David Woodhouse at AWS, who maintains the open source OpenConnect VPN client, explains how he integrated Coverity Scan with GitLab CI.
MITRE’s 2019 CWE Top 25 list contains many code quality issues that can result in security vulnerabilities. Static analysis can help you mitigate them.
Web frameworks can introduce security issues into web applications. Mitigate this risk with a static analysis tool that understands the frameworks you use.
With so many application security tools, how do you choose the best ones for your environment? Learn how to assemble your application security toolkit.
Code quality and code security aren’t the same, but they’re closely related. And in the current cyberthreat environment, developers should care about both.
The Code Sight IDE plugin uses the Coverity static analysis engine to find issues as developers code. Release 2019.4 supports more languages and IDEs.
Posted in Static Analysis (SAST) | Comments Off on Announcing Code Sight 2019.4
Static application security testing helps you find and fix vulnerabilities earlier in the development life cycle, resulting in more secure software.
Posted in Static Analysis (SAST) | Comments Off on How to win the application security arms race
Improve your web application security management by finding and fixing security vulnerabilities earlier and achieving compliance with industry standards.
Posted in Static Analysis (SAST) | Comments Off on How to manage web application security with Coverity
You’ve finally purchased a static analysis solution—but do you know how to use it? Learn how to implement SAST tools in a way that best suits your environment.
Posted in Static Analysis (SAST) | Comments Off on So you just bought a SAST tool. Now what?
Both enterprise and open source static analysis tools can boost your application security program. But each has its strengths. Learn more before you choose.
Posted in Static Analysis (SAST) | Comments Off on How to choose between enterprise and open source static analysis