Synopsys a Leader in Static Application Security Testing

Synopsys Inc. has been positioned as a leader in The Forrester Wave: Static Application Security Testing, Q4 2017.

The report provides an in-depth analysis evaluating the 10 most significant vendors in static application security testing (SAST). The Synopsys Static Analysis (Coverity) solution received the highest scores in the current offering and strategy categories. Within the current offering category, Synopsys also received the highest scores in the criteria of rule management and software development life cycle (SDLC) integration.

"We're proud to have Forrester recognise Synopsys as a leader in SAST," said Andreas Kuehlmann, GM of the Synopsys Software Integrity Group. "As the foundational component of our Software Integrity Platform, the Synopsys Static Analysis solution has not only continued to deliver the value customers expect from an enterprise SAST tool— but it has also evolved to address emerging trends in software like the shift to more rapid and iterative development workflows and the increasingly diverse ecosystem of programming languages, frameworks, and toolchains."

According to the Forrester Wave report, "Synopsys provides SAST scanning capabilities for use early in the SDLC. Synopsys Static Analysis (formerly Synopsys Coverity) is the company's traditional SAST scanning tool, and SecureAssist provides on-the-fly scanning inside the IDE. Synopsys Static Analysis helps users view the impact of rule changes by displaying a comparison of results before and after the change without requiring a new scan… Synopsys Static Analysis stands out for its strong rule management and SDLC integration."

The Forrester Wave report also states, "Security pros need SAST tools to enable developers. Companies have traditionally used SAST tools late in the software development life cycle (SDLC) to scan products for vulnerabilities in proprietary code. Now, SAST vendors are trying to serve new users as security pros demand that their products give developers early remediation advice throughout the SDLC."

The Synopsys Static Analysis solution, a core component of the Synopsys Software Integrity Platform, has a strong legacy as a development tool for reducing risk and lowering overall project cost by identifying critical defects and security vulnerabilities early in the SDLC. In addition to its accurate and actionable analysis, the Synopsys Static Analysis solution is optimised for use in DevOps environments and CI/CD workflows, with strong integration support for a wide range of development tools.

Also Read

Stay in the know with our newsletter