We performed a comparison between Coverity and ShiftLeft based on real PeerSpot user reviews.
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Application Security Testing (AST)."The solution has improved our code quality and security very well."
"The product has been beneficial in logging functionality, allowing me to categorize vulnerabilities based on severity. This aids in providing updated reports on subsequent scans."
"The solution effectively identifies bugs in code."
"We were very comfortable with the initial setup."
"The most valuable feature of Coverity is the wrapper. We use the wrapper to build the C++ component, then we use the other code analysis to analyze the code to the build object, and then send back the result to the SonarQube server. Additionally, it is a powerful capabilities solution."
"I like Coverity's capability to scan codes once we push it. We don't need more time to review our colleagues' codes. Its UI is pretty straightforward."
"The most valuable feature is that there were not a whole lot of false positives, at least on the codebases that I looked at."
"Coverity gives advisory and deviation features, which are some of the parts I liked."
"When it comes to ShiftLeft, the most valuable feature is definitely its ease of use and cost-effectiveness."
"We actually specified several checkers, but we found some checkers had a higher false positive rate. I think this is a problem. Because we have to waste some time is really the issue because the issue is not an issue. I mean, the tool pauses or an issue, but the same issue is the filter now.Some check checkers cannot find some issues, but sometimes they find issues that are not relevant, right, that are not really issues. Some customisation mechanism can be added in the next release so that we can define our Checker. The Modelling feature provided by Coverity helps in finding more information for potential issues but it is not mature enough, it should be mature. The fast testing feature for security testing campaign can be added as well. So if you correctly integrate it with the training team, maybe you can help us to find more potential issues."
"It would be great if we could customize the rules to focus on critical issues."
"Ideally, it would have a user-based license that does not have a restriction in the number of lines of code."
"The tool needs to improve its reporting."
"The solution could use more rules."
"I would like to see integration with popular IDEs, such as Eclipse."
"Its price can be improved. Price is always an issue with Synopsys."
"Sometimes it's a bit hard to figure out how to use the product’s UI."
"Having support from senior management is crucial in making it mandatory for teams to collaborate with the security team throughout the development process."
Coverity is ranked 4th in Application Security Testing (AST) with 33 reviews while ShiftLeft is ranked 18th in Application Security Testing (AST) with 1 review. Coverity is rated 7.8, while ShiftLeft is rated 10.0. The top reviewer of Coverity writes "Best SAST tool to check software quality issues". On the other hand, the top reviewer of ShiftLeft writes "Effectively in identify and fix bugs early in the development lifecycle". Coverity is most compared with SonarQube, Klocwork, Fortify on Demand, Checkmarx One and Veracode, whereas ShiftLeft is most compared with SonarQube, Black Duck and Semgrep Supply Chain.
See our list of best Application Security Testing (AST) vendors.
We monitor all Application Security Testing (AST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.