[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"article-black-duck-coverity-ai-era-triage-en":3,"article-related-black-duck-coverity-ai-era-triage-en":32,"series-industry-159e13cc-8932-4ae4-a9b5-cf99b63e3e89":77},{"id":4,"slug":5,"title":6,"content":7,"summary":8,"source":9,"source_url":10,"author":11,"image_url":12,"cover_image":12,"category":13,"language":14,"translated_content":11,"related_article_id":15,"keywords":16,"key_takeaways":25,"views":29,"created_at":30,"published_at":31,"topic_cluster_id":11},"159e13cc-8932-4ae4-a9b5-cf99b63e3e89","black-duck-coverity-ai-era-triage-en","Black Duck’s Coverity gets better at AI-era triage","\u003Cp>What changed in Black Duck Coverity, and which update matters most for your DevSecOps team?\u003C\u002Fp>\u003Cp data-speakable=\"summary\">Black Duck updated Coverity with AI-linked scanning, faster triage, and broader language coverage.\u003C\u002Fp>\u003Ctable>\u003Cthead>\u003Ctr>\u003Cth>Item\u003C\u002Fth>\u003Cth>What it adds\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd>MCP server\u003C\u002Ftd>\u003Ctd>Lets AI coding agents run local Coverity scans\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Security impact lens\u003C\u002Ftd>\u003Ctd>Sorts issues by security priority for compliance work\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>IDOR checker\u003C\u002Ftd>\u003Ctd>Finds insecure direct object reference flaws in JavaScript and TypeScript\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>AI-assisted triage\u003C\u002Ftd>\u003Ctd>Helps cut false-positive noise in C and C++ scans\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Rust support\u003C\u002Ftd>\u003Ctd>Adds support for Rust 1.92\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>1. MCP server for AI coding agents\u003C\u002Fh2>\u003Cp>Black Duck’s \u003Ca href=\"https:\u002F\u002Fwww.blackduck.com\u002F\">Black Duck\u003C\u002Fa> added a \u003Ca href=\"\u002Ftag\u002Fmodel-context-protocol\">Model Context Protocol\u003C\u002Fa> server to \u003Ca href=\"https:\u002F\u002Fwww.blackduck.com\u002Fproducts\u002Fcoverity.html\">Coverity\u003C\u002Fa>, letting \u003Ca href=\"\u002Ftag\u002Fai-coding-agents\">AI coding agents\u003C\u002Fa> trigger local security and code-quality scans inside the development flow. The practical value is simple: the scan happens where the code is being written, so developers get feedback before the change spreads farther.\u003C\u002Fp>\n\u003Cfigure class=\"my-6\">\u003Cimg src=\"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1785371565151-tk2v.png\" alt=\"Black Duck’s Coverity gets better at AI-era triage\" class=\"rounded-xl w-full\" loading=\"lazy\" \u002F>\u003C\u002Ffigure>\n\u003Cp>The company says the integration can work with the large language model a team already prefers, which matters for groups standardizing on different AI tools. That makes the feature less about a single assistant and more about wiring Coverity into the AI workflow teams already use.\u003C\u002Fp>\u003Cul>\u003Cli>Local scans from AI agents\u003C\u002Fli>\u003Cli>Security and quality findings in context\u003C\u002Fli>\u003Cli>Model choice is not locked to one vendor\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>2. Security impact lens for compliance sorting\u003C\u002Fh2>\u003Cp>Coverity now includes a security impact lens that helps teams sort and filter issues by priority. In the article’s example, that is meant to make it easier to align with compliance demands such as the European Union’s Cyber Resilience Act, which can require faster reporting and tighter issue handling.\u003C\u002Fp>\u003Cp>This is less about finding more bugs and more about deciding which bugs deserve attention first. For teams buried under scan output, that distinction can save time and reduce the chance that a high-risk issue sits in the queue behind lower-value noise.\u003C\u002Fp>\u003Cul>\u003Cli>Filter by security priority\u003C\u002Fli>\u003Cli>Support for compliance-driven triage\u003C\u002Fli>\u003Cli>Useful when issue volume is high\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>3. IDOR checker for JavaScript and TypeScript\u003C\u002Fh2>\u003Cp>Black Duck also added a checker for Insecure Direct Object Reference, or IDOR, vulnerabilities in JavaScript and \u003Ca href=\"\u002Ftag\u002Ftypescript\">TypeScript\u003C\u002Fa> code. IDOR flaws are a common application security problem because they can expose data or actions that should have stayed behind access controls.\u003C\u002Fp>\n\u003Cfigure class=\"my-6\">\u003Cimg src=\"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1785371565564-5t2g.png\" alt=\"Black Duck’s Coverity gets better at AI-era triage\" class=\"rounded-xl w-full\" loading=\"lazy\" \u002F>\u003C\u002Ffigure>\n\u003Cp>For teams shipping web apps, this is a focused addition rather than a broad platform change. It targets a specific weakness in two widely used languages, which can help security teams catch a class of issue that often slips through general-purpose review.\u003C\u002Fp>\u003Cul>\u003Cli>Targets JavaScript\u003C\u002Fli>\u003Cli>Targets TypeScript\u003C\u002Fli>\u003Cli>Finds IDOR-specific flaws\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>4. AI-assisted triage for C and C++ scans\u003C\u002Fh2>\u003Cp>Coverity now includes AI-assisted issue triage tuned for C and C++ scans, where false positives can pile up quickly. That matters because teams often spend too much time sorting alerts before they can fix the code that actually needs attention.\u003C\u002Fp>\u003Cp>The update is meant to speed up review, not replace it. In practice, the value is in reducing the manual work of separating likely real defects from findings that look urgent but are not worth immediate action.\u003C\u002Fp>\u003Ccode>Use case: prioritize true defects faster\nBest fit: C\u002FC++ codebases with noisy scan output\nGoal: reduce time spent on false positives\u003C\u002Fcode>\u003Ch2>5. Rust 1.92 support\u003C\u002Fh2>\u003Cp>Black Duck also added support for \u003Ca href=\"\u002Ftag\u002Frust\">Rust\u003C\u002Fa> 1.92, which extends Coverity’s reach into a language that continues to gain ground in security-sensitive development. For teams using Rust in production, version support matters because static analysis tools need to keep pace with the compiler and language features developers actually ship.\u003C\u002Fp>\u003Cp>This update is the least flashy of the group, but it is often the one that decides whether a tool stays in the build pipeline. If your codebase includes Rust, version compatibility is not a nice-to-have, it is what keeps scanning from breaking when the toolchain moves forward.\u003C\u002Fp>\u003Cul>\u003Cli>Rust 1.92 compatibility\u003C\u002Fli>\u003Cli>Useful for mixed-language codebases\u003C\u002Fli>\u003Cli>Helps keep scanning current with the toolchain\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>How to decide\u003C\u002Fh2>\u003Cp>If your team is already using \u003Ca href=\"\u002Ftag\u002Fai-coding\">AI coding\u003C\u002Fa> agents, the MCP server is the most direct upgrade because it puts scans inside the workflow. If your main pain is backlog management, the security impact lens and AI-assisted triage will matter more, since both focus on ranking and reducing noise.\u003C\u002Fp>\u003Cp>Teams building in JavaScript, TypeScript, C, C++, or Rust should look at the language-specific additions first. The best fit depends on whether your bottleneck is AI integration, compliance sorting, false positives, or language coverage.\u003C\u002Fp>","5 Coverity updates help teams scan AI code, rank risk faster, and catch more flaws, including Rust 1.92 and IDOR checks.","devops.com","https:\u002F\u002Fdevops.com\u002Fblack-duck-extends-scope-and-reach-of-code-scanning-tool\u002F",null,"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1785371565151-tk2v.png","industry","en","426b9a43-e4a1-4d1f-9386-540db4df1f70",[17,18,19,20,21,22,23,24],"Black Duck","Coverity","DevSecOps","static analysis","AI coding agents","MCP","IDOR","Rust 1.92",[26,27,28],"Coverity now plugs AI coding agents into local scans through an MCP server.","The new security impact lens helps teams sort issues for compliance and triage.","Black Duck added IDOR detection for JavaScript and TypeScript plus Rust 1.92 support.",1,"2026-07-30T00:32:20.980792+00:00","2026-07-30T00:32:20.97+00:00",{"tags":33,"relatedLang":36,"relatedPosts":40},[34],{"name":21,"slug":35},"ai-coding-agents",{"id":15,"slug":37,"title":38,"language":39},"black-duck-coverity-ai-era-triage-zh","Coverity 5 項更新，AI 時代更好分流風險","zh",[41,47,53,59,65,71],{"id":42,"slug":43,"title":44,"cover_image":45,"image_url":45,"created_at":46,"category":13},"641c6e1d-19fb-4d51-8b87-cd2722aff9f0","huang-open-letter-open-weight-ai-playbook-en","Huang’s open-letter playbook for open-weight AI","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1785378794497-8tsz.png","2026-07-30T02:32:50.034947+00:00",{"id":48,"slug":49,"title":50,"cover_image":51,"image_url":51,"created_at":52,"category":13},"ede3349c-e12d-4c2e-a32e-bcf826f2d941","32-firms-back-open-weight-ai-dc-letter-en","32 firms back open-weight AI in DC letter","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1785376973124-2q0q.png","2026-07-30T02:02:24.643723+00:00",{"id":54,"slug":55,"title":56,"cover_image":57,"image_url":57,"created_at":58,"category":13},"ebec2cf3-cdf6-4be2-9142-1f6ca364cb1e","huang-primo-post-x-difende-ia-aperta-en","Huang usa il suo primo post su X per difendere l’IA aperta","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1785375179161-8he1.png","2026-07-30T01:32:36.158612+00:00",{"id":60,"slug":61,"title":62,"cover_image":63,"image_url":63,"created_at":64,"category":13},"1c981f4c-0ebe-452a-a696-c00d6de563bf","anthropic-opus-5-cheaper-ai-race-en","Anthropic’s Opus 5 makes the AI race cheaper","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1785369763641-46lq.png","2026-07-30T00:02:20.31072+00:00",{"id":66,"slug":67,"title":68,"cover_image":69,"image_url":69,"created_at":70,"category":13},"7b06e05b-02b0-4a5c-8d0b-6adce1bee281","openai-distillation-playbook-kimi-panic-en","OpenAI’s distillation playbook explains the Kimi panic","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1785348176697-vqa2.png","2026-07-29T18:02:31.600923+00:00",{"id":72,"slug":73,"title":74,"cover_image":75,"image_url":75,"created_at":76,"category":13},"9a24e175-fbd2-4cbb-bd1b-f24603e8cd49","gemini-35-flash-lets-you-buy-speed-en","Gemini 3.5 Flash lets you buy speed","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1785312220271-ijow.png","2026-07-29T08:03:14.408404+00:00",[78,83,88,93,98,103,108,113,118,123],{"id":79,"slug":80,"title":81,"created_at":82},"d35a1bd9-e709-412e-a2df-392df1dc572a","ai-impact-2026-developments-market-en","AI's Impact in 2026: Key Developments and Market Shifts","2026-03-25T16:20:33.205823+00:00",{"id":84,"slug":85,"title":86,"created_at":87},"5ed27921-5fd6-492e-8c59-78393bf37710","trumps-ai-legislative-framework-en","Trump's AI Legislative Framework: What's Inside?","2026-03-25T16:22:20.005325+00:00",{"id":89,"slug":90,"title":91,"created_at":92},"e454a642-f03c-4794-b185-5f651aebbaca","nvidia-gtc-2026-key-highlights-innovations-en","NVIDIA GTC 2026: Key Highlights and Innovations","2026-03-25T16:22:47.882615+00:00",{"id":94,"slug":95,"title":96,"created_at":97},"0ebb5b16-774a-4922-945d-5f2ce1df5a6d","claude-usage-diversifies-learning-curves-en","Claude Usage Diversifies, Learning Curves Emerge","2026-03-25T16:25:50.770376+00:00",{"id":99,"slug":100,"title":101,"created_at":102},"69934e86-2fc5-4280-8223-7b917a48ace8","openclaw-ai-commoditization-concerns-en","OpenClaw's Rise Raises Concerns of AI Model Commoditization","2026-03-25T16:26:30.582047+00:00",{"id":104,"slug":105,"title":106,"created_at":107},"b4b2575b-2ac8-46b2-b90e-ab1d7c060797","google-gemini-ai-rollout-2026-en","Google's Gemini AI Rollout Extended to 2026","2026-03-25T16:28:14.808842+00:00",{"id":109,"slug":110,"title":111,"created_at":112},"6e18bc65-42ae-4ad0-b564-67d7f66b979e","meta-llama4-fabricated-results-scandal-en","Meta's Llama 4 Scandal: Fabricated AI Test Results Unveiled","2026-03-25T16:29:15.482836+00:00",{"id":114,"slug":115,"title":116,"created_at":117},"bf888e9d-08be-4f47-996c-7b24b5ab3500","accenture-mistral-ai-deployment-en","Accenture and Mistral AI Team Up for AI Deployment","2026-03-25T16:31:01.894655+00:00",{"id":119,"slug":120,"title":121,"created_at":122},"5382b536-fad2-49c6-ac85-9eb2bae49f35","mistral-ai-high-stakes-2026-en","Mistral AI: Facing High Stakes in 2026","2026-03-25T16:31:39.941974+00:00",{"id":124,"slug":125,"title":126,"created_at":127},"9da3d2d6-b669-4971-ba1d-17fdb3548ed5","cursors-meteoric-rise-pressures-en","Cursor's Meteoric Rise Faces Industry Pressures","2026-03-25T16:32:21.899217+00:00"]