"80 to 90 percent of bugs found by previous static analysis tools we used were false positives, but results produced by Coverity Static Analysis are very accurate. It is much easier to plan our development cycles now."
"ScanIP was a huge help as it was a tool that allowed us not only to visualize our bench top sample results but also to extract quantitative data that would have otherwise been impossible to investigate."
"Identify is invaluable because of the great visibility it provides into bugs that we can trace back to either hardware or software, quickly identifying the source without data buffer overload.”
"We have chosen to off-load a lot of the work associated with doing scans to Synopsys. They’re the experts, and it works for our current business model. That is a very company specific decision. Every company has their own list of requirements."
"It is very important to understand each team’s skills and take a down-to-earth approach. For example, sales and those who are not acquainted with software may not even understand what open source is, so it has to be explained. It is also very important not to just end up emphasizing risks, because that can discourage the use of OSS. While developer support is essential, if you can also involve marketing, sales, and call center agents in training activities, you can propel OSS governance."
"Even once we had an official policy in place, it was clear that we needed to bring all stakeholders on board with the importance of OSS license compliance in software development."
"Both security and license compliance were equally important in our selection of Black Duck."
"Black Duck was the only solution that provided everything we wanted. Black Duck analysis speeds are very fast, and vulnerability information is distributed quickly."
"We wanted to understand the code better. If there were any potential issues with open source we wanted to identify those issues up front."
"Black Duck met Entersekt’s checklist of what we needed in an open source vulnerability management solution better than any other vendor."
"Having a tool that lets us look at our code and look at what issues could be introduced enables us to be a lot more informed and have a higher degree of confidence that when we release software we’re not introducing additional risks."
"Coverity is a cornerstone in building secure C code as part of our security development lifecycle."
“We use open source software in nearly everything we do because it helps us produce higherquality software, better and faster.”
"We selected Black Duck for three reasons: for reputation, ease of use, and confidence in the results."
"Properly executed fuzzing techniques can provide a low-cost, efficient means of finding vulnerabilities, covering more code paths and value iterations than a manual analysis can perform in a short period of time."