---
title: Black Duck Coverity Static Reviews
meta_title: 'Black Duck Coverity Static Reviews 2026: Details, Pricing, & Features
  | G2'
meta_description: Filter 65 reviews by the users' company size, role or industry to
  find out how Black Duck Coverity Static works for a business like yours.
aggregate_rating:
  rating_value: 4.3
  review_count: 65
  scale: '5'
date_modified: '2026-07-20'
parent_category:
  name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t"
  url: https://www.g2.com/categories/devsecops
---

# Black Duck Coverity Static Reviews
**Vendor:** Black Duck  
**Category:** [Static Application Security Testing (SAST) Software](https://www.g2.com/categories/static-application-security-testing-sast)  
**Average Rating:** 4.3/5.0  
**Total Reviews:** 65
## About Black Duck Coverity Static
Coverity® is a fast, accurate, and highly scalable static analysis (SAST) solution that helps development and security teams address security and quality defects early in the software development life cycle (SDLC), track and manage risks across the application portfolio, and ensure compliance with security and coding standards.




## Black Duck Coverity Static Reviews
  ### 1. Functional but duplicated information

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** July 17, 2018

**What do you like best about Black Duck Coverity Static?**

The ability of separate bugs by types and different folders where the source code is located.

**What do you dislike about Black Duck Coverity Static?**

There are a lot of duplicated information, and fake bugs that depending of the compiler it seems to be an error or not.

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

Checking code syntax error and possible memory leaks.

  ### 2. Comprehensive static analysis tool

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** July 08, 2018

**What do you like best about Black Duck Coverity Static?**

The reports are easy to read and understand, helping you find and fix bugs quickly.

**What do you dislike about Black Duck Coverity Static?**

It can take a bit of work to set up suitably for a given project.

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

Automates the process of catching otherwise hard to detect bugs in software.

  ### 3. Best for finding security issues 

**Rating:** 3.5/5.0 stars

**Reviewed by:** Raju K. | Small-Business (50 or fewer emp.)

**Reviewed Date:** June 04, 2018

**What do you like best about Black Duck Coverity Static?**

Security issues
Static dynamic code analysis 


**What do you dislike about Black Duck Coverity Static?**

False positives are not detected properly with code analysis 

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

Code reviews for early security bugs 

  ### 4. Well done service

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Small-Business (50 or fewer emp.)

**Reviewed Date:** July 30, 2018

**What do you like best about Black Duck Coverity Static?**

The good technical service it offers, in less than 24h

**What do you dislike about Black Duck Coverity Static?**

The user experience is a bit confusing if you're new

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

Security issues we have everyday

  ### 5. Coverity

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Semiconductors | Enterprise (> 1000 emp.)

**Reviewed Date:** November 08, 2017

**What do you like best about Black Duck Coverity Static?**

It scrutinizes code with somewhat blind logic and address weak point of the code. It is good at identifying vulnerable points and helps toward future proof coding. Automatic backround run also make its integration into code flow seamless. Code analysis and suggestion is quite amazing and accurate so help the fix or improvement a lot. 

**What do you dislike about Black Duck Coverity Static?**

By nature, it runs blind test to many degree so usage based limits are not well honored. It's like double edge of sword so it is its own strong point but at the same time somewhat stubburn point also. Review or coordinated work support is one of lacking capability. It just has tracking capability currently. 

**Recommendations to others considering Black Duck Coverity Static:**

For longer term projects, across large group of teams with different coding level background, coverity can be a great tool to maintain quality and plug possible vulnerable coding practice through through check. 

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

Robustness in code in general. Great help in achieving uniform coding quality across multiple team with diverse background. 

  ### 6. Detailed and Complete 

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Computer Software | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 18, 2017

**What do you like best about Black Duck Coverity Static?**

Specific feedback broken down to the line of code where the opportunity for improvement has been found. Can easily track which issues have been addressed and what the resolution was, or that code is as expected or otherwise won't be updated and it will quit flagging that issue.

**What do you dislike about Black Duck Coverity Static?**

Adds overhead to the build, slowing them down a bit. I also understand that it is fairly expensive although I don't manage the budget so I just try to make good use of the results.

**Recommendations to others considering Black Duck Coverity Static:**

We also considered using Visual Studio Team System tools, NAnt and SonarQube.

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

Shipping code with fewer bugs. We also used it to evaluate changes from one compiler version to the next.

  ### 7. Great tool for finding code defects

**Rating:** 4.5/5.0 stars

**Reviewed by:** Bill C. | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 12, 2017

**What do you like best about Black Duck Coverity Static?**

Coverity was able to find  code defects that other products were unable to find. 
It was incorporated in our build easily and support was great.

**What do you dislike about Black Duck Coverity Static?**

We hit a few defects when looking at our million+ lines of code project. Some were 
not code defects but flagged as defects. Others we would like to pass certian
constructs without warning, but were unable.

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

We were able to increase reliability of our product which made our customers very happy.

  ### 8. Coverity - Static Code Analysis Tool of Choice

**Rating:** 5.0/5.0 stars

**Reviewed by:** Benjamin C. | Director - Application Security, Computer Software, Enterprise (> 1000 emp.)

**Reviewed Date:** November 28, 2017

**What do you like best about Black Duck Coverity Static?**

The 2017 version of Coverity scans the latest of version of C++ and Javascript (ES6) better than the other SAST tools.

**What do you dislike about Black Duck Coverity Static?**

Coverity's licensing is based on the number of developers who work on a component that is scanned, rather than the number of developers who actually use the tool.

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

Business problems being solved by using Coverity are to uncover security vulnerabilities in code before code is released.   We have caught security vulnerabilities before code has been released to the livesite.

  ### 9. Good tool for static analysis

**Rating:** 4.0/5.0 stars

**Reviewed by:** Jim C. | Director of QA, Internet, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 21, 2017

**What do you like best about Black Duck Coverity Static?**

Very good for embedded development and very effective in detecting hard-to-find bugs. Very low false positive rate. 

**What do you dislike about Black Duck Coverity Static?**

Analysis Result dashboard can be more user friendly.

**Recommendations to others considering Black Duck Coverity Static:**

Useful for finding the corner cases and minute bugs

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

It supports wide variety of platforms and with number of different compilers.

  ### 10. Good product

**Rating:** 3.0/5.0 stars

**Reviewed by:** Kevin K. | Core Developer, Computer Software, Mid-Market (51-1000 emp.)

**Reviewed Date:** November 29, 2017

**What do you like best about Black Duck Coverity Static?**

It is very helpful in getting the errors fixed quickly and it gives the solutions

**What do you dislike about Black Duck Coverity Static?**

The user interface is pretty ugly in my opinion

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

Possible security risks

  ### 11. Coverity for code quality and analysis

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Telecommunications | Enterprise (> 1000 emp.)

**Reviewed Date:** January 07, 2018

**What do you like best about Black Duck Coverity Static?**

I like static and dynamic analysis of code..The root cause of each defect is clearly explained, 

**What do you dislike about Black Duck Coverity Static?**

Certain times becomes slow,Easy to implement, challenging to get teams to adopt and use effectively

**Recommendations to others considering Black Duck Coverity Static:**

Yes I would like to recommend

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

making it easy to fix bugs

  ### 12. Decent but could be better

**Rating:** 3.0/5.0 stars

**Reviewed by:** Verified User in Semiconductors | Enterprise (> 1000 emp.)

**Reviewed Date:** January 02, 2018

**What do you like best about Black Duck Coverity Static?**

It has caught some serious memory leak issues. It is good to have. 

**What do you dislike about Black Duck Coverity Static?**

Many false positives and dead code detections have been frustrating. 

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

Code quality and memory leak detections

  ### 13. Excellent Static code analysis tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Enterprise (> 1000 emp.)

**Reviewed Date:** November 17, 2017

**What do you like best about Black Duck Coverity Static?**

Its excellent features like dereferences of NULL pointers, buffer overruns, concurrency issues and many more

**What do you dislike about Black Duck Coverity Static?**

Nothing at all, I find the tool very useful for many coding problems

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

Production code is thoroughly analyzed before deployment.

  ### 14. Coverity for static analysis

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Wireless | Mid-Market (51-1000 emp.)

**Reviewed Date:** March 18, 2017

**What do you like best about Black Duck Coverity Static?**

The path detection and pointing exact location of defect

**What do you dislike about Black Duck Coverity Static?**

Longer compile time and some of the graphs shown 

**What problems is Black Duck Coverity Static solving and how is that benefiting you?**

Code quality and automation of reducing defect density

  ### 15. WhiteHat's Sentinel

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Banking

**Reviewed Date:** April 03, 2013

**What do you like best about Black Duck Coverity Static?**

This is a cloud based service that specializes in continuous application security scanning services. Their tool set runs continuously to identify vulnerabilities using production safe scanning. The scan process is slower but very thorough. WhiteHat also has human testers manually review all results, ensuring zero false positives.

The solution is extremely compelling, they have expert testers who provide a zero false positive rate and great results. This has proved to be a tremendous cloud offering, where we only deal with proven vulnerabilities, saving us huge amounts of time.

**What do you dislike about Black Duck Coverity Static?**

There isn't much to dislike about this service, the cost is relatively reasonable but a bit on the high side. They don't yet have great support for web services or native mobile apps, but as I understand that is on its way. That is really the only criticism I have to offer.

**Recommendations to others considering Black Duck Coverity Static:**

Even if you are skeptical, run through a trial of the solution. Their results will surprise you and show you the value you need.


## Black Duck Coverity Static Discussions
  - [What is Coverity used for?](https://www.g2.com/discussions/what-is-coverity-used-for)
  - [What is coverity connect?](https://www.g2.com/discussions/what-is-coverity-connect)
  - [How does Coverity Static Analysis work?](https://www.g2.com/discussions/how-does-coverity-static-analysis-work)
  - [What is Coverity report?](https://www.g2.com/discussions/what-is-coverity-report)
  - [What is Coverity software?](https://www.g2.com/discussions/what-is-coverity-software)

- [View Black Duck Coverity Static pricing details and edition comparison](https://www.g2.com/products/black-duck-coverity-static/reviews?page=2&section=pricing&secure%5Bexpires_at%5D=2026-08-01+13%3A43%3A42+-0500&secure%5Bsession_id%5D=01877046-8602-42d2-b9a2-b8cab4bb1d5d&secure%5Btoken%5D=f61e37dcc227e74b36a926a61a92c2931c2331170dfb6a5709b85394ec273ae6&format=llm_user)

## Black Duck Coverity Static Features
**Administration**
- API / Integrations
- Extensibility

**Documentation**
- Feedback
- Prioritization
- Remediation Suggestions

**Agentic AI - Static Code Analysis**
- Adaptive Learning
- Natural Language Interaction
- Proactive Assistance

**Analysis**
- Reporting and Analytics
- Issue Tracking
- Static Code Analysis
- Code Analysis

**Security**
- False Positives
- Custom Compliance
- Agility

**Testing**
- Command-Line Tools
- Manual Testing
- Test Automation
- Compliance Testing
- Black-Box Scanning
- Detection Rate
- False Positives

**Agentic AI - Static Application Security Testing (SAST)**
- Autonomous Task Execution

## Top Black Duck Coverity Static Alternatives
  - [SonarQube](https://www.g2.com/products/sonarqube/reviews) - 4.4/5.0 (153 reviews)
  - [Checkmarx](https://www.g2.com/products/checkmarx/reviews) - 4.2/5.0 (44 reviews)
  - [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews) - 3.8/5.0 (25 reviews)

