Black Duck Coverity is a paid static analysis solution for finding security vulnerabilities and code quality defects in source code before software ships. It examines source without executing it and analyzes codebases across files and libraries. Black Duck lists support for 22 programming languages and more than 250 frameworks, with standards including MISRA, AUTOSAR, ISO 26262, PCI DSS, CERT C/C++/Java, DISA STIG, OWASP Top 10, and CWE Top 25. The Code Sight IDE plug-in provides real-time results, issue summaries, and code fixes. IDE, source-control, and CI connections can trigger scans on commits and pull requests; listed integrations include GitHub, GitLab, Bitbucket, Azure DevOps, Jenkins, AWS CodeBuild, Concourse, and Travis CI. Deployment supports fully air-gapped on-premises environments, including Kubernetes clusters. Coverity Connect and Coverity Reports support Windows and Linux servers. Pricing is by enterprise quote, customized to team size and codebase; there is no free plan listed.
Who it is for
It suits organizations seeking static source-code analysis integrated into development workflows, especially teams working with the listed languages, frameworks, and compliance standards.
What is good
- Scans code without executing it
- Supports 22 languages and over 250 frameworks
- IDE plug-in provides code fixes and issue summaries
- Scans can run on commits and pull requests
- Supports air-gapped on-premises deployment
What to know first
- No free plan is listed
- Pricing requires an enterprise quote
- Price is customized to team size and codebase
Verdict
Coverity pairs broad language and framework coverage with IDE, source-control, and CI integrations. Teams need to request a quote, and the facts list no free plan.
Black Duck Coverity plans and pricing
All plansCompared on static analysis tools
- Free plan
- No



