We have a development team and we are using this product for static code analysis.
Senior Technical Specialist at a tech services company with 201-500 employees
Integrates well with Jenkins and GitLab, and has helped us find errors before going into production
Pros and Cons
- "The most valuable feature is the integration with Jenkins."
- "Ideally, it would have a user-based license that does not have a restriction in the number of lines of code."
What is our primary use case?
How has it helped my organization?
This product has definitely helped our organization. Based on what I have heard from the development team, they have found a lot of issues before code goes into production.
What is most valuable?
The most valuable feature is the integration with Jenkins. Jenkins can be used to automatically run it to perform the code analysis.
Integration with GitLab is helpful.
What needs improvement?
Coverity is too costly, which is why we are trying other tools. Ideally, it would have a user-based license that does not have a restriction in the number of lines of code.
Buyer's Guide
Coverity
December 2024
Learn what your peers think about Coverity. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
For how long have I used the solution?
We have been using Coverity for between five and six years.
What do I think about the scalability of the solution?
Coverity is used across our entire organization.
How was the initial setup?
The initial setup in the Windows environment was straightforward. However, for Linux, it has some complexity.
What about the implementation team?
We have a separate team in the company that takes care of deployment. One person is enough for the task
What's my experience with pricing, setup cost, and licensing?
The licensing fees are based on the number of lines of code. We may not need more than five user licenses but with a restriction on the number of lines of code, for a small company the cost will shoot up.
Which other solutions did I evaluate?
Our license for Coverity has expired and we are in the process of exploring new static code analysis tools. Ideally, we would like to have one that is low-cost.
One of the products that I have downloaded a trial version for is SonarQube. At this point, I have only installed the Windows version but I plan on testing the Linux version, as well.
What other advice do I have?
In summary, this is a helpful product and the feedback that I have heard from the development team is good.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Chief Specialist at a government with 501-1,000 employees
The product improves the quality of my work, but the usability could be improved
Pros and Cons
- "The solution has helped to increase staff productivity and improved our work significantly by approximately 20 percent."
- "They could improve the usability. For example, how you set things up, even though it's straightforward, it could be still be easier."
What is our primary use case?
I am using the latest version for my business. I personally do product evaluations, and this product has improved the efficiency of my work.
How has it helped my organization?
The product improves the way that we do product evaluations.
What is most valuable?
It improves the quality of my work.
What needs improvement?
They could improve the usability. For example, how you set things up, even though it's straightforward, it could be still be easier.
What do I think about the stability of the solution?
The stability works quite well.
What do I think about the scalability of the solution?
The scalability is good enough.
How are customer service and technical support?
We haven't had any problems with the product so far.
Which solution did I use previously and why did I switch?
We did not have another solution before. We decided to purchase Coverity because the way we were working previously wasn't efficient. So, we were trying to improve our efficiency.
How was the initial setup?
The initial setup was straightforward.
What was our ROI?
We have seen ROI.
The solution has helped to increase staff productivity and improved our work significantly by approximately 20 percent.
Which other solutions did I evaluate?
This solution seemed to fit our purposes.
What other advice do I have?
Try it out for yourself, and decide whether it's useful for you.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Static Application Security Testing (SAST)Popular Comparisons
SonarQube Server (formerly SonarQube)
Veracode
GitLab
Checkmarx One
OWASP Zap
SonarQube Cloud (formerly SonarCloud)
Fortify on Demand
Acunetix
PortSwigger Burp Suite Professional
HCL AppScan
Qualys Web Application Scanning
Klocwork
Invicti
Parasoft SOAtest
Kiuwan
Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the difference between Coverity and SonarQube?
- What is the biggest difference between Coverity and SonarQube?
- How would you decide between Coverity and Sonarqube?
- What Application Security Solution Do You Use That Is DevOps Friendly?
- Which is the most comprehensive open source Web Security Testing tool?
- What is the best Application Security Testing platform?
- When evaluating Application Security Testing, what aspect do you think is the most important to look for?
- SAST vs. DAST: Which is better for application security testing?
- What tools do you rely on for building a DevSecOps pipeline?
- What does the Log4j/Log4Shell vulnerability mean for your company?