Coverity on Polaris 2025.12.0 Release Notes

Coverity on Polaris

Version
latest
Here's what's new in Coverity on Polaris 2025.12.0.

Platform

  • Coverity 2024.12.0 is no longer supported.
  • Support for Coverity 2025.3.0 and 2024.9.1 are deprecated. They will be discontinued in a future release.
  • Coverity on Polaris supports Coverity Versions:
    • Coverity 2025.12.0 (recommended)
    • Coverity 2025.9.0
    • Coverity 2025.6.2
    • Coverity 2025.6.0
    • Coverity 2025.3.0 (deprecated)
    • Coverity 2024.9.1 (deprecated)
  • Coverity on Polaris now supports Coverity 2025.12.0. See Coverity 2025.12.0: Supported Platforms, Languages, and Compilers. It includes the following changes:
    • Added support for macOS 26.
    • Added support for Go 1.25.
    • Added support for Java 25.
    • Added support for Kotlin 2.2.
    • Added support for Scala.
    • Added support for GNU GCC 15.2.
    • Added support for Xcode 26.
    • Added support for Oracle JDK 25 and Open JDK 25
    • Support for macOS on Intel (macosx) is deprecated and will be removed in the 2026.12.0 release.
    • Support for Go 1.24 is deprecated and will be removed in a future release.
    • Support for JavaScript/TypeScript quality checkers are deprecated and will be removed in a future release.
    • Support for Go quality checkers are deprecated and will be removed in a future release.
    • Support for Python quality checkers are deprecated and will be removed in a future release.
    • Support for Kotlin quality checkers are deprecated and will be removed in a future release.
    • Support for Bazel 6 is deprecated and will be removed in a future release.
    • Support for Xcode 12.x-14.x is deprecated and will be removed in a future release.
    • Support for SpotBugs is deprecated and will be removed in a future release.
    • Support for Detekt is deprecated and will be removed in a future release.
    • Support for macOS 13 was removed.
    • Support for Windows 10 was removed.
    • Support for Go 1.23 was removed.
    • Support for Open JDK 24 and Oracle JDK 24 was removed.
    • Support for Swift is now autocapture only via Rapid Scan Static (Sigma) engine.
    • Checker Information:
      • Added support for xtensa 2023.11 on Linux.

      • Added support for xtensa 2024.4 on Linux.

      • Added support for xtensa 2025.5 on Linux.

      • The TAINTED_SCALAR checker now offers the propagate_taint_on_rshift option.

      • Added a new C/C++ checker, HARDCODED_SECRETS, which finds cases where a secret, such as a password, cryptographic key, or token is stored in plaintext directly in the source code. This checker is disabled by default.

      • Improved the WRAPPER_ESCAPE checker to avoid reporting false positives when a pointer cannot be stored in a global variable in a call to a function because parameters prevents it.

      • The SSRF checker now supports C# and VB.

      • The integrated version of PMD has been updated from 7.4.0 to 7.17.0 [Apex].

      • Brakeman Pro for Ruby on Rails security analysis has been upgraded to version 7.1.0

      • Fixed a false positive for the UNLOGGED_SECURITY_EXCEPTION checker. [C#]

      • Fixed a false positive for the RISKY_CRYPTO checker. [C#]

      • The HARDCODED_SECRET checker now find instances where a password string is compared against hard-coded passwords.

    • Bug Fix: An inconsistency in results of issue when filtering by issue kind was identified as caused by issues being categorized as both quality and security. The fix is to categorize these types of issues as issue kind security.
    • Known issues:No known issues at this time.

CLI

  • The following versions of the Coverity on Polaris CLI Scan Client are supported in this release:
    • 2025.12.0 (recommended)
    • 2025.9.0
    • 2025.6.0
    • 2025.3.0 (deprecated)
    • 2024.9.2 (deprecated)