Besides being a classic quote from the movie, Top Gun, it’s also a mantra of most software development organizations today. We know that time to market is critical and development cycles are shrinking, so development teams need to make sure that the processes and technology they adopt will not slow them down. The same goes for security. With developers under pressure to deliver more functionality at a rapid pace, security is easily overlooked. It’s handled by ‘that other team’ anyway, right? Wrong. Security is everyone’s responsibility in the development lifecycle, including developers. But the question is not why security should be addressed in development, but how it can be addressed efficiently in development.
According to renowned security expert Bruce Schneier, “Assurance is less about developing new security techniques than about using the ones we have.” This statement rings true for development testing technologies such as static analysis. Static analysis is not just about finding quality issues in the code, but also finds common security issues as well. Think buffer overflow. It also integrates with the development and defect tracking workflow, so developers, management, and security teams can quickly identify, assign, and address common security vulnerabilities in code without having to overhaul their process—and without slowing them down.
We are excited to join forces with our friends at Wind River to bring development testing for security to the embedded software development teams building their products on the Wind River platform. Development teams choose Wind River because the platform is ready to use. For example, it’s already pre-built with industry-leading protocols and security certifications, it optimizes application performance, and works with a large partner ecosystem, including Coverity. You can save precious development time with Wind River, and now with Coverity you can do the same by building security testing into the development process as you are writing code–when issues are easiest and fastest to fix–without leaving your workflow. Security doesn’t have to be painful for development, or slow you down.
We are offering a free evaluation of Coverity Static Analysis, pre-configured for Wind River VxWorks and Wind River Linux and integrated with the Wind River Workbench IDE. You can sign up here.


