Prepare the run
Identify the analyzer, target build, source scope, standard, and output location. Confirm that the required executable and license are available before analysis.Coverity
Usecoverity-cli for setup and commands, and validate-coverity for a controlled run. coverity-compliance covers coding-standard configurations; coverity-connect covers connected workflows when requested.
Provide the intended build command and current compiler configuration. Keep capture and analysis on the same source revision and verify the generated report before relying on it.
Parasoft C/C++test
Useparasoft-cpptest-cli for setup and validate-parasoft for analysis. Choose the appropriate input for the project: a compilation database, build data file, or traced build.
A check of one compile command is a limited analysis. The optional parasoft-cpptest-mcp integration can help read rules and existing reports; it does not replace running the analyzer.
Perforce QAC
Usevalidate-qac to coordinate the installed QAC workflow. Provide the controlled QAC project, current build inputs, selected components, and first-party source roots.
Confirm vendor and generated-code boundaries before synchronization. Preserve the project’s reviewed rule configuration and explain missing components or unfinished analysis in the result.
MISRA and CERT
Name the analyzer you want when invokingvalidate-MISRA or validate-CERT. If you need an open-source workflow, use the cppcheck and clang-tidy setup.
Ask the report to separate:
- Files and build configurations analyzed.
- Setup errors, skipped files, and incomplete checks.
- Automated findings.
- Requirements that need manual review.
- Existing approved deviations or suppressions.
Automated analysis supports a review; it does not establish compliance or certification by itself. Do not treat an incomplete run as a clean result.

