富士ソフト インダストリービジネス事業部 Official site

Static analysis tool "Black Duck Coverity"

Coverity detects defects and vulnerabilities hidden in source code early, enabling high-quality and secure development.

Coverity Static Analysis is a static analysis (SAST) tool provided by Black Duck, which is globally adopted in the field of application security. It detects defects and security vulnerabilities without executing the source code, supporting improvements in quality and security from the early stages of development. Utilizing its unique advanced analysis technology, it analyzes data flows and execution paths across functions and modules, accurately detecting critical defects such as null references, memory leaks, deadlocks, and race conditions. Additionally, practical analysis results that minimize false positives allow developers to focus on the issues that truly need attention. It supports a wide range of languages including C/C++, Java, C#, Python, and Go, and is utilized in diverse development environments from embedded software to business systems and web applications. Furthermore, it integrates with development tools such as GitHub, GitLab, and Jenkins, enabling the automation of quality management in CI/CD environments. Fujisoft provides comprehensive support from the introduction of Coverity to operational establishment and integration into development processes, assisting customers in improving quality and building a secure software development framework.

Static analysis tool "Black Duck Coverity"

basic information

**Effects of Introduction** - Detect defects and vulnerabilities early in the development process, reducing rework costs - Improve software quality and security levels - Reduce code review and verification effort, enhancing development efficiency - Automate quality checks in CI/CD environments - Support secure development and compliance measures **Features** - High-precision detection of defects such as null references, memory leaks, and deadlocks - Efficient quality improvement achieved through analysis results with reduced false positives - Compatible with development environments like GitHub, GitLab, and Jenkins - Compliant with major standards such as MISRA, CERT, OWASP Top 10, and CWE Top 25 **Strengths of Fujisoft** Fujisoft provides one-stop support from the introduction of Black Duck products to operational establishment. Leveraging a wide range of experience from embedded software development to business system development, we propose optimal implementations tailored to our customers' development environments and operational policies. Additionally, by supporting integration with CI/CD environments, embedding into quality management processes, and formulating operational rules, we assist in building a continuous quality improvement and secure development system that cannot be achieved by tool implementation alone.

Price range

Delivery Time

Applications/Examples of results

- Quality and security verification in automotive software development - Static analysis of software for embedded devices and IoT devices - Quality improvement measures for industrial equipment and control systems - Vulnerability detection in web applications and business systems - Automated quality checks in DevSecOps and CI/CD environments - Compliance with various standards and guidelines such as MISRA, CERT, and OWASP - Development of systems requiring high reliability in finance, healthcare, and manufacturing - Code quality management in large-scale software development

Recommended products

Distributors

Fujisoft has a history of 40 years in embedded development since its founding, accumulating various experiences in both software and hardware. Based on the experience cultivated over many years, a team of over 2,000 embedded technology experts provides embedded services across a wide range of fields, including automotive, medical, industrial, and home appliances. Our seamless development system, covering everything from hardware to software, allows our consultants to propose solutions starting from the "soft phase," such as requirements specification, and we offer a consistent solution that encompasses development, research, testing, and production.