In Black Duck® Code Sight™, Static Application Security Testing (SAST) is provided by both the Rapid Scan Static and Coverity Analysis products. Static-analysis issues are tracked by a server, which can be either a Coverity Connect server or a Coverity on Polaris server.
This section describes how to set up Coverity Analysis, how static analysis works, and how to view issues.
Note:
Code Sight can also display SAST issues that have been detected by Coverity remotely, or by
Polaris running on a remote server.