About

Coverity Scan is a static analysis service for registered open source projects. It analyzes submitted builds and source code to find defects and vulnerabilities across Java, C/C++, C#, JavaScript, Ruby, and Python projects, then presents the results for developer triage and remediation.

The service is intended for open source maintainers and uses a responsible-disclosure workflow: detailed findings are generally visible only to approved project members until issues are resolved. Build submissions are limited by project size, with up to 28 builds per week for projects under 100K lines of code, 21 for 100K to 500K lines, 14 for 500K to 1 million lines, and 7 for projects above 1 million lines.

  • Static analysis for open source code
  • Java, C/C++, C#, JavaScript, Ruby, Python
  • Responsible disclosure workflow
  • Up to 28 builds per week
  • Project-size-based build limits
  • GitHub and Travis CI integration

Free Tier Value

48
FTV score
Est. value$8.00 / month
Credit cardRequired
Feature parity78%

This free tier is genuinely usable for open source projects: it includes analysis results at no charge, downloadable submission software, and ongoing access after approval, but it is capped by project size and weekly build limits. With no paid self-serve plan shown on the page, the practical value is best estimated as a modest but real monthly allowance worth about $8, reflecting a strong free offering with approval gating and submission quotas rather than an uncapped service.

What's included in the free tier

  • Access to analysis results for registered open source projects at no charge.
  • Project registration and access to registered projects after approval by the project owner or Scan administrator.
  • Download of the software needed to submit a build for analysis after project registration.
  • Build submission limits of up to 28 per week for projects under 100K lines of code, 21 per week for 100K–500K, 14 per week for 500K–1M, and 7 per week for over 1M.
  • Access to detailed analysis results for approved project members only, with responsible disclosure of issues before public release.