We performed a comparison between Coverity and Polyspace Code Prover based on real PeerSpot user reviews.
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Static Application Security Testing (SAST)."The product has been beneficial in logging functionality, allowing me to categorize vulnerabilities based on severity. This aids in providing updated reports on subsequent scans."
"It's pretty stable. I rate the stability of Coverity nine out of ten."
"Coverity is scalable."
"We were very comfortable with the initial setup."
"The solution has helped to increase staff productivity and improved our work significantly by approximately 20 percent."
"It's very stable."
"This solution is easy to use."
"The security analysis features are the most valuable features of this solution."
"Polyspace Code Prover has made me realize it differs from other static code analysis tools because it runs the code. So it's quite distinct in that aspect."
"The product detects memory corruptions."
"Polyspace Code Prover is a very user-friendly tool."
"When we work on safety modules, it is mandatory to fulfill ISO 26262 compliance. Using Prover helps fulfill the standard on top of many other quality checks, like division by zero, data type casts, and null pointer dereferences."
"The outputs are very reliable."
"They could improve the usability. For example, how you set things up, even though it's straightforward, it could be still be easier."
"The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming."
"Coverity is not stable."
"We use GitHub and Gitflow, and Coverity does not fit with Gitflow. I have to create a screen for our branches, and it's a pain for developers. It has been difficult to integrate Coverity with our system."
"Coverity could improve the ease of use. Sometimes things become difficult and you need to follow the guides from the website but the guides could be better."
"Coverity is far from perfection, and I'm not 100 percent sure it's helping me find what I need to find in my role. We need exactly what we are looking for, i.e. security errors and vulnerabilities. It doesn't seem to be reporting while we are changing our code."
"We'd like it to be faster."
"The level of vulnerability that this solution covers could be improved compared to other open source tools."
"Automation could be a challenge."
"I'd like the data to be taken from any format."
"One of the main disadvantages is the time it takes to initiate the first run."
"The tool has some stability issues."
"Using Code Prover on large applications crashes sometimes."
Coverity is ranked 4th in Static Application Security Testing (SAST) with 34 reviews while Polyspace Code Prover is ranked 23rd in Application Security Tools with 5 reviews. Coverity is rated 7.8, while Polyspace Code Prover is rated 7.6. The top reviewer of Coverity writes "Best SAST tool to check software quality issues". On the other hand, the top reviewer of Polyspace Code Prover writes "A stable solution for developing software components". Coverity is most compared with SonarQube, Klocwork, Fortify on Demand, Checkmarx One and Polaris Software Integrity Platform, whereas Polyspace Code Prover is most compared with SonarQube, Klocwork, CodeSonar, Parasoft SOAtest and GitLab.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.