Program analysis

TrustInSoft Mathematically Guarantees Zero Bug Vehicles with New Application Security Test

Retrieved on: 
Wednesday, June 9, 2021

The new Zero Bug AST leverages the TrustInSoft Analyzer to automate the power of Formal Methods testing, bringing the benefits to static and dynamic C/C++ source code analysis.

Key Points: 
  • The new Zero Bug AST leverages the TrustInSoft Analyzer to automate the power of Formal Methods testing, bringing the benefits to static and dynamic C/C++ source code analysis.
  • TrustInSoft Analyzer democratizes Formal Methods by making its advanced testing processes available to any developer at an affordable cost.
  • "Our new Zero Bug Application Security Test automates the power of Formal Methods for customers to save bug detection time by 40X, decrease code verification time by 4X, and avoid disastrous real world problems."
  • The TrustInSoft Analyzer is a hybrid static and dynamic code analyzer that automates Formal Methods to mathematically guarantee C/C++ code quality, security and safety.

AdaCore Broadens its Cybersecurity Capabilities with the Acquisition of Componolit GmbH

Retrieved on: 
Tuesday, February 16, 2021

AdaCore , a trusted provider of software development and verification tools, announces the acquisition of Componolit GmbH , effective as of February 1, 2021.

Key Points: 
  • AdaCore , a trusted provider of software development and verification tools, announces the acquisition of Componolit GmbH , effective as of February 1, 2021.
  • View the full release here: https://www.businesswire.com/news/home/20210216005666/en/
    Cyrille Comar, Co-founder and President of AdaCore Europe, and Alexander Senier, Founder and CEO of Componolit.
  • (Photo: Business Wire)
    The acquisition of Componolit will provide AdaCore with a further foothold to expand its growing market share in Germany where the requirement for high-assurance software is increasing rapidly.
  • Componolit technology will also bring new capabilities to AdaCore's suite of automated testing and static analysis tools.

Vector Partners with Axivion For Distribution of Static Code Analysis Tool

Retrieved on: 
Tuesday, November 17, 2020

Axivion is a manufacturer of innovative software solutions for static code analysis and protection against software erosion.

Key Points: 
  • Axivion is a manufacturer of innovative software solutions for static code analysis and protection against software erosion.
  • The Axivion Suite is a mature tool suite for automated static code analysis and architecture checks.
  • Especially for complex development projects with globally distributed design teams, Axivion Suite ensures the quality and long-term maintainability of the source code.
  • Axivion is ISO 9001 certified and has more than 150 customers with several thousand users in various industries worldwide.

ShiftLeft NextGen Static Analysis Now Available on GitHub Marketplace to Support Developer-Centric Security

Retrieved on: 
Tuesday, September 8, 2020

ShiftLeft, Inc. , the leader in application security (AppSec) for developers, today announced that its NextGen Static Analysis (NG SAST) product is now available on GitHub Marketplace .

Key Points: 
  • ShiftLeft, Inc. , the leader in application security (AppSec) for developers, today announced that its NextGen Static Analysis (NG SAST) product is now available on GitHub Marketplace .
  • Now available as a free GitHub App, NG SAST enables extremely fast and highly accurate code analysis to be easily integrated into developer workflows in just a few clicks.
  • In the modern software development lifecycle (SDLC) developers perform the majority of the application security work, not traditional AppSec teams.
  • Now that NG SAST is available through GitHub Marketplace, developers can make their own choices about which tools they adopt.

DHS Awards GrammaTech $3.5M to Modernize Open-Source Software Analysis Tools

Retrieved on: 
Thursday, September 27, 2018

The goal of the project is to modernize open-source static analysis tools, which are used by developers to detect cyber vulnerabilities in software systems.

Key Points: 
  • The goal of the project is to modernize open-source static analysis tools, which are used by developers to detect cyber vulnerabilities in software systems.
  • Develop real-world test cases using bug injection technology that make it easier to evaluate static analysis tools.
  • "GrammaTech's selection by DHS as the STAMP performer affirms our leadership in the field of static analysis," said Tim Teitelbaum, CEO of GrammaTech.
  • With both static and dynamic analysis tools that analyze source code as well as binary executables, GrammaTech continues to advance the science of superior software analysis, providing technology for developers to produce safer software.

SEI CERT Division Releases Downloadable Source Code Analysis Tool

Retrieved on: 
Wednesday, August 15, 2018

PITTSBURGH, Aug. 15, 2018 /PRNewswire/ -- The CERT Division of the Software Engineering Institute (SEI) at Carnegie Mellon University today announced the release of its Source Code Analysis Laboratory (SCALe) application .

Key Points: 
  • PITTSBURGH, Aug. 15, 2018 /PRNewswire/ -- The CERT Division of the Software Engineering Institute (SEI) at Carnegie Mellon University today announced the release of its Source Code Analysis Laboratory (SCALe) application .
  • The SCALeapplication can be used to identify source code flaws that may lead to vulnerabilities.
  • By using output from multipleflaw-finding static analysis tools,SCALe can be used to efficiently analyzemore code defects thanany singlestatic analysis tool would find.
  • It takes as input the source code for a program, plus output from static analysis tools (flaw-finding tools and code metrics tools) that were run on the code.