Here's what's new in Coverity on Polaris 2026.6.0.
Platform
- Coverity 2025.6.0 and 2025.6.2 are no longer supported.
- Support for Coverity 2025.9.0 is deprecated. It will be discontinued in a future release.
- Coverity on Polaris supports Coverity Versions:
- 2026.6.0 (recommended)
- 2026.3.0
- 2025.12.0
- 2025.9.0 (deprecated)
- Coverity on Polaris now supports Coverity 2026.6.0. See Coverity 2026.6.0: Supported Platforms, Languages, and Compilers. It includes the following changes:
- Sigma 2026.3.0 updates the Linux runtime version requirement to
glibc 2.28or newer for Sigma support on Linux x86_64 and Linux ARM64. - Added support for Java 26.
- Added support for Go 1.26.
- Removed support for Go 1.24.
- Added support for Scala 3.8 via the bundled Rapid Scan Static (Sigma) engine.
- Added support for Visual Studio 2026 capture.
- Removed support for FreeBSD 13.
- Deprecation notice: macOS 14 is deprecated as of 2026.6.0 and will be removed in a future release.
- Deprecation notice: Java 17 is deprecated as of 2026.6.0 and will be removed in a future release.
-
Important: KOTLIN CHECKER UPDATES
- Kotlin dataflow checkers are being migrated to the bundled Rapid Scan Static (Sigma) engine in 2026.6.0.
- Coverity on Polaris customers may see new Kotlin dataflow defects.
- Existing Coverity dataflow defects may disappear, and triage history may be lost.
- Those defects will be reported as new defects and will need to be re-triaged.
- Checker Information:
- Improved documentation and CWE mapping for the
URL_MANIPULATIONchecker. - Removed interdependence between the
SQLIandSQL_NOT_CONSTANTcheckers to address customer false negatives. - Added Spring Framework modernization updates for Java analysis.
- Coverity on Polaris 2026.6.0 includes cumulative Sigma-derived content from 2026.3.0, 2026.4.0, and 2026.4.1:
- Added detection for hardcoded keystore and truststore passwords in Spring Integration. Sigma's existing generic secret detection continues to identify hardcoded passwords, bearer tokens, and API keys across Spring Security, Spring Boot Actuator, and various platforms including Twitch, Coinbase, OpenSea, Huawei, Hunter, and IBM.
- New check
broad_domain_attribute_cookie_core_scala_http4s_response_cookieadded for Scala. - New check
broad_domain_attribute_cookie_dotnet_core_netadded for CSharp. - New check
broad_domain_attribute_cookie_play_configadded for Scala. - New check
broad_domain_attribute_cookie_play_mvcadded for Scala. - New check
certificate_verification_disabled_crypto_sshadded for Go. - New check
certificate_verification_disabled_crypto_tlsadded for Go. - New check
cors_with_credentials_null_origin_result_playadded for Scala. - New check
csrf_protection_disabled_beegoadded for Go. - New check
csrf_protection_disabled_beego_configadded for Go. - New check
excessive_session_lifetime_beegoadded for Go. - New check
excessive_session_lifetime_beego_configadded for Go. - New check
excessive_session_lifetime_ginadded for Go. - New check
excessive_session_lifetime_gorillaadded for Go. - New check
hardcoded_credentials_core_kotlinadded for Kotlin. - New check
header_injection_core_kotlinadded for Kotlin. - New check
implicit_intent_core_kotlinadded for Kotlin. - New check
insecure_file_permission_core_go_osadded for Go. - New check
missing_httponly_attribute_core_scala_http4s_response_cookieadded for Scala. - New check
missing_httponly_attribute_dotnet_core_netadded for CSharp. - New check
missing_httponly_attribute_play_configadded for Scala. - New check
missing_httponly_attribute_play_mvcadded for Scala. - New check
missing_permission_check_androidadded for Kotlin. - New check
missing_samesite_attribute_core_scala_http4s_response_cookieadded for Scala. - New check
missing_secure_attribute_core_scala_http4s_response_cookieadded for Scala. - New check
missing_secure_attribute_dotnet_core_netadded for CSharp. - New check
missing_secure_attribute_play_configadded for Scala. - New check
missing_secure_attribute_play_mvcadded for Scala. - New check
missing_tls_moleculer_transporteradded for JavaScript, TypeScript. - New check
missing_tls_slick_play_database_configadded for Scala. - New check
os_cmd_injection_core_kotlinadded for Kotlin. - New check
path_manipulation_core_kotlinadded for Kotlin. - New check
persistent_cookie_dotnet_core_netadded for CSharp. - New check
regex_injection_core_kotlinadded for Kotlin. - New check
root_path_attribute_cookie_core_scala_http4s_response_cookieadded for Scala. - New check
root_path_attribute_cookie_dotnet_core_netadded for CSharp. - New check
root_path_attribute_cookie_play_configadded for Scala. - New check
root_path_attribute_cookie_play_mvcadded for Scala. - New check
script_code_injection_core_kotlinadded for Kotlin. - New check
sensitive_data_leak_core_kotlinadded for Kotlin. - New check
sqli_core_kotlinadded for Kotlin. - New check
unencrypted_sensitive_data_core_kotlinadded for Kotlin. - New check
unrestricted_access_to_file_core_kotlinadded for Kotlin. - New check
unsafe_deserialization_core_kotlinadded for Kotlin. - New check
unsafe_functionality_unsafeadded for Go. - New check
unsafe_jni_core_kotlinadded for Kotlin. - New check
url_manipulation_core_kotlinadded for Kotlin. - New check
xpath_injection_core_kotlinadded for Kotlin. - New hardcoded secrets pattern
Consumer Key (generic)added. - New hardcoded secrets pattern
GitGuardian Personal Access Tokenadded. - New hardcoded secrets pattern
GitGuardian Service Account Tokenadded. - New hardcoded secrets pattern
GitHub Keyadded. - New hardcoded secrets pattern
Github Personal Access Tokenadded. - New hardcoded secrets pattern
GoCardless API Keyadded. - New hardcoded secrets pattern
Google API Keyadded. - New hardcoded secrets pattern
Heroku OAuth Access Tokenadded. - New hardcoded secrets pattern
HubSpot Private App Tokenadded. - New hardcoded secrets pattern
Token in keyadded. - Added Perplexity API key and updated Secret key hardcoded secret patterns enabling Sigma to detect hardcoded API keys from major LLM providers including OpenAI, Anthropic, Perplexity AI, and Gemini. This enhancement significantly improves Sigma's ability to identify exposed credentials for AI services, helping teams prevent unauthorized access to their LLM accounts.
- Modified existing Java check
missing_tls_spring_boot_couchbaseto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_boot_datasourceto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_boot_flywayto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_boot_influxto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_boot_neo4jto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_boot_r2dbcto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_data_mongodbto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_data_r2dbcto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_datasourceto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_httpto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_http_clientto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_http_client_reactiveto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_r2dbc_connectionto support Kotlin, Scala. - Modified existing Java check
missing_tls_spring_reactive_websocketto support Kotlin, Scala. - New check
missing_tls_spring_boot_elasticsearchadded for Java, Kotlin, Scala. - New check
missing_tls_spring_security_oauthadded for Java, Kotlin, Scala. - New check
basic_auth_enabled_ginadded for Go. - New check
broad_domain_attribute_play_configadded for Scala. - New check
cors_no_credentials_permissive_origin_result_play_configadded for Scala. - New check
cors_with_credentials_http_origin_result_play_configadded for Scala. - New check
jwt_no_claims_validation_core_goadded for Go. - New check
missing_tls_apache_commons_ioadded for Java, Kotlin, Scala. - New check
missing_tls_apache_datasourceadded for Java, Kotlin, Scala. - Modified existing Java, Scala check
missing_tls_apache_httpto support Kotlin. - New check
missing_tls_core_java_sqladded for Java, Kotlin. - New check
missing_tls_jackson_coreadded for Java, Kotlin, Scala. - New check
missing_tls_jackson_objectmapperadded for Java, Kotlin, Scala. - New check
missing_tls_jackson_objectreaderadded for Java, Kotlin, Scala. - Modified existing Java check
missing_tls_spring_resttemplateto support Kotlin. - New check
missing_tls_datastax_driveradded for Java, Kotlin, Scala. - New check
missing_tls_dom4j_ioadded for Java, Kotlin, Scala. - New check
missing_tls_dom4j_jaxbadded for Java, Kotlin, Scala. - New check
missing_tls_guava_resourcesadded for Java, Kotlin, Scala. - New check
missing_tls_mongodbadded for Java, Kotlin, Scala. - New check
missing_tls_vertxadded for Java, Kotlin, Scala. - New check
sensitive_data_leak_java_grpcadded for Java. - New check
signature_verification_disabled_maven_wrapperadded for Properties. - New hardcoded secrets pattern
Generic Application Keyadded. - New hardcoded secrets pattern
Spring OAuth2 Password Grant Requestadded. - New hardcoded secrets pattern
Spring OAuth2 Token Introspectoradded. - New hardcoded secrets pattern
Spring Security Refresh Tokenadded. - New hardcoded secrets pattern
Spring Security Tokenadded. - Modified existing Java check
certificate_verification_disabled_core_javato support Kotlin. - Removed the
certificate_verification_disabled_androidcheck which is duplicated by the existingcertificate_verification_disabled_core_javacheck. - Modified existing Java check
debug_logging_enabled_reactor_nettyto support Scala. - Modified existing Java check
file_upload_misconfiguration_of_fields_servletto support Scala. - Modified existing Java check
file_upload_misconfiguration_of_filesize_servletto support Scala. - New check
broad_filesystem_access_dropwizard_setupadded for Scala. - New check
missing_tls_java_grpc_insecureadded for Java. - New check
missing_tls_play_wsadded for Scala. - New check
missing_tls_result_playadded for Scala. - New hardcoded secrets pattern
AWS IAM Passwordadded. - New hardcoded secrets pattern
Basic Auth Credentials Springframeworkadded. - New hardcoded secrets pattern
Hardcoded IP Addressadded. - New hardcoded secrets pattern
Java Security PKCS8/X509 Encoded Keyadded. - New hardcoded secrets pattern
Javax Context Propertiesadded. - New hardcoded secrets pattern
Javax Crypto DES Keyadded. - New hardcoded secrets pattern
Spring RSA Crypto Saltadded. - New hardcoded secrets pattern
Spring Security Crypto Passwordadded. - New hardcoded secrets pattern
Spring Security RSocket Metadata Passwordadded. - New hardcoded secrets pattern
Spring Security Remember me Keyadded.
- Improved documentation and CWE mapping for the
- Sigma 2026.3.0 updates the Linux runtime version requirement to
- Bug Fix: No known issues at this time.
- Known issues: No known issues at this time.
CLI
- The following versions of the Coverity on Polaris CLI Scan Client are supported in this release:
- 2026.6.0 (recommended)
- 2026.3.0
- 2025.12.0
- 2025.9.0 (deprecated)