[go: up one dir, main page]

Introducing G2.ai, the future of software buying.Try now
Aikido Security
Sponsored
Aikido Security
Visit Website
Product Avatar Image
Klocwork

By Perforce

Aikido Security
Sponsored
Aikido Security
Visit Website
It's been two months since this profile received a new review
Leave a Review

Klocwork Reviews & Product Details

Klocwork Product Details
Profile Status

This profile is currently managed by Klocwork but has limited features.

Are you part of the Klocwork team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Value at a Glance

Averages based on real user reviews.

Perceived Cost

$$$$$
Aikido Security
Sponsored
Aikido Security
Visit Website
Product Avatar Image

Have you used Klocwork before?

Answer a few questions to help the Klocwork community

Klocwork Reviews (23)

Reviews

Klocwork Reviews (23)

4.4
23 reviews

Search reviews
View Filters
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
April M.
AM
Technology Integration Safety Intern
Small-Business (50 or fewer emp.)
"Klocwork Review"
What do you like best about Klocwork?

There are a lot of built-in checkers that were helpful. There are so many of them, and they are all very well documented, so using them was straightforward. Creating checkers was also easy because they have a guide on getting started and links that explain the different checkers. Customer support always got back to me quickly. There is an entire library of information on the portal. If you need help or information it's probably already documented and it's easy to find. Review collected by and hosted on G2.com.

What do you dislike about Klocwork?

At first, getting started was confusing. I wasted a lot of time trying to set up and install. It was much easier and faster when I had a link to a setup/install guide. Review collected by and hosted on G2.com.

CW
Software Assurance Tools Program Manager/Static Analysis Domain Expert
Mid-Market (51-1000 emp.)
"Klocwork is a very mature, robust and helpful static code analysis tool"
What do you like best about Klocwork?

Klocwork does a really good job of finding the most critical defects. The incremental build capabilities to compare results between different versions of the software is very helpful. The web review interface is intuitive and supports effective review of any analysis results. Review collected by and hosted on G2.com.

What do you dislike about Klocwork?

It would be great to have continued improvements in creating possible custom checkers tailored to your specific software under analysis. It would also be helpful to provide even more robust export and reporting capabilities for the results so that we can more readily incorporate analysis results into other business processes where appropriate in the organization. Review collected by and hosted on G2.com.

MN
Expert SW integration and toolchain
Small-Business (50 or fewer emp.)
"Static code analysis fit for modern CI/CD"
What do you like best about Klocwork?

Klocwork helps us to analyze source code against coding standards like MISRA C as well as standards like CVE which we look forward to use for cyber security analysis. Klocwork also integrates well with our CI/CD toolchain and provides nice integrations with popular IDE's. But most importatnly perhaps is the awesome support and quick feedback Perforce provides to the customers. Review collected by and hosted on G2.com.

What do you dislike about Klocwork?

Perforce could improve the REST API. More functions to allow creation of projects and other administrative tasks, which are done with the kwadmin tool for us to improve automation even further. A docker container on docker hub would also be nice to get. Review collected by and hosted on G2.com.

DP
Senior Firmware Engineer
Enterprise (> 1000 emp.)
"Great tool for static analysis on embedded projects"
What do you like best about Klocwork?

The provided tools, documentation, and support make static analysis report creation an easy task. Also, the MISRA C checkers add to get complete reports fulfills customer requirements. With the Klocwork reports, we have been able to prevent and fix critical issues, and improve our source code. Review collected by and hosted on G2.com.

What do you dislike about Klocwork?

I consider that the report creation can be improved. Being able to customize better which data and charts are added. The report can be obtained on PDF format, but this document does not include detailed information about the build. Review collected by and hosted on G2.com.

Verified User in Defense & Space
ED
Small-Business (50 or fewer emp.)
"Leading with Cyber Excellence using Klocwork"
What do you like best about Klocwork?

A complete solution, desktop, server, API, reports, compliance tailoring, CI/CD integration with JIRA, JENKINS and Github. The support team is the best! Review collected by and hosted on G2.com.

What do you dislike about Klocwork?

A narrow set of computer languages supported, out-of-the-box works but can result in false positives or false negatives if not configured correctly. Review collected by and hosted on G2.com.

Verified User in Automotive
CA
Mid-Market (51-1000 emp.)
"Klocwork review"
What do you like best about Klocwork?

Included links to how to fix found issues. Review collected by and hosted on G2.com.

What do you dislike about Klocwork?

Inexistent traceability of developer's issue suppression from their desktop. The way of working proposed by Klocwork is to have dedicated team that reviews suppressions but this becomes a bottleneck when this team needs to overwatch many small embedded projects. Therefore in such situation everyone gets allowed to suppress issues in order to maintain development agility. This in turn leads to people suppressing issues without discussing them with a peer programmer. With the possibility to trace that an issue was suppresed by a developer from the desktop it would help discover issues that were suppressed despite they should not been suppressed.

It is a good feature to be able to configure that the issues can be suppressed from the portal only but it is not possible today to configure the tool to hinder developers suppressing issues from the desktop tool. Review collected by and hosted on G2.com.

Response from Steve Howard of Klocwork

Dear Reviewer.

Thank you for taking the time to review Klocwork.

Klocwork will actually trace all defects throughout the codebase and even suppressions made on the desktop, PROVIDED that you 'connect' those local desktop projects in the developer IDEs or on the command line, etc. to the central server project for the Master branch, etc. Once you are using 'connected' local projects, all status changes made by the developers on their local feature branches will be stored within the Klocwork defect database and tracked with a full audit trail of who made the change, when and why.

It is also possible, using the granular Klocwork permissions structure to setup a compliance workflow, whereby different project personnel (developers, QA, build engineers) have different permissions in terms of moving the defects between states. i.e. you can require that only QA team members have the right to change a status from, say 'defer' (indicating a deviation request) to 'ignore' (indicating a deviation approval'). This means that you won't then suffer with the problem you mention that this "leads to people suppressing issues without discussing them".

It additionally means that when you get into the release stream for the project, you will know that all deviations to the required standard (e.g. MISRA) have already been approved by QA through the cycle and the generated standards compliance reports will be correct and ready for certification, so no further review are required, saving time.

I hope this is useful information but please feel free to raise a support ticket via the portal should you encounter further issues.

Kind regards

Steve

See how Klocwork improved
Verified User in Defense & Space
AD
Mid-Market (51-1000 emp.)
"Using Klockwork as our main static code analysis tool."
What do you like best about Klocwork?

Build a successful product by minimizing code issues at any stage of development. Modern UI, Quality Gates. We can manage each project's configuration and rules. Also, KW taxemonics has a lot of built-in known ones. Review collected by and hosted on G2.com.

What do you dislike about Klocwork?

The web UI looks and feels outdated, and the scanner on the build machine does not return a non-zero value when project rules are not met. Review collected by and hosted on G2.com.

Verified User in Industrial Automation
AI
Small-Business (50 or fewer emp.)
"Good practice for static code review, not so easy to use"
What do you like best about Klocwork?

inline analisys of C++ code directly from Eclipse. Review collected by and hosted on G2.com.

What do you dislike about Klocwork?

unprofiled Visual Studio plugin, that let VS crash quite often. Review collected by and hosted on G2.com.

Vikash K.
VK
Validation, Quality, DevOps, SW Legal compliance, SW Security & Cloud Performance
Enterprise (> 1000 emp.)
"Klocwork has improved our code quality. Checkers have kept our code quality at very high note."
What do you like best about Klocwork?

Wide range of checkers. valuable issue segregation and easy report visibility for all type is issues/warnings. User friendly commands for building and analysis. Awesome commands to automate klocwork scan activities. It integrates with CI/CD tools, containers, cloud services, and machine provisioning making automated security testing easy. Security Standards: CWE, OWASP, CERT, PCI DSS, DISA STIG, and ISO/IEC TS 17961.

It analyzes source code in real time, simplifies peer code reviews, and extends the life of complex software. Review collected by and hosted on G2.com.

What do you dislike about Klocwork?

Only few programming languages are supported. Few more security checks required. strong filtering and report analysis features required. would like to see better codes between projects and a more user-friendly desktop in the next release. Issue we have is that whenever we need to get the code we have to build it first. Then we can get the report. I would like to see a dashboard added to provide a clear look and feel. The dashboard would then supplement the users to enable them to get a quick view of the content, as long is it is clear. A presentational dashboard would be good. Review collected by and hosted on G2.com.

Verified User in Defense & Space
UD
Mid-Market (51-1000 emp.)
"klockworks is great"
What do you like best about Klocwork?

It's easy to use and customize to flag just the items you will to catch. Also you can omit files you know have issues (lots of time commercial software you don't want to change) Review collected by and hosted on G2.com.

What do you dislike about Klocwork?

Nothing really its so easy to use. We use it to catch potential coding errors Review collected by and hosted on G2.com.

Pricing

Pricing details for this product isn’t currently available. Visit the vendor’s website to learn more.

Klocwork Comparisons
Product Avatar Image
SonarQube
Compare Now
Product Avatar Image
Coverity
Compare Now
Product Avatar Image
Checkmarx
Compare Now