Recommendations to others considering Black Duck Coverity Static:
Use Jenkins to scan the code both the raw code and also at compile time when it's pulling in all the libraries and dependencies. Whenever a MR is submitted to Gitlab, it triggers a Jenkins job which will scan the raw code. Whenever a Jenkins build is tagged as release candidate, Coverity gets pulled in after everything is downloaded and built/compiled/etc. Review collected by and hosted on G2.com.
What problems is Black Duck Coverity Static solving and how is that benefiting you?
It picked up all the big ones and it picked up a lot more stuff overall than the other scanners. The stuff it picked up was legitimate also, not a lot of false positives/alerts, useless noise that didn't warrant attention. We did a comprehensive analysis against multiple security scanners and spent 2 days comparing the scanning results of 4 different scanners against 4 different git repositories, aligning all the detections next to each other to see how they matched up, and in the end, Coverity won. Review collected by and hosted on G2.com.