Skip to main content
Embedder can help configure and run your analyzer, interpret findings, and verify that the intended source files were checked. Start with LSP and static analyzers to enable a tool.

Prepare the run

Identify the analyzer, target build, source scope, standard, and output location. Confirm that the required executable and license are available before analysis.
A successful process exit alone is insufficient if capture was partial or the report is missing. Review the source coverage and configuration with the findings.

Coverity

Use coverity-cli for setup and commands, and validate-coverity for a controlled run. coverity-compliance covers coding-standard configurations; coverity-connect covers connected workflows when requested. Provide the intended build command and current compiler configuration. Keep capture and analysis on the same source revision and verify the generated report before relying on it.

Parasoft C/C++test

Use parasoft-cpptest-cli for setup and validate-parasoft for analysis. Choose the appropriate input for the project: a compilation database, build data file, or traced build. A check of one compile command is a limited analysis. The optional parasoft-cpptest-mcp integration can help read rules and existing reports; it does not replace running the analyzer.

Perforce QAC

Use validate-qac to coordinate the installed QAC workflow. Provide the controlled QAC project, current build inputs, selected components, and first-party source roots. Confirm vendor and generated-code boundaries before synchronization. Preserve the project’s reviewed rule configuration and explain missing components or unfinished analysis in the result.

MISRA and CERT

Name the analyzer you want when invoking validate-MISRA or validate-CERT. If you need an open-source workflow, use the cppcheck and clang-tidy setup. Ask the report to separate:
  • Files and build configurations analyzed.
  • Setup errors, skipped files, and incomplete checks.
  • Automated findings.
  • Requirements that need manual review.
  • Existing approved deviations or suppressions.
Automated analysis supports a review; it does not establish compliance or certification by itself. Do not treat an incomplete run as a clean result.

Remediate findings

Choose a finding or module, ask for a focused fix, and repeat the same analysis and relevant tests. Review any proposal to suppress a finding, exclude source, change shared rules, or publish results separately from the code fix.
Last modified on September 12, 2026