Rapid Scan Static is one of the engines that Code Sight can run to perform static application security testing (SAST; also known as static analysis).

Compared to Coverity Analysis, Rapid Scan Static is meant to be fast and easy to use.

Rapid Scan Static is an ideal solution for rapidly evolving projects, for cloud adopters, and for those who are just starting their application security journey and need to assess their code without a major investment of time and resources.

Rapid Scan Static uses the Sigma engine, which has its own set of checkers to report actionable results that developers can fix right away, at their desktop. It does not generate reports or evaluate compliance with standards such as MISRA. You can find a thorough description in the Sigma User Guide.

This engine can scan not only source code, but its accompanying text-based metadata. See the Code Sight support matrix for details.

Rapid SAST scans are strictly local: Rapid Scan Static does not rely on communication with a centralized server.