The version of Coverity used for static analysis can be modified at the organization, application, project, and branch level. To change an application's Coverity version, follow these steps:
Note: Only Organization Administrators, Organization Application Managers, and other users with permissions to manage application settings can complete these steps.
- Go to Portfolio and open an application.
- Go to .
- Under SAST Analysis, select Edit.
- Select the appropriate Coverity version, as required.
- To use the latest supported version of Coverity, select Automatically use latest version (recommended).
Selecting this option ensures that the application always uses the most recent supported version of Coverity. When a new version of Coverity is available, the application will automatically use it for SAST tests.
- To use a specific version of Coverity, select Use a specific tool version, and select the appropriate version from the dropdown.
Important: Here, you can select the latest supported version of Coverity, or a deprecated one. When you choose a specific version of Coverity, the version assigned to the application will not change when a new version of Coverity is added to Polaris, even if support for the version you selected is removed. When support for a version of Coverity ends, SAST tests that attempt to use the unsupported version will not run. To resume testing, you must activate a supported version of Coverity.
When you choose to use a specific Coverity version (including the recommended version), the corresponding version of Rapid Scan Static (Sigma) is locked, and won't change when newer Sigma versions are available.
- To use the latest supported version of Coverity, select Automatically use latest version (recommended).
- Select Save.
Important: After you change an application's Coverity version, a full SAST test must be performed on at least one branch in affected projects before rapid SAST tests can run.