TrustRadius: an HG Insights company

FOSSA vs. Coverity Static Analysis (SAST)

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    FOSSA

    Score2 out of 10
    N/AFOSSA is a software composition analysis tool that continuously scans for open-source components and tracks dependencies and license compliance.N/A

    Synopsys Coverity

    Score8.3 out of 10
    N/ASynopsys offers the Coverity static application security testing (SAST) solution, to help users build software that’s more secure, higher-quality, and compliant with standards.N/A
    Pricing
    FOSSASynopsys Coverity
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    FOSSASynopsys Coverity
    Free Trial
    NoNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoYes
    Entry-level Setup FeeNo setup feeOptional
    Additional Details—Contact the Synopsys Software Integrity Group (SIG) Sales team at https://www.synopsys.com/software-integrity/contact-sales.html for more detailed pricing information.
    More Pricing Information
    Best Alternatives
    FOSSASynopsys Coverity
    Small Businesses
    No answers on this topic
    No answers on this topic
    Medium-sized Companies
    No answers on this topic
    SonarQube
    Score8.7 out of 10
    Enterprises
    No answers on this topic
    SonarQube
    Score8.7 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    FOSSASynopsys Coverity
    Likelihood to Recommend
    5.0
    (1 ratings)
    9.0
    (1 ratings)
    Support Rating
    10.0
    (1 ratings)
    -
    (0 ratings)
    User Testimonials
    FOSSASynopsys Coverity
    Likelihood to Recommend
    FOSSA
    The only issue we have had is sometimes the web app is too slow, and that causes issues with us wanting to continue to use FOSSA over going with another tool. That is the only problem. I noticed it happened more recently, but if that is solved now or will be solved, I would 100% recommend this tool to anyone!
    Incentivized
    Read full review
    Synopsys
    Best suits for large scale and dynamic development environment. It may be best tool if you want to release your apps with less TAT. However if you have a CRM tool which is COTS product it can offer little help. Even then you should be familiar with what features of Coverity Static Analysis (SAST) are helpful for your development environment
    Incentivized
    Read full review
    Pros
    FOSSA
    • Setup of tool.
    • Speed of scans.
    • Automated emails with reports.
    Incentivized
    Read full review
    Synopsys
    • It can provide security scanning dashboard
    • Help detect vulnerabilities and recommend remediation
    • Integration of devsecops helps speed up release cycles
    Incentivized
    Read full review
    Cons
    FOSSA
    • Interface for loading results can be slow, this is the #1 issue we have faced.
    • Speed of scans could be improved.
    Incentivized
    Read full review
    Synopsys
    • Coverage of integration with other security tools can be improved
    • Customisation of dashboard to enable customer choice of tracking
    • Showcase devsecops progressive tasks from SLA and violation from code scanner perspective
    Incentivized
    Read full review
    Support Rating
    FOSSA
    Never needed support but the chat and help seem forefront of the app!
    Incentivized
    Read full review
    Synopsys
    No answers on this topic
    Alternatives Considered
    FOSSA
    BlackDuck and Synk
    Incentivized
    Read full review
    Synopsys
    Coverity Static Analysis (SAST) has wide coverage in terms of Owasp Top 10 vulnerabilities, various types of languages, backward integration. While other tools offer similar experience of code scanning, coverity helps in pointed recommendations for quick closure of vulnerabilities. The historical analysis of vulnerabilities is a good value add in understanding which type of code and which language is better in improving cyber security maturity.
    Incentivized
    Read full review
    Return on Investment
    FOSSA
    • Hard to measure the ROI, but no doubt having licenses be above board is fantastic for protection of your software.
    • Caused developers to make more informed decisions.
    Incentivized
    Read full review
    Synopsys
    • Helped reduce efforts of development team avoiding rework
    • Increased security maturity
    • Increased efficiency of the teams
    Incentivized
    Read full review
    ScreenShots

    Synopsys Coverity Screenshots

    Screenshot of Coverity works with the Code Sight™ IDE plugin, enabling developers to find and fix security and quality defects as they write code.Screenshot of Coverity provides broad security and quality checker support for 21 languages and over 70 frameworks.