
CodeSonar Version 9.0 Available
(Bethesda/USA, Offenburg/Germany, 25 March 2025)
CodeSecure has released version 9.0 of its static code analysis tool, CodeSonar.
The focus of this release is a significant performance improvement in the MISRA analysis, enabling analyses that previously took several hours to be completed in less than 30 minutes. Additionally, the coverage of the MISRA C 2023 standard has been increased to 97%, and the coverage of the AUTOSAR 14 standard has also been improved. Android 14 and 15 are now supported as well.
CodeSonar 9.0 can now be installed via a secure Docker registry hosted by CodeSecure. Alternatively, customers can download Docker images from "Ironbank," a registry for secure images operated by the U.S. Department of Defense. Furthermore, the compiler models for IAR and QNX have been adapted to new features of these compilers.
Another highlight is the enhancement of the DISA STIG report in CodeSonar Hub, which now includes a summary of results along with explanatory texts for each warning.

Static Code Analysis: CodeSonar Version 8.3 Available
(Bethesda/USA, Offenburg/Germany, 16 Dezember 2024)
CodeSecure has released version 8.3 of the static Code Analysis Tool CodeSonar. The focus of this release was upgrading our Java and C# analysis, improved reporting, and upgrades to our QNX and GGC compiler models.CodeSonar 8.3 supports Java 21 and 22. This also makes it possible to analyse the new language functions.
The check for compliance with the MISRA C 2023 standard has been further improved. CodeSonar 8.3 supports version 14 of the GCC compiler.

CodeSonar 8.2: New Version with Enhanced Analysis Features Now Available
(Bethesda/USA, Offenburg/Germany, 22 August 2024)
CodeSecure Inc. has released the latest version of their software, CodeSonar 8.2.This edition introduces important new features and improvements:
- Expanded Language Support: Python warnings have received references to the CWE standard. Corresponding mappings are in preparation for Kotlin, Go, Rust and JavaScript. Java warnings have also been aligned with the CWE 660 vulnerability.
- .NET 8.0 C# Analysis: The new version now supports .NET 8.0 C# analyses.
- New Floating-Point Overflow Checker : Detects overflows in floating-point operations.
- Improved Coding Standards: Coverage of the MISRA C 2023 and JSF++ coding standards has been improved.
- Integration with Gerrit Code Review: Facilitates collaboration in large teams.
- Expanded Compiler Support: Including Keil C251, MPLAB C30, and the latest versions of GCC 13 and clang 18.
- New Filtering Options in CodeSonar Hub: The option of filtering warnings relating to standards has been introduced.
Customers with an existing license can simply upgrade to the new version to take advantage of these enhancements.

CodeSonar 8.1 Available: All-In-One SAST Platform with Expanded Language Support
(Bethesda/USA, Offenburg/Germany, 4 April 2024)
CodeSonar language coverage now includes Kotlin, Python, Go, Rust, JavaScript, and TypeScriptCodeSecure today announced a major new release for CodeSonar, the leading SAST platform for securing product software. CodeSonar 8.1 extends the developer centric approach for product security to include language support for Kotlin, Python, Go, Rust, JavaScript, and TypeScript in addition to C/C++, Java and C#.
CodeSonar supports now more than 90 compilers, including clang, GCC, Microsoft, IAR, Tasking, QNX, WindRiver.
WRth hundreds of built-in checkers, CodeSonar examines code for potential vulnerabilities, coding errors, and compliance violations. From memory leaks to buffer overflows, CodeSonar’s advanced static analysis capabilities help identify issues early in the development cycle, saving time and resources in the long run.
Host Platforms: Whether you prefer cloud-based solutions or on-premises deployment, or fully air-gapped environments, CodeSonar offers flexible host platform options to suit your needs.
Learn more about multi language support in our video.

Static Analysis: CodeSonar 8.0 Available
(Bethesda/USA, Offenburg/Germany, 22 November 2023)
CodeSecure has released version 8.0 of the static code analysis tools CodeSonar. The focus of this release was increasing the coverage for coding standards, re-certifying the development process, and building the integrations. CodeSonar 8.0 has new branding, as well as numerous bug fixes, compatibility updates, and other improvements.Here are some more details on the improvements:
- Integrations: Jira Server, Gerrit (beta, full integration will be available in 8.1.).
- 50% coverage of the new MISRA C 2023 standard (100% coverage of MISRA C 2023 will be available in 8.1.).
- SANS 25 2023 support.
- CodeSonar Hub: Improved Single Sign-on to support the latest versions of Chrome, Edge, Firefox, and Safari.
- Certification for use in ISO 26262 ASIL D, IEC 61508 SIL4, and EN 50128 SIL4 projects.
- Hybrid SaaS improvements include improved support for AWS load balancers and more robust behavior if worker tasks stall, increasing the reliability and scalability CodeSecure's Hybrid SaaS solution for large and small customers.

GrammaTech’s Application Security Testing Software Business sold to Battery Ventures
(Bethesda/USA, 5 September 2023)
Our partner GrammaTech today announced that Battery Ventures has acquired its software products division, including the CodeSonar and CodeSentry product lines. The transaction establishes a new, independent entity that will operate under the CodeSecure, Inc. name and be headquartered in Bethesda, Maryland.GrammaTech will continue to offer cyber security research and development services and tools to the US defense and intelligence community.
Further information is available on the CodeSecure website

Static Analysis: GrammaTech CodeSonar 7.4 Available
(Ithaca/USA, Offenburg/Germany, 28 July 2023)
GrammaTech has released version 7.4 of CodeSonar. The new version increases the coverage for coding standards valued by aerospace and defense customers. CodeSonar now offers coverage of the JSF++ standard. In addition, the rule coverage in our Functional Safety (FUSA) kit has been increased. Improvements to the Hybrid SaaS installer means that customers are supported that want to manage a SaaS instance themselves.Here are some more details on the improvements:
- JSF++ support.
- Expanded coverage in the Functional Safety (FUSA) kit.
- Support for building with Bazel.
- New rules to support MISRA C 2023.
- Support for Android 13.
- C# and Java analysis is now fully supported in Hybrid SaaS.
- Self-managed Hybrid SaaS deployment option for customers.
- Refreshed CodeSonar for Binaries to find errors in a program, without needing to look at the code that was used to build it.

GrammaTech has released CodeSonar 7.3
(Ithaca/USA, Offenburg/Germany, 11 April 2023)
The focus of this releases was increasing our coverage for coding standards. CodeSonar now covers 100% of the MISRA C 2012 rules. We have improved and simplified our instructions for integrating CodeSonar with GitHub or GitLab, which will make it easier for our customers to adopt CodeSonar. Improvements to compiler models, support for the .NET7 framework and the latest versions of C and C++, and improvements to Hybrid Cloud round out the highlights of the release.CodeSonar for Binaries is also refreshed. Being able to find errors in a program, without needing to look at the code that was used to build it.
