This release includes the following enhancements:
Initial release date: May 29, 2026
Latest update: 2026.1.3 (August 28, 2026)
Support for Agentic Development Workflows
This release expands support for agentic development workflows, enabling automated remediation of static analysis violations in agentic CI/CD pipelines, LLM-enabled command-line environments, and IDEs. New agent skills and MCP tools are provided that allow you to easily integrate with AI-first development workflows. See Configuring the MCP Server Extension for AI Agents.
- Parasoft now extends AI coding agents with skills for detecting and automatically fixing C/C++test static analysis violations. The new workflows run analysis, iteratively fix reported violations, verify each round of changes, and can optionally commit fixes by rule. These skills integrate with GitHub Copilot CLI, OpenAI Codex CLI, and other coding agents that support MCP tools and skills. See Fixing Violations Using AI Coding Agents.
- A new MCP tool for retrieving the violation count from an XML report has been added, making it easier to determine whether violations exist and whether automated fixing workflows should be applied. See Configuring the MCP Server Extension for AI Agents.
Enhanced Static Analysis
- The scripting engine for RuleWizard rules has been updated to Python 3.14.
IMPORTANT: If you have custom static analysis rules that use RuleWizard's scripting blocks implemented as Python code, contact Parasoft Support for migration guidance. - New code analysis rules have been added to extend coverage of compliance standards. See New Rules for the list of new rules.
- Static analysis rules have been updated to improve accuracy and performance. See Updated Rules for the list of updated rules.
- The filter for limiting the number of violations reported per rule has been improved. A new option has been added to not count rule violations that were suppressed. See Static Tab Settings - Defining How Static Analysis is Performed.
- Support for static analysis of CUDA C++ syntax has been enhanced.
- C/C++ parser has been enhanced to better support modern C and C++ syntax.
Support for Compilers
The following compilers are now supported:
| Compiler Name | Compiler Identifier |
|---|---|
| Clang C/C++ Compiler v 20.0 (x86_64) | clang_20-x86_64 |
| Clang C/C++ Compiler v 20.0 (aarch64) | clang_20-aarch64 |
| Clang C/C++ Compiler v 21.0 (x86_64) | clang_21-x86_64 |
| Clang C/C++ Compiler v 21.0 (aarch64) | clang_21-aarch64 |
| Green Hills Software Compiler for ARM v. 2022.1.x | ghsarm_2022_1 |
| Green Hills Software Compiler for ARM64 v. 2022.1.x | ghsarm64_2022_1 |
| GNU GCC 15.x (aarch64/arm64) | gcc_15-aarch64 |
| GNU GCC 15.x (arm/aarch32) | gcc_15-aarch32 |
| GNU GCC 15.x (x86_64) | gcc_15-64 |
| IAR BXARM v. 9.50x | iccarm_9_50 |
| Metaware DesignWare ARC C/C++ Compiler V-2023.12** | ccac_2023_12 |
| Microsoft Visual C++ 14.5 | vc_14_5 |
| Microsoft Visual C++ 14.5 (x64) | vc_14_5-64 |
| Vx-toolset for TriCore C/C++ Compiler 6.3* | vxtc_6_3 |
| TI ARM Clang Compiler 4.0 | tiarmclang_4_0 |
* - Support for runtime analysis for Linux has been added.
** - Static analysis only.
See Compilers.
Support for IDEs
The following IDE is now supported:
- Visual Studio 2026
New and Updated Test Configurations
The following test configuration has been added:
- VVSG 2.0
The following test configurations have been updated:
- AUTOSAR C++14 Coding Guidelines
- CWE Top 25 + On the Cusp 2023
- CWE Top 25 + On the Cusp 2024
- CWE Top 25 2023
- CWE Top 25 2024
- DISA-ASD-STIG
- Global Analysis
- High Integrity C++
- Joint Strike Fighter
- MISRA C++ 2008
- MISRA C++ 2023
- Modern C++ (11, 14 and 17)
- OWASP API Security Top 10 2019
- OWASP API Security Top 10 2023
- OWASP Top 10 2017
- OWASP Top 10 2021
- Security Rules
- SEI CERT C Guidelines
- SEI CERT C Rules
- SEI CERT C++ Rules
- UL 2900
Breaking Changes
- The scripting engine for RuleWizard rules has been updated to Python 3.14.
IMPORTANT: If you have custom static analysis rules that use RuleWizard's scripting blocks implemented as Python code, contact Parasoft Support for migration guidance. - In certain AWS or Azure Windows Server 2025 environments, the
machineIdmay change after upgrading. If this happens, you will need to acquire a new license from Parasoft. - Parasoft AI Assistant, available in the Visual Studio plugin, has been removed. MCP tools can be used instead. For details, see Configuring the MCP Server Extension for AI Agents.
Additional Updates
A new configuration option has been added that limits the scope of analysis to modified lines of code, either locally or compared to a reference branch or commit. See Configuring File Filters with Advanced Settings.
Deprecated and Removed Support
Deprecated Support for IDEs
Support for the following IDE is deprecated and will be removed in a future release:
- Visual Studio 2017 Professional
Compilers to Be Deprecated
Support for the following compilers will be deprecated in future releases:
- ARM Compiler 6.16
- Clang C/C++ Compiler v 16.0 (aarch32)
- Clang C/C++ Compiler v 16.0 (aarch64)
- Clang C/C++ Compiler v 16.0 (x86_64)
- GNU GCC 8.x
- GNU GCC 8.x (aarch64/arm64)
- GNU GCC 8.x (arm/aarch32)
- GNU GCC 8.x (x86_64)
- GNU GCC 9.x
- GNU GCC 9.x (aarch64/arm64)
- GNU GCC 9.x (arm/aarch32)
- GNU GCC 9.x (x86_64)
- Green Hills Software Compiler for PPC v. 2019.1.x
- Hexagon Clang Compiler v. 8.7.x
- HighTec GCC for Tricore 4.9.x
- IAR BXARM v. 8.50x
- IAR Compiler for ARM v. 9.10x
- Metaware DesignWare ARC C/C++ Compiler P-2019.09
- RX C/C++ Compiler 2.5x
Deprecated Compilers
Support for the following compilers is deprecated and will be removed in future releases:
- ARM Compiler 6.14
- Clang C/C++ Compiler v 12.0 (x86_64)
- Clang C/C++ Compiler v 15.0 (x86_64)
- GNU GCC 7.x
- GNU GCC 7.x (x86_64)
- Hexagon Clang Compiler v. 8.6.x
- IAR Compiler for ARM v. 8.40x
- IAR Compiler for ARM v. 8.50x
- Microchip MPLAB C32 Compiler for PIC32 v2.0x
- Microsoft Visual C++ 14.1
- Microsoft Visual C++ 14.1 (x64)
- TI ARM C/C++ Compiler GNU GCC 7.x
- Vx-toolset for TriCore C/C++ Compiler 4.2
Removed Support for Compilers
The following compilers are no longer supported:
- IAR Compiler for ARM v. 8.20x
- IAR Compiler for ARM v. 8.22x
- TI ARM C/C++ Compiler v18.1
- Wind River Clang 8.0.x
Updates to Rules
New Rules
Rule ID | Header |
|---|---|
APSC_DV-001540-a | Protect against using unprotected credentials |
APSC_DV-001995-j | Avoid time-of-check, time-of-use race conditions when accessing files |
APSC_DV-002520-l | Protect against using unprotected credentials |
APSC_DV-002530-l | Protect against using unprotected credentials |
APSC_DV-002560-l | Protect against using unprotected credentials |
AUTOSAR-A10_2_1-c | Derived classes shall not conceal functions that are inherited from their bases |
AUTOSAR-A7_3_1-b | Derived classes shall not conceal functions that are inherited from their bases |
AUTOSAR-A8_5_4-b | A class shall only define an initializer-list constructor when it is the only constructor |
AUTOSAR-M5_0_7-c | An explicit cast of a complex expression should not convert between integer and floating-point types, increase the size nor change the signedness of the underlying type |
AUTOSAR-M5_0_8-c | An explicit cast of a complex expression should not convert between integer and floating-point types, increase the size nor change the signedness of the underlying type |
AUTOSAR-M5_0_9-b | An explicit cast of a complex expression should not convert between integer and floating-point types, increase the size nor change the signedness of the underlying type |
BD-API-ALLOC | Do not pass 0 value as a size argument to the allocation functions |
BD-SECURITY-EXECPATH | Always specify absolute paths when executing commands |
BD-SECURITY-REMTMP | Remove temporary resources before termination |
BD-SECURITY-TDPASSWD | Protect against using unprotected credentials |
BD-SECURITY-TDSLEEP | Validate potentially tainted data before it is used as a sleep function argument |
BD-TRS-LOCKDSTR | Do not destroy a mutex while it is locked |
BD-TRS-TOCTOUF | Avoid time-of-check, time-of-use race conditions when accessing files |
CERT_C-CON31-d | Do not destroy a mutex while it is locked |
CERT_C-MEM04-b | Do not pass 0 value as a size argument to the allocation functions |
CERT_C-MEM04-c | Do not pass 0 value as a size argument to the realloc function |
CERT_C-MEM04-d | Validate potentially tainted data before it is used to determine the size of memory allocation |
CERT_CPP-CON50-b | Do not destroy a mutex while it is locked |
CERT_CPP-MEM52-c | Handle memory allocation failures when using the 'new' operator |
CODSTA-323 | An explicit cast of a complex expression should not convert between integer and floating-point types, increase the size nor change the signedness of the underlying type |
CODSTA-67_c | 'decltype' and 'auto' should be used consistently in all declarations of the same entity |
CODSTA-76_b | The identifier 'main' followed by an opening parenthesis should not be used, except in the declaration of the global function 'main' |
CODSTA-CPP-215 | Casts shall not be performed between a pointer to function and any other type |
CWE-14-a | Avoid calls to memory-setting functions that can be optimized out by the compiler |
CWE-170-a | Ensure strings are zero terminated |
CWE-170-b | The values returned by functions 'read' and 'readlink' shall be used |
CWE-170-c | Use of possibly not null-terminated string with functions expecting null-terminated string |
CWE-252-b | Consistently check the returned value of non-void functions |
CWE-256-a | Protect against using unprotected credentials |
CWE-287-b | Protect against using unprotected credentials |
CWE-319-a | Protect against using unprotected credentials |
CWE-367-b | Avoid time-of-check, time-of-use race conditions when accessing files |
CWE-400-c | Validate potentially tainted data before it is used as a sleep function argument |
CWE-426-b | Always specify absolute paths when executing commands |
CWE-459-b | Remove temporary resources before termination |
CWE-506-b | Do not use the 'SetFileTime()' function |
CWE-522-a | Protect against using unprotected credentials |
CWE-667-b | Do not destroy a mutex while it is locked |
CWE-667-c | Do not use blocking functions while holding a lock |
CWE-73-a | Protect against file name injection |
CWE-833-a | Do not acquire locks in different order |
CWE-843-b | Do not read the value of a non-active union field |
CWE-99-a | Protect against file name injection |
HICPP-13_1_1-b | Derived classes shall not conceal functions that are inherited from their bases |
JSF-094_c | An inherited nonvirtual function shall not be redefined in a derived class |
MISRA2008-5_0_7_c | There shall be no explicit floating-integral conversions of a cvalue expression |
MISRA2008-5_0_8_c | An explicit integral or floating-point conversion shall not increase the size of the underlying type of a cvalue expression |
MISRA2008-5_0_9_b | An explicit integral conversion shall not change the signedness of the underlying type of a cvalue expression |
MISRA2012-RULE-17_2_b | Functions shall not call themselves, either directly or indirectly |
MISRAC2012-RULE_17_2-b | Do not use recursion |
MISRAC2025-RULE_17_2-b | Do not use recursion |
MISRACPP2023-0_2_3-c | A project shall not contain unused private member type declarations |
MISRACPP2023-6_0_4-b | The identifier 'main' followed by an opening parenthesis should not be used, except in the declaration of the global function 'main' |
MISRACPP2023-6_2_3-e | Template specialization should be declared in the same file (or in the file directly included) as the primary template or a user-defined type, for which the specialization is declared |
MISRACPP2023-6_4_2-c | Derived classes shall not conceal functions that are inherited from their bases |
MISRACPP2023-6_9_1-b | 'decltype' and 'auto' should be used consistently in all declarations of the same entity |
MISRACPP2023-8_2_4-b | Casts shall not be performed between a pointer to function and any other type |
MRM-64 | Handle memory allocation failures when using the 'new' operator |
OOP-101 | Derived classes shall not conceal functions that are inherited from their bases |
OWASP2017-A2-b | Protect against using unprotected credentials |
OWASP2019-API3-s | Avoid time-of-check, time-of-use race conditions when accessing files |
OWASP2021-A7-b | Protect against using unprotected credentials |
OWASP2023-API2-b | Protect against using unprotected credentials |
SECURITY-56 | Do not use the 'SetFileTime()' function |
TEMPL-16_b | Template specialization should be declared in the same file (or in the file directly included) as the primary template or a user-defined type, for which the specialization is declared |
VVSG-2_3_1_A-a | For any iteration statement there shall be no more than one break or goto statement used for loop termination |
VVSG-2_3_1_A-b | The continue statement shall only be used within a well formed for loop |
VVSG-2_3_1_B-a | The goto statement shall not be used |
VVSG-2_3_1_D-a | The facilities provided by <setjmp.h> should not be used |
VVSG-2_3_1_D-b | The standard header files <setjmp.h> or <csetjmp> shall not be used |
VVSG-2_3_1_D-c | Control shall not be transferred into a try or catch block using a goto or a switch statement |
VVSG-2_3_D-a | Do not hard code string literals |
VVSG-2_4_A-a | A declaration shall be visible when an object or function with external linkage is defined |
VVSG-2_4_A-b | An external object or function shall not have more than one non-defining declaration in translation unit |
VVSG-2_4_A-c | Protected member function shall not return non-const handles to private class-data |
VVSG-2_4_A-d | Public member functions shall not return non-const handles to private/protected class-data |
VVSG-2_4_A-e | Member data in non-POD types shall be private |
VVSG-2_4_A-f | Do not increase the accessibility of overridden or hidden methods |
VVSG-2_4_C-a | Any one function (or method) will contain no more than 200 logical source lines of code (L-SLOCs) |
VVSG-2_5_2_A-a | Validate potentially tainted data before it is used to determine the size of memory allocation |
VVSG-2_5_2_A-b | Protect against command injection |
VVSG-2_5_2_A-c | Avoid printing tainted data on the output console |
VVSG-2_5_2_A-d | Protect against environment injection |
VVSG-2_5_2_A-e | Protect against file name injection |
VVSG-2_5_2_A-f | Exclude unsanitized user input from format strings |
VVSG-2_5_2_A-g | Avoid potential integer overflow/underflow on tainted data |
VVSG-2_5_2_A-h | Validate potentially tainted data before it is used in the controlling expression of a loop |
VVSG-2_5_2_A-i | Protect against using unprotected credentials |
VVSG-2_5_2_A-j | Validate potentially tainted data before it is used as a sleep function argument |
VVSG-2_5_2_A-k | Protect against SQL injection |
VVSG-2_5_3_A-a | Do not print potentially sensitive information, resulting from an application error into exception messages |
VVSG-2_5_3_B-a | Avoid printing tainted data on the output console |
VVSG-2_5_3_C-a | Protect against command injection |
VVSG-2_5_3_C-b | Protect against environment injection |
VVSG-2_5_3_C-c | Protect against file name injection |
VVSG-2_5_3_C-d | Protect against SQL injection |
VVSG-2_5_4_A-a | Avoid signed integer overflows |
VVSG-2_5_4_A-b | Avoid null pointer dereferencing |
VVSG-2_5_4_A-c | Avoid division by zero |
VVSG-2_5_4_B-a | Avoid accessing arrays out of bounds |
VVSG-2_5_4_B-b | Avoid accessing arrays and pointers out of bounds |
VVSG-2_5_4_B-c | Avoid tainted data in array indexes |
VVSG-2_5_4_C-a | Avoid buffer overflow due to defining incorrect format limits |
VVSG-2_5_4_C-b | Avoid overflow due to reading a not zero terminated string |
VVSG-2_5_4_C-c | Avoid overflow when reading from a buffer |
VVSG-2_5_4_C-d | Avoid overflow when writing to a buffer |
VVSG-2_5_4_C-e | Prevent buffer overflows from tainted data |
VVSG-2_5_4_C-f | Avoid buffer overflow from tainted data due to defining incorrect format limits |
VVSG-2_5_4_C-g | Avoid buffer write overflow from tainted data |
VVSG-2_5_4_C-h | Avoid buffer read overflow from tainted data |
VVSG-2_5_4_E-a | Validate values passed to library functions |
VVSG-2_5_4_E-b | The validity of parameters must be checked inside each function |
VVSG-2_5_4_F-a | Avoid wraparounds when performing arithmetic integer operations |
VVSG-2_5_4_F-b | Integer overflow or underflow in constant expression in '+', '-', '*' operator |
VVSG-2_5_4_F-c | Integer overflow or underflow in constant expression in '<<' operator |
VVSG-2_5_4_G-a | Exclude unsanitized user input from format strings |
VVSG-2_5_4_I-a | A pointer operand and any pointer resulting from pointer arithmetic using that operand shall both address elements of the same array |
VVSG-2_5_4_I-b | Do not compare two unrelated pointers |
VVSG-2_5_4_I-c | Do not subtract two pointers that do not address elements of the same array |
VVSG-2_5_4_I-d | Do not store an already-owned pointer value in an unrelated smart pointer |
VVSG-2_5_4_J-a | Properly deallocate dynamically allocated resources |
VVSG-2_5_4_J-b | Do not use resources that have been freed |
VVSG-2_5_4_J-c | Allocate sufficient memory to hold an object of a given type |
VVSG-2_5_4_J-d | Do not free resources using invalid pointers |
VVSG-2_5_4_J-e | Ensure resources are freed |
VVSG-2_5_4_K-a | Always assign a new value to an expression that points to deallocated memory |
VVSG-2_5_4_K-b | Always assign a new value to global or member variable that points to deallocated memory |
VVSG-2_5_4_K-c | Always assign a new value to parameter or local variable that points to deallocated memory |
VVSG-2_5_4_N-a | Protect against SQL injection |
VVSG-2_5_B-a | Variable should be used in context of single critical section |
VVSG-2_5_B-b | Avoid double locking |
VVSG-2_5_B-c | Do not abandon unreleased locks |
VVSG-2_5_B-d | Do not destroy a mutex while it is locked |
VVSG-2_5_B-e | Do not acquire locks in different order |
VVSG-2_5_B-f | There shall be no data races between threads |
VVSG-2_5_B-g | Usage of functions prone to race is not allowed |
VVSG-3_1_1_C-a | Every source file will be documented with an introductory comment that provides information on the file |
VVSG-3_1_1_C-b | Document functions in comments that precede function definitions |
VVSG-11_1_B-a | Avoid passing sensitive data to functions that write to log files |
VVSG-11_1_C-a | Avoid passing unvalidated binary data to log methods |
VVSG-13_3_C-a | Do not use weak encryption functions |
VVSG-14_2_G-a | Avoid conditions that always evaluate to the same value |
VVSG-14_2_G-b | Avoid switch with unreachable branches |
VVSG-14_2_G-c | Avoid unused values |
VVSG-14_2_G-d | A source file should not contain unused macro definitions |
VVSG-14_2_G-e | A project should not contain unused local variables |
VVSG-14_2_G-f | Eliminate unused parameters |
VVSG-14_2_G-g | Avoid unused private member variables |
VVSG-14_2_G-h | A function should not contain unused label declarations |
VVSG-14_2_G-i | A project should not contain unused variables with internal linkage |
VVSG-14_2_I-a | A file should directly include only the headers that contain declarations and definitions required to compile that file |
Updated Rules
New parameters
New parameters have been added to the following rules (see the rule documentation for details of each parameter's behavior):
Rule ID | Parameter name |
|---|---|
CODSTA-CPP-205, MISRACPP2023-15_0_2-a | Report defaulted functions |
CODSTA-CPP-206, MISRACPP2023-6_8_4-a | Enforce const-rvalue-ref-qualified overloads |
BD-PB-RECFUN, AUTOSAR-A7_5_2-a, CERT_C-MEM05-a, HICPP-5_2_2-b, MISRA2008-7_5_4, MISRA2012-RULE-17_2_b, MISRAC2012-RULE_17_2-b, MISRAC2025-RULE_17_2-b, MISRACPP2023-8_2_10-a | Report on virtual function calls |
BD-PB-OVERFARRAY, AUTOSAR-A5_2_5-b, CERT_C-EXP39-c, CWE-119-b, CWE-121-b, CWE-122-b, CWE-124-b, CWE-125-b, CWE-126-b, CWE-127-b, CWE-787-b, HICPP-5_2_1-b, MISRA2012-RULE-18_1_b, MISRAC2012-RULE_18_1-b, MISRAC2025-RULE_18_1-b, OWASP2019-API3-c, VVSG-2_5_4_B-b | Report violations when pointer dereference within structure bounds is out of the allocated array bounds |
BD-PB-ZERO, AUTOSAR-A5_6_1-a, AUTOSAR-M0_3_1-e, CERT_C-FLP03-a, CERT_C-INT33-a, CWE-369-a, HICPP-5_5_1-a, MISRA2008-0_3_1_c, MISRA2012-DIR-4_1_c, MISRA2012-RULE-1_3_a, MISRAC2012-DIR_4_1-c, MISRAC2012-RULE_1_3-a, MISRAC2025-DIR_4_1-c, MISRAC2025-RULE_1_3-a, MISRACPP2023-4_1_3-d, VVSG-2_5_4_A-c | Report on floating point division |
BD-PB-VOVR, AUTOSAR-A0_1_1-a, CERT_C-DCL22-a, CWE-563-a, MISRA2008-0_1_6, MISRA2012-RULE-2_2_b, MISRAC2012-RULE_2_2-b, MISRAC2025-RULE_2_2-b, MISRACPP2023-0_1_1-a, VVSG-14_2_G-c | Reporting on variable declarations: including unused variables of reference type |
Major specification changes
The specification of the following rule has been significantly changed: CODSTA-CPP-208, MISRACPP2023-18_4_1-a
The rule has been extended to additionally report deallocation functions that are neither implicitly nor explicitly noexcept.
struct S
{
void operator delete(void* ptr) noexcept(false); // Violation (previously the rule did not apply)
};
All changes
The following rules have been updated:
Category ID | Rule IDs |
|---|---|
AUTOSAR C++14 Coding Guidelines | AUTOSAR-A0_1_1-a, AUTOSAR-A0_1_2-a, AUTOSAR-A0_1_3-a, AUTOSAR-A0_1_6-a, AUTOSAR-A12_1_3-a, AUTOSAR-A12_1_5-a, AUTOSAR-A12_8_3-a, AUTOSAR-A14_7_2-a, AUTOSAR-A15_0_2-a, AUTOSAR-A15_1_4-a, AUTOSAR-A18_9_3-a, AUTOSAR-A27_0_1-g, AUTOSAR-A27_0_1-h, AUTOSAR-A27_0_2-a, AUTOSAR-A27_0_2-b, AUTOSAR-A4_10_1-b, AUTOSAR-A5_0_1-f, AUTOSAR-A5_2_5-a, AUTOSAR-A5_2_5-b, AUTOSAR-A5_2_5-c, AUTOSAR-A5_3_2-a, AUTOSAR-A5_6_1-a, AUTOSAR-A7_5_2-a, AUTOSAR-M0_1_10-a, AUTOSAR-M0_1_10-b, AUTOSAR-M0_1_2-ac, AUTOSAR-M0_1_4-a, AUTOSAR-M0_3_1-a, AUTOSAR-M0_3_1-b, AUTOSAR-M0_3_1-d, AUTOSAR-M0_3_1-e, AUTOSAR-M0_3_1-f, AUTOSAR-M0_3_1-g, AUTOSAR-M16_0_6-a, AUTOSAR-M2_10_1-a, AUTOSAR-M3_4_1-a, AUTOSAR-M5_0_16-a, AUTOSAR-M5_0_16-b, AUTOSAR-M5_0_17-a, AUTOSAR-M8_5_2-a, AUTOSAR-M9_3_3-a |
Coding Conventions for C++ | CODSTA-CPP-106, CODSTA-CPP-205, CODSTA-CPP-206, CODSTA-CPP-208, CODSTA-CPP-209, CODSTA-CPP-214, CODSTA-CPP-54, CODSTA-CPP-58, CODSTA-CPP-78, CODSTA-CPP-82 |
Coding Conventions for Modern C++ | CODSTA-MCPP-04, CODSTA-MCPP-47_b, CODSTA-MCPP-53 |
Coding Conventions | CODSTA-67_b, CODSTA-227, CODSTA-303, CODSTA-312, CODSTA-313 |
Common Weakness Enumeration | CWE-119-a, CWE-119-b, CWE-119-e, CWE-121-a, CWE-121-b, CWE-121-e, CWE-122-a, CWE-122-b, CWE-122-e, CWE-124-a, CWE-124-b, CWE-124-d, CWE-125-a, CWE-125-b, CWE-126-a, CWE-126-b, CWE-127-a, CWE-127-b, CWE-134-a, CWE-188-b, CWE-194-c, CWE-20-d, CWE-20-g, CWE-22-a, CWE-23-a, CWE-36-a, CWE-364-a, CWE-366-a, CWE-369-a, CWE-377-a, CWE-401-a, CWE-404-a, CWE-459-a, CWE-469-a, CWE-476-a, CWE-479-a, CWE-563-a, CWE-570-a, CWE-571-a, CWE-59-a, CWE-665-a, CWE-665-b, CWE-667-a, CWE-668-a, CWE-690-a, CWE-74-a, CWE-74-c, CWE-77-a, CWE-772-a, CWE-773-a, CWE-775-a, CWE-78-a, CWE-787-a, CWE-787-b, CWE-787-d, CWE-832-a |
DISA ASD STIG | APSC_DV-000060-a, APSC_DV-001995-i, APSC_DV-002000-a, APSC_DV-002400-a, APSC_DV-002510-a, APSC_DV-002520-b, APSC_DV-002520-h, APSC_DV-002520-j, APSC_DV-002530-b, APSC_DV-002530-h, APSC_DV-002530-j, APSC_DV-002550-b, APSC_DV-002550-h, APSC_DV-002550-j, APSC_DV-002560-b, APSC_DV-002560-h, APSC_DV-002560-j, APSC_DV-002590-b, APSC_DV-002590-d, APSC_DV-003235-a |
Flow Analysis | BD-PB-ARRAY, BD-PB-CC, BD-PB-CHECKRET, BD-PB-NP, BD-PB-OVERFARRAY, BD-PB-OVERFNZT, BD-PB-OVERFWR, BD-PB-PTRARR, BD-PB-PTRSUB, BD-PB-RECFUN, BD-PB-SIGHAN, BD-PB-STREAMFLAGS, BD-PB-STREAMFMT, BD-PB-SUBSEQMOVE, BD-PB-VOVR, BD-PB-ZERO, BD-RES-LEAKS, BD-SECURITY-TDCMD, BD-SECURITY-TDFNAMES, BD-SECURITY-TDINPUT, BD-TRS-DLOCK, BD-TRS-LOCK, BD-TRS-REVLOCK, BD-TRS-SYMLINK, BD-TRS-THRDR |
Global Static Analysis | GLOBAL-ONEUSEVAR, GLOBAL-UNUSEDFUNC, GLOBAL-UNUSEDTYPE |
High Integrity C++ | HICPP-12_4_5-a, HICPP-17_3_1-a, HICPP-18_3_1-a, HICPP-1_2_1-i, HICPP-2_4_1-a, HICPP-2_5_3-a, HICPP-3_5_1-c, HICPP-5_1_2-b, HICPP-5_2_1-a, HICPP-5_2_1-b, HICPP-5_2_1-c, HICPP-5_2_2-b, HICPP-5_5_1-a, HICPP-6_4_1-a, HICPP-8_4_2-a, HICPP-9_1_1-a |
Initialization | INIT-12, INIT-16, INIT-17, INIT-17_b |
Joint Strike Fighter | JSF-052, JSF-069, JSF-115_a, JSF-117_b, JSF-136_b, JSF-144, JSF-186_h, JSF-204.1_b, JSF-207, JSF-214 |
Memory and Resource Management | MRM-34 |
MISRA C 2004 | MISRA2004-12_2_b, MISRA2004-18_1, MISRA2004-19_10, MISRA2004-9_2 |
MISRA C 2012 (Legacy) | MISRA2012-DIR-4_13_a, MISRA2012-DIR-4_13_d, MISRA2012-DIR-4_13_e, MISRA2012-DIR-4_13_f, MISRA2012-DIR-4_14_e, MISRA2012-DIR-4_14_f, MISRA2012-DIR-4_14_l, MISRA2012-DIR-4_1_a, MISRA2012-DIR-4_1_b, MISRA2012-DIR-4_1_c, MISRA2012-DIR-4_1_e, MISRA2012-DIR-4_1_h, MISRA2012-DIR-4_1_i, MISRA2012-DIR-4_7_a, MISRA2012-DIR-5_1_c, MISRA2012-RULE-13_2_b, MISRA2012-RULE-14_3_zc, MISRA2012-RULE-18_1_a, MISRA2012-RULE-18_1_b, MISRA2012-RULE-18_1_c, MISRA2012-RULE-18_2, MISRA2012-RULE-1_3_a, MISRA2012-RULE-1_3_e, MISRA2012-RULE-1_3_g, MISRA2012-RULE-20_7, MISRA2012-RULE-21_17_a, MISRA2012-RULE-21_17_b, MISRA2012-RULE-22_1, MISRA2012-RULE-22_16, MISRA2012-RULE-22_17, MISRA2012-RULE-22_18, MISRA2012-RULE-2_2_b, MISRA2012-RULE-9_2 |
MISRA C 2023 (MISRA C 2012) | MISRAC2012-DIR_4_1-a, MISRAC2012-DIR_4_1-b, MISRAC2012-DIR_4_1-c, MISRAC2012-DIR_4_1-e, MISRAC2012-DIR_4_1-h, MISRAC2012-DIR_4_1-i, MISRAC2012-DIR_4_13-a, MISRAC2012-DIR_4_13-d, MISRAC2012-DIR_4_13-e, MISRAC2012-DIR_4_13-f, MISRAC2012-DIR_4_14-e, MISRAC2012-DIR_4_14-f, MISRAC2012-DIR_4_14-l, MISRAC2012-DIR_4_7-a, MISRAC2012-DIR_5_1-c, MISRAC2012-RULE_13_2-b, MISRAC2012-RULE_14_3-ac, MISRAC2012-RULE_18_1-a, MISRAC2012-RULE_18_1-b, MISRAC2012-RULE_18_1-c, MISRAC2012-RULE_18_2-a, MISRAC2012-RULE_1_3-a, MISRAC2012-RULE_1_3-e, MISRAC2012-RULE_1_3-g, MISRAC2012-RULE_20_7-a, MISRAC2012-RULE_21_17-a, MISRAC2012-RULE_21_17-b, MISRAC2012-RULE_22_1-a, MISRAC2012-RULE_22_16-a, MISRAC2012-RULE_22_17-a, MISRAC2012-RULE_22_18-a, MISRAC2012-RULE_2_2-b, MISRAC2012-RULE_9_2-a |
MISRA C 2025 | MISRAC2025-DIR_4_1-a, MISRAC2025-DIR_4_1-b, MISRAC2025-DIR_4_1-c, MISRAC2025-DIR_4_1-e, MISRAC2025-DIR_4_1-h, MISRAC2025-DIR_4_1-i, MISRAC2025-DIR_4_13-a, MISRAC2025-DIR_4_13-d, MISRAC2025-DIR_4_13-e, MISRAC2025-DIR_4_13-f, MISRAC2025-DIR_4_14-e, MISRAC2025-DIR_4_14-f, MISRAC2025-DIR_4_14-l, MISRAC2025-DIR_4_7-a, MISRAC2025-DIR_5_1-c, MISRAC2025-RULE_13_2-b, MISRAC2025-RULE_14_3-ac, MISRAC2025-RULE_18_1-a, MISRAC2025-RULE_18_1-b, MISRAC2025-RULE_18_1-c, MISRAC2025-RULE_18_2-a, MISRAC2025-RULE_1_3-a, MISRAC2025-RULE_1_3-e, MISRAC2025-RULE_1_3-g, MISRAC2025-RULE_21_17-a, MISRAC2025-RULE_21_17-b, MISRAC2025-RULE_22_1-a, MISRAC2025-RULE_22_16-a, MISRAC2025-RULE_22_17-a, MISRAC2025-RULE_22_18-a, MISRAC2025-RULE_2_2-b, MISRAC2025-RULE_9_2-a |
MISRA C++ 2008 | MISRA2008-0_1_10, MISRA2008-0_1_10_b, MISRA2008-0_1_2_aa, MISRA2008-0_1_4, MISRA2008-0_1_5, MISRA2008-0_1_6, MISRA2008-0_1_7, MISRA2008-0_3_1_a, MISRA2008-0_3_1_b, MISRA2008-0_3_1_c, MISRA2008-0_3_1_e, MISRA2008-0_3_1_h, MISRA2008-0_3_1_i, MISRA2008-14_5_1, MISRA2008-16_0_6, MISRA2008-2_10_1, MISRA2008-3_4_1_a, MISRA2008-5_0_16_a, MISRA2008-5_0_16_b, MISRA2008-5_0_17, MISRA2008-5_0_1_b, MISRA2008-7_5_4, MISRA2008-8_5_2, MISRA2008-9_3_3 |
MISRA C++ 2023 | MISRACPP2023-0_0_2-a, MISRACPP2023-0_1_1-a, MISRACPP2023-0_1_2-a, MISRACPP2023-10_2_3-a, MISRACPP2023-15_0_2-a, MISRACPP2023-15_1_5-a, MISRACPP2023-18_4_1-a, MISRACPP2023-18_4_1-b, MISRACPP2023-19_3_4-a, MISRACPP2023-28_6_1-a, MISRACPP2023-28_6_3-b, MISRACPP2023-4_1_3-c, MISRACPP2023-4_1_3-d, MISRACPP2023-4_6_1-b, MISRACPP2023-6_4_1-g, MISRACPP2023-6_7_2-a, MISRACPP2023-6_8_4-a, MISRACPP2023-6_9_1-a, MISRACPP2023-7_0_6-a, MISRACPP2023-7_0_6-b, MISRACPP2023-7_11_1-a, MISRACPP2023-8_2_10-a, MISRACPP2023-8_7_1-a, MISRACPP2023-8_7_1-b, MISRACPP2023-8_7_1-d, MISRACPP2023-8_7_1-e, MISRACPP2023-8_7_2-a |
Naming Conventions | NAMING-42, NAMING-47 |
Optimization | OPT-01, OPT-30 |
OWASP API Security Top 10 (2019) | OWASP2019-API3-b, OWASP2019-API3-c, OWASP2019-API3-e, OWASP2019-API3-g, OWASP2019-API4-b, OWASP2019-API8-a, OWASP2019-API8-d, OWASP2019-API8-e |
OWASP API Security Top 10 (2023) | OWASP2023-API10-d, OWASP2023-API10-g, OWASP2023-API10-i, OWASP2023-API4-d |
OWASP Top 10 (2017) | OWASP2017-A1-b, OWASP2017-A1-e, OWASP2017-A5-a |
OWASP Top 10 (2021) | OWASP2021-A1-a, OWASP2021-A3-b, OWASP2021-A3-e |
Physical File Organization | PFO-10 |
Possible Bugs | PB-23 |
Security | SECURITY-39 |
SEI CERT C++ | CERT_CPP-CON56-a, CERT_CPP-CTR54-c, CERT_CPP-DCL56-a, CERT_CPP-ERR57-a, CERT_CPP-EXP50-b, CERT_CPP-EXP63-a, CERT_CPP-FIO51-a, CERT_CPP-MSC54-a, CERT_CPP-STR50-b, CERT_CPP-STR50-c, CERT_CPP-STR51-a |
SEI CERT C | CERT_C-API01-a, CERT_C-ARR30-a, CERT_C-ARR36-a, CERT_C-ARR38-b, CERT_C-ARR38-d, CERT_C-ARR39-a, CERT_C-CON01-a, CERT_C-CON30-a, CERT_C-DCL19-a, CERT_C-DCL22-a, CERT_C-ENV01-c, CERT_C-ERR32-b, CERT_C-EXP08-b, CERT_C-EXP10-b, CERT_C-EXP30-b, CERT_C-EXP34-a, CERT_C-EXP39-c, CERT_C-FIO21-b, CERT_C-FIO22-a, CERT_C-FIO32-a, CERT_C-FIO37-a, CERT_C-FIO42-a, CERT_C-FLP03-a, CERT_C-INT33-a, CERT_C-MEM00-e, CERT_C-MEM05-a, CERT_C-MEM12-a, CERT_C-MEM31-a, CERT_C-MSC12-j, CERT_C-MSC19-a, CERT_C-MSC19-b, CERT_C-POS30-a, CERT_C-POS35-b, CERT_C-POS48-b, CERT_C-POS54-a, CERT_C-PRE01-a, CERT_C-SIG30-a, CERT_C-SIG31-a, CERT_C-SIG34-a, CERT_C-STR02-a, CERT_C-STR02-b, CERT_C-STR03-a, CERT_C-STR31-a, CERT_C-STR31-b, CERT_C-STR32-a, CERT_C-WIN30-a |
Template | TEMPL-13, TEMPL-16 |
Deprecated Rules
The following rules are deprecated and will be removed in a future release:
Rule ID | Notes |
|---|---|
CODSTA-124_c | CODSTA-CPP-215 (parameterized) can be used instead. |
CODSTA-MCPP-13_d | CODSTA-MCPP-13_b and CODSTA-MCPP-13_c can be used instead. |
OOP-17 | OOP-101 (parameterized) can be used instead. |
OOP-32 | OOP-101 (parameterized) can be used instead. |
OOP-53 | OOP-101 (parameterized) can be used instead. |
MRM-34 | MRM-64 can be used instead. |
Removed Rules
Rule ID | Notes |
|---|---|
APSC_DV-001995-b | Removed from DISA-ASD-STIG configuration. For other configurations, BD-TRS-SYMLINK can be used instead. |
AUTOSAR-A10_2_1-a | Removed from AUTOSAR C++14 configuration. For other configurations, OOP-101 (parameterized) can be used instead. |
AUTOSAR-A10_2_1-b | Removed from AUTOSAR C++14 configuration. For other configurations, OOP-101 (parameterized) can be used instead. |
AUTOSAR-A7_3_1-a | Removed from AUTOSAR C++14 configuration. For other configurations, OOP-101 (parameterized) can be used instead. |
AUTOSAR-A8_5_4-a | Removed from AUTOSAR C++14 configuration. For other configurations, CODSTA-MCPP-47_b or CODSTA-MCPP-47 can be used instead. |
AUTOSAR-M5_0_7-a | Removed from AUTOSAR C++14 configuration. For other configurations, CODSTA-323 (parameterized) or CODSTA-198_b can be used instead. |
AUTOSAR-M5_0_7-b | Removed from AUTOSAR C++14 configuration. For other configurations, CODSTA-323 (parameterized) or MISRA2004-10_3 can be used instead. |
AUTOSAR-M5_0_8-a | Removed from AUTOSAR C++14 configuration. For other configurations, CODSTA-323 (parameterized) or MISRA2004-10_3 can be used instead. |
AUTOSAR-M5_0_8-b | Removed from AUTOSAR C++14 configuration. For other configurations, CODSTA-323 (parameterized) or CODSTA-198 can be used instead. |
AUTOSAR-M5_0_9-a | Removed from AUTOSAR C++14 configuration. For other configurations, CODSTA-323 (parameterized) or MISRA2004-10_3 can be used instead. |
CERT_C-MEM04-a | Removed from SEI CERT C configuration. For other configurations, MISRA2004-20_3 can be used instead. |
CERT_CPP-MEM52-a | Removed from SEI CERT C++ configuration. For other configurations, MRM-64 can be used instead. |
CWE-20-i | Removed from CWE Top 25 configurations. For other configurations, BD-SECURITY-TDFNAMES can be used instead. |
CWE-367-a | Removed from CWE Top 25 configurations. For other configurations, BD-TRS-SYMLINK can be used instead. |
CWE-506-a | Removed from CWE Top 25 configurations. For other configurations, BD-SECURITY-SENSLOG can be used instead. |
HICPP-13_1_1-a | Removed from High Integrity C++ configuration. For other configurations, OOP-101 (parameterized) can be used instead. |
HICPP-5_2_2-a | Removed from High Integrity C++ configuration. For other configurations, BD-PB-RECFUN or MISRA2004-16_2 can be used instead. |
JSF-094 | Removed from JSF configuration. For other configurations, OOP-101 (parameterized) can be used instead. |
JSF-094_b | Removed from JSF configuration. For other configurations, OOP-101 (parameterized) can be used instead. |
MISRA2008-5_0_7_a | Removed from MISRA C++ 2008 configuration. For other configurations, CODSTA-323 (parameterized) or CODSTA-198_b can be used instead. |
MISRA2008-5_0_7_b | Removed from MISRA C++ 2008 configuration. For other configurations, CODSTA-323 (parameterized) or MISRA2004-10_3 can be used instead. |
MISRA2008-5_0_8 | Removed from MISRA C++ 2008 configuration. For other configurations, CODSTA-323 (parameterized) or MISRA2004-10_3 can be used instead. |
MISRA2008-5_0_8_b | Removed from MISRA C++ 2008 configuration. For other configurations, CODSTA-323 (parameterized) or CODSTA-198 can be used instead. |
MISRA2008-5_0_9 | Removed from MISRA C++ 2008 configuration. For other configurations, CODSTA-323 (parameterized) or MISRA2004-10_3 can be used instead. |
MISRA2012-RULE-17_2 | Removed from MISRA C 2012 (Legacy) configuration. For other configurations, BD-PB-RECFUN or MISRA2004-16_2 can be used instead. |
MISRAC2012-RULE_17_2-a | Removed from MISRA C 2012 configuration. For other configurations, BD-PB-RECFUN or MISRA2004-16_2 can be used instead. |
MISRAC2025-RULE_17_2-a | Removed from MISRA C 2025 configuration. For other configurations, BD-PB-RECFUN or MISRA2004-16_2 can be used instead. |
MISRACPP2023-6_2_3-d | Removed from MISRA C++ 2023 configuration. For other configurations, TEMPL-16_b or TEMPL-16 can be used instead. |
MISRACPP2023-6_4_2-a | Removed from MISRA C++ 2023 configuration. For other configurations, OOP-101 (parameterized) can be used instead. |
MISRACPP2023-6_4_2-b | Removed from MISRA C++ 2023 configuration. For other configurations, OOP-101 (parameterized) can be used instead. |
MISRACPP2023-8_2_4-a | Removed from MISRA C++ 2023 configuration. For other configurations, CODSTA-CPP-215 (parameterized) can be used instead. |
OWASP2019-API3-m | Removed from OWASP API Top 10 2019 configuration. For other configurations, BD-TRS-SYMLINK can be used instead. |
Resolved Bugs and FRs
Bug/FR ID | Description |
|---|---|
CPP-48539 | [security] VVSG e-voting static analysis security rules |
CPP-48613 | [compiler] Conditionally enable CPPTEST_HAS_LONG_LONG in C++test runtime for EWARM targets |
CPP-56290 | [compiler] Support for GHS ARM 2022.1.x (full, extended, windows+linux) |
CPP-56781 | [static] Review and improve mapping for AUTOSAR M5-0-[7..9] |
CPP-58069 | [static] Improve mapping for CERT C MEM04-C |
CPP-58874 | [stubs] QuickExecutionMode triggers Invalid stub configuration when using stub callbacks |
CPP-59668 | [static] Improve mapping for MISRACPP2023 Rule 6.4.2 |
CPP-59703 | [static] Improve MISRACPP2023-6_4_2 mapping to support base class functions introduced via 'using-declarations' |
CPP-59750 | [engine] /tmp/ParaSoft files reported due to incorrect code instrumentation |
CPP-59757 | [engine] Empty initializer list incorrectly creates one default-constructed string |
CPP-60151 | [compiler] Support for Tasking Compiler 6.3 (Linux x86-64, Full, Extended) |
CPP-60263 | [compiler] Support for Metaware DesignWare ARC C/C++ Compiler 2023.12 (Static, Extended, Windows) |
CPP-60271 | [engine] Class template argument deduction - user defined deduction guides error |
CPP-60328 | [static] False positive of CODSTA-MCPP-04 (MISRACPP2023-7_11_1-a, AUTOSAR-A4_10_1-b) on constant expressions resulting from decltype and sizeof |
CPP-60406 | [static] Update MISRA C++ Rule 6.4.2 |
CPP-60459 | [engine] cpptestcc instantiates incorrect templated constructor overload |
CPP-60565 | [coverage] Decision Coverage not reported for switch with 'try-catch' right after 'case' |
CPP-60574 | [compiler] Support for TI Clang Compiler 4.0.x (Full, Extended, Linux, Target: arm32) |
CPP-60687 | [engine] error: parameter pack "TypeT" was referenced but not expanded |
CPP-60704 | [engine] Narrowing in list initialization ignored in non-evaluated context |
CPP-60824 | [engine] cwc errors are reported during static analysis on TriCore v6.3r1 (vxtc_6_3) compiler |
CPP-60846 | [coverage] Missing runtime coverage due to C++20 operator rewriting |
CPP-61133 | [engine] Instrumentation error: error: more than one instance of constructor matches the argument list |
CPP-61145 | [static] NAMING-42 rule does not report violations on const arrays in C code |
CPP-61156 | [engine] error C2276: '&': illegal operation on bound member function expression |
CPP-61172 | [coverage] Static functions (or functions from unnamed namespace) incorrectly grouped in the DTP Coverage Explorer |
CPP-61173 | [engine] Standard exception was caught : Unknown calling convention. |
CPP-61175 | [engine] Instrumentation error: no matching function for call to kind<capnp::AnyStruct>() |
CPP-61179 | [engine] error: 'enum class foo::EMessaging<foo::BMU_DBC::BMUA_nmResp>::PubIdx' is private within this context |
CPP-61186 | [engine] Instrumentation compilation error for consecutive 'enum' values at the 'signed int' boundary |
CPP-61191 | [engine] error: expected ) before { token |
CPP-61242 | [engine] Incorrect instrumentation for C-language compound literal if the type is an array with a bound of 0 (GCC). |
CPP-61248 | [compiler] Support for GNU GCC 15 (Full, Extended, Linux, targets: x86_64, arm32, arm64) |
CPP-61251 | [ide] Support for Visual Studio 2026 IDE |
CPP-61254 | [static] MISRA2004-18_1 reports false positive on a const object of complete type |
CPP-61270 | [static] CODSTA-227 (CERT_C-POS54-a) reports false positive violations on member functions |
CPP-61271 | [engine] Instrumentation fails on operator deduction for code using Eigen Template Library |
CPP-61272 | [static] False Positive MISRA2008-3_4_1_a (OPT-01) declaring any more locally would cause a dangling pointer |
CPP-61284 | [static] CODSTA-CPP-106 (AUTOSAR-A12_1_5-a) reports false positive on a class with template constructor |
CPP-61321 | [static] CODSTA-CPP-82 reports false positives on static const members |
CPP-61365 | [docs] Link to "Understanding reports" is guarded by "parasoft2" password |
CPP-61380 | [static] MISRA2004-12_2_b (MISRA2012-RULE-13_2_b) reports false positive when a function with variadic template is called as argument |
CPP-61390 | [static] Report unused suppressions in report.xml |
CPP-61392 | [compiler] Support for Clang 20 (Linux x86-64, arm64, Full, Extended) |
CPP-61406 | [build] Improve cpptest-project.cmake: use CMAKE_HOST_WIN32 instead of WIN32 |
CPP-61410 | [engine] error: a template-dependent designator is not allowed |
CPP-61426 | [engine] instrumented compilation problem with QNX 8: cc1plus: error: to generate dependencies you must specify either -M or -MM |
CPP-61434 | [static] False positive for INIT-12 (CERTCPP-DCL56) on variable template instantiation with template parameter |
CPP-61471 | [compiler] Support for Clang 21 (Linux x86-64, arm64, Full, Extended) |
CPP-61473 | [static] CERT_CPP-DCL56-a (INIT-12) false positive at being not initialized |
CPP-61480 | [unit] Ignore compiler settings that may affect the expansion of the _FILE_ macro for unit testing and app monitoring |
CPP-61508 | [static] False positives of MISRACPP2023-7_0_6-b with different representations of the same type |
CPP-61512 | [static] False Positive of PB-23 on std::get_time Usage |
CPP-61525 | [static] GLOBAL-ONEUSEVAR [AUTOSAR-M0_1_4-a] potential false positive on variable used as template parameter default value |
CPP-61529 | [compiler] Support for IAR ANSI C/C++ Compiler V9.50.3 /LNX for ARM BX Functional Safety edition (Linux, Full, Extended) |
CPP-61549 | [compiler] Improve support for '-msection-asm-name' option for tricoregcc_4_9 compiler |
CPP-61572 | [docs] Incorrect Links in C/C++ Test Documentation |
CPP-61575 | [static] Rule OPT-30 reports false positive on global function declared as friend in template class |
CPP-61576 | [static] CODSTA-MCPP-53 (MISRACPP2023-28_6_1-a) reports false positive on std::move from <algorithm> library |
CPP-61589 | [engine] error: expression must have a constant value |
CPP-61592 | [static] MISRACPP2023_7_11_1-a False Positive |
CPP-61606 | [docs] Link for Supported Linux Compilers is Blocked |
CPP-61620 | [static] MISRA2004-19_10 (MISRACPP2023-19_3_4) improvements for case when parameter of function-like macro is used as template parameter |
CPP-61654 | [engine] Error: expression must have a constant value (clang) |
CPP-61657 | [engine] 'expected a ">"' parse error (symbol incorrectly treated as template) for clang compilers |
CPP-61674 | [static] TEMPL-13 (MISRA2008-14_5_1) reports false positives on non-generic functions |
CPP-61678 | [engine] cpptestcc internal error: assertion failed at: "interpret.c", line 26987 in interpret_constexpr_ctor |
CPP-61688 | [static] CODSTA-CPP-78 (MISRA2008-9_3_3) reports false positive on function containing lambda with a call to non-const function |
CPP-61689 | [static] CODSTA-303 (MISRACPP2023-6_4_1-g) FP for 'using'-declarations |
CPP-61690 | [engine] internal error: assertion failed: find_local_static_variable_init: none found for specified variable and scope (il.c, line 17226 in find_local_static_variable_init) |
CPP-61700 | [static] MRM-34 (CERT_CPP-MEM52-a) reports false positive on placement new |
CPP-61719 | [compiler] MSVC: "/Zc:strictStrings-" not being recognized |
CPP-61720 | [static] False positive MISRA2008-8_5_2 Default initialization of struct member results in warning |
CPP-61816 | [bazel] Include "implementation_deps" when tracking dependencies |
CPP-61831 | [compiler] Improve support for align8 option for gharm_2022_1+ compilers |
CPP-61868 | [compiler] TI CCS 9 tic2000_18_1 - C/C++test preprocessor command option -fe conflicts with user option -eo* |
CPP-61869 | [static] CODSTA-MCPP-04 False Positive for 'decltype' on struct member |
FA-10463 | BD-PB-OVERFARRAY incorrectly reported x2 when violation occurs in the function argument |
FA-10472 | BD-PB-VOVR false positive - no information about use of a const pointer variable initialized with another const |
FA-10501 | Missing modeled error information for VxWorks-7 MT locking APIs |
FA-10513 | BD-PB-OVERFWR false positives for some function calls taking buffer pointer casted to a void pointer |
FA-10518 | Inconsistent assumptions about possible values of local static variables |
FA-10563 | Missing semantic model for strnlen function causes inaccurate results |
FA-10646 | Division by floating-point zero should not change the value of the divisor to the unknown value. |
FA-10676 | BD-PB-CC bogus violation on struct passed to memcpy function |
FA-10677 | MISRACPP2023-28_6_3-b (BD-PB-SUBSEQMOVE) false positive when std::move has been called on the temporary copy |
XT-33967 | Review and improve "Findings per rule" filter. |
Resolved Bugs and FRs in 2026.1.3
Bug/FR ID | Description |
|---|---|
CPP-62427 | [engine] Bad default function arguments reconstruction for Clang-based compilers |
CPP-62430 | [engine] Parsing problem with gcc v11: assertion failed |
CPP-62524 | [engine] Parse error: constexpr constructor must initialize direct base class |
CPP-62594 | [static] GLOBAL-UNIQUETYPEDEFC and GLOBAL-UNIQUETYPEC violations depends on source files order during analysis. |
CVE-2026-8763 | Critical vulnerabilities resolved by upgrading bc-fips to 2.1.3 |
CVE-2026-59638 | Critical vulnerability resolved by upgrading bctls-fips to 2.1.24 |