Black Duck Integrates AI Capabilities into Coverity: A Major Update in Application Security Testing
In a significant development for application security testing, Black Duck has unveiled AI-driven features in Coverity, its well-established static application security testing tool. This new integration, marking the first instance of artificial intelligence features being incorporated into the two-decade-old product, aims to tackle some of the persistent challenges in application security, particularly the notoriously high rate of false positives associated with C and C++ code analysis. Furthermore, the update introduces compliance features that align with the upcoming regulatory requirements set forth by the European Union.
At the heart of this exciting update is an innovative AI-assisted issue triage system. Designed specifically to mitigate false positives in C and C++ findings, this new feature enhances the overall accuracy of triage across all languages supported by Coverity. What sets this approach apart is Black Duck’s emphasis on customer autonomy; organizations can execute these AI features using their preferred large language models, steering clear of reliance on vendor-hosted services. This is particularly beneficial for organizations operating in regulated industries or those with stringent data governance policies that prevent the transmission of sensitive code to external services.
This launch also includes the introduction of a Model Context Protocol server, enabling AI coding agents to trigger localized Coverity scans. This advancement facilitates the retrieval of security and quality findings directly within the organization’s workflow, enhancing efficiency. Rather than solely depending on probabilistic judgments about code safety, agentic tools can now act on deterministic, reproducible scan outputs. This enhancement serves to empower developers and security professionals, streamlining the process of identifying and remediating vulnerabilities.
Moreover, the release addresses a common class of vulnerabilities by introducing AI-powered detection of Insecure Direct Object Reference (IDOR) flaws, specifically in JavaScript and TypeScript codebases. IDOR vulnerabilities often appear in API-related security breaches, where applications expose internal identifiers without appropriate authorization checks. The proactive identification of such vulnerabilities is essential for safeguarding against potential exploitation.
With the reporting deadlines under the EU Cyber Resilience Act looming, Black Duck has rolled out two compliance-focused features in this update. The Security Impact Lens is designed to allow users to sort and filter findings based on their security priority. By applying the same prioritization approach that Coverity has historically utilized for code quality issues, this feature empowers organizations to streamline their security triage processes effectively.
Additionally, a CRA-aligned checker option is included, mapping scan results directly to the vulnerability management and cybersecurity obligations outlined in the new regulation. This feature is particularly relevant for organizations seeking to ensure compliance as legislative scrutiny around cybersecurity grows.
The update further extends language support to encompass Rust 1.92, which reflects the growing adoption and importance of this programming language in contemporary software development. Along with language support enhancements, users will benefit from a redesigned user interface that boasts improved navigation and issue filtering capabilities. This modernization aims to make the overall user experience more intuitive and efficient for teams tasked with managing security in their codebases.
All new capabilities are now available to existing Coverity customers without necessitating any changes to the product’s deterministic and auditable scanning foundation. Organizations can enjoy immediate access to these AI-powered features, bolstered by comprehensive implementation guidance housed within the Coverity Documentation Portal. As security and development teams evaluate how the AI triage capabilities may alleviate manual review burdens, they must also assess whether the CRA-aligned features sufficiently address their specific regulatory compliance needs.
In summary, Black Duck’s integration of AI features into Coverity represents a formidable step toward enhancing application security testing. By addressing long-standing challenges associated with false positives and aligning with impending regulatory requirements, this update positions Coverity as a more robust and agile tool in the face of today’s evolving threat landscape.

