PVS-Studio, originally developed as a universal tool for finding errors in software code, is now gradually focusing on ensuring safety and security of applications, identifying potential zero-day vulnerabilities. This was facilitated by the support of CERT and MISRA standards, the classification of analyzer warnings in accordance with the CWE standard, the development of data flow analysis mechanisms for tainted data checking, and so on.

On August 6, 2020, Forrester Research released a study called “Now Tech: Static Application Security Testing, Q3 2020”, which included the PVS-Studio analyzer as a SAST-specialized solution. Forrester is one of the leading researchers of the impact of new and innovative technologies on business processes and the market, so the inclusion of PVS-Studio in this study is a decent confirmation (both for our users and for us) of the relevance of this direction in which our product is developing. The research report is available for purchase to subscribers and customers of Forrester Research.

#security #devops #programming #devsecops #pvs-studio #static code analysis #sast #cve #forrester research

PVS-Studio Code Analyzer as A Tool for Finding Security Defects
1.15 GEEK