Basic Information
Tool first release date
Version release date
Software cost
Software license
MIT License
Supported operating systems
FreeBSD, macOS, Linux, NetBSD, Solaris, Windows, POSIX
Process Integration
Deployment model
Workstation, CI Server, Standalone Server
Analysis inputs
Source code
Display results in IDE
Pre-commit invocation from workstation
CI Integration
Generic command line interface (CLI)
Able to analyze incremental changes to code (commit, patch, pull request)
Can schedule scans
API method to report results in SARIF format
API method to report results in XML/JSON/CSV format
Supported programming languages
Claimed Weakness Coverage
Claimed Weakness Coverage information hasn't been collected yet for this analyzer.
Really want it? Let us know.
Checker Customization
Can disable checkers
Can customize checker logic
First-class API to create new checkers
Speed & Scalability
Parallelizes on one host
Results Quality
Provides explanation of warning
Provides severity of warning
Provides confidence information about warning
Provides code context around warning
Provides control flow context for warning
Provides data flow context for warning
Provides code coverage information per checker
Results suppression even after code changes
Show differences in results set to previous scan
Two-way data sync with external remediation bug tracker
Graphical user interface (GUI)
Centralized reporting
Installation guide or documentation
User/operator guide or documentation
Integration guide or API documentation
Open source project health
Currently mainly in maintenance mode, but we occasionally integrate new features through pull requests.