?