- One place for all extensions for Visual Studio, Azure DevOps Services, Azure DevOps Server and Visual Studio Code. Discover and install extensions and subscriptions to create the dev environment you need.
- Develop secure software with the Fortify on Demand Visual Studio Extension. Developers can request static assessments, download results, collaborate with team members and remediate vulnerabilities - all within the IDE.
Develop secure software with the Fortify on Demand Visual Studio Extension. Developers can request static assessments, download results, collaborate with team members and remediate vulnerabilities.
HP Fortify SCA provides root-cause vulnerability detection through the most comprehensive set of secure coding rules available and supports the widest array of languages, platforms, build environments (Integrated Development Environments, or IDEs) and software component APIs.
- Conduct static analysis to pinpoint root causes of security vulnerabilities in source code
- Detect more than 480 types of software security vulnerabilities across 20 development languages—the most in the industry.
- Receive prioritized results sorted by severity of risk and guidance on how to fix vulnerabilities in line-of-code detail
- Ensure compliance with application security mandates
Hardware Requirements
HP Fortify Software recommends that you install HP Fortify Static Code Analyzer (SCA) on a high-end processor with at least 1 GB of RAM.
Platforms and Architectures
HP Fortify SCA supports the following platforms and architectures:
| Operating System | Architecture | Version | 
|---|---|---|
| Linux | x86: 32-bit & 64-bit | Fedora Core 7 Red Hat® ES 4, ES5 Novell SUSE 10 Oracle EL 5.2 | 
| Windows® | x86: 32-bit & 64-bit | 2003 SP1 2008 XP Vista Business Vista Ultimate Windows 7 | 
| Windows® | x86: 32-bit | 2000 | 
| Mac OS | x86 | 10.5, 10.6 | 
| Oracle Solaris | SPARC | 8, 9, 10 | 
| x86 | 10 | |
| HP-UX | PA-RISC | 11.11 | 
| AIX | PPC | 5.2 | 
| FreeBSD | x86: 32-bit | 6.3, 7.0 | 
Note: Audit Workbench and Secure Coding Plug-ins are not supported on HP-UX, IBM® AIX®, Oracle™ Solaris™, and Free BSD.
Note: The Secure Coding Package for Microsoft Visual Studio 2003 is not supported on Windows Vista or above.
International Platforms and Architectures
HP Fortify SCA supports double-byte and international character sets when installed on the following platforms:
| Operating System | Version | Architecture | 
|---|---|---|
| Linux | Red Hat® ES 5, Novell SUSE 10 Fedora Core 7 | x86: 32-bit | 
| Windows® | 2003 SP1 2008 Vista Business Vista Ultimate | x86: 32-bit | 
| Oracle Solaris | 10 | x86 | 
For non-English platforms, the following are NOT supported:
- OS: Windows 2000, HP-UX, IBM AIX, Macintosh OS X, Oracle Solaris SPARC, and all 64-bit architecture
- Application Servers: Jrun, jBoss, BEA Weblogic 10
- Database: DB2
Note: No localized documentation is included in this release.
Languages
HP Fortify SCA supports the following programming languages:
| Language | Version | 
|---|---|
| ASP.NET, VB.NET, C# (.NET) | 1.1, 2.0, 3.0, 3.5 | 
| C/C++ | See 'Compilers' | 
| Classic ASP (with VBScript) | 2 / 3 | 
| COBOL | IBM Enterprise Cobol for z/OS 3.4.1 with IMS, DB2, CICS, MQ | 
| CFML | 5, 7, 8 | 
| HTML | 2 | 
| Java | 1.3, 1.4, 1.5, 1.6 | 
| JavaScript/AJAX | 1.7 | 
| JSP | JSP 1.2 / 2.1 | 
| PHP | 5 | 
| PL/SQL | 8.1.6 | 
| Python | 2.6 | 
| T-SQL | SQL Server 2005 | 
| Visual Basic | 6 | 
| VBScript | 2.0 / 5.0 | 
| ActionScript/MXML | 3 and 4 | 
| XML | 1.0 | 
| ABAP/4 | 
| Build Tools | Version | 
|---|---|
| Ant | 1.5.x, 1.6.x, 1.7.x | 
| Maven | 2.0.9 or later | 
Hp Fortify Visual Studio 2015
Compilers

HP Fortify SCA supports the following compilers:
| Compilers | Operating System | 
|---|---|
| GNU gcc 2.9 – 4 | AIX, Linux, HP-UX, Mac OS, Solaris, Windows | 
| GNU g++ 3 – 4 | AIX, Linux, HP-UX, Mac OS, Solaris, Windows | 
| IBM javac 1.3 – 1.6 | AIX | 
| Intel icc 8.0 | Linux | 
| Microsoft cl 12.x – 13.x | Windows | 
| Microsoft csc 7.1 – 8.x | Windows | 
| Oracle cc 5.5 | Solaris | 
| Oracle javac 1.3 – 1.6 | Linux, HP-UX, Mac OS, Solaris, Windows | 
Fortify Plugin For Visual Studio
Integrated Development Environments
The HP Fortify Software Security Center Plug-in for Eclipse and HP Fortify Software Security Center Package for Visual Studio are supported on the following platforms:
| Operating System | IDE | 
|---|---|
| Linux | Eclipse 3.2, 3.3, 3.4, 3.5, 3.6 RAD 7, 7.5 RSA 7, 7.5 JBuilder 2008 R2 JDeveloper 10.1.3, 11.1.1 | 
| Windows | Eclipse 3.2, 3.3, 3.4, 3.5 Visual Studio 2003, 2005, 2008,2010 RAD 6, 7, 7.5 RSA 7, 7.5 JBuilder 2008 R2 JDeveloper 10.1.3, 11.1.1 | 
| Mac OSX | Eclipse 3.2, 3.3, 3.4, 3.5, 3.6 JBuilder 2008 R2 JDeveloper 10.1.3, 11.1.1 | 
Note: HP Fortify Software Security Center does not support Eclipse 3.4+ running on a 64-bit JRE. However, HP Fortify Software Security Center does support 32-bit Eclipse running on a 32-bit JRE on a 64-bit platform.
Third-Party Integrations
HP Fortify Audit Workbench and Secure Code Plug-ins (SCP) support the following service integrations:
| Service | Application | Version | Supported Tool | 
|---|---|---|---|
| Bug Creation | Bugzilla | 3.0 | Audit Workbench, Visual Studio SCP, Eclipse SCP | 
| HP Quality Center | 9.2, 10.0 | Audit Workbench, Eclipse SCP | |
| Microsoft Team Foundation Server | 2005, 2008,2010 | Visual Studio SCP | 
Note: HP Quality Center integration requires that you install Audit Workbench and/or the Secure Code Plug-in for Eclipse on a Windows platform.
Note: HP Quality Center integration requires you to install the HPQC Client-Side Add-in software.
Note: Team Foundation Server integration requires you to install the Visual Studio Team Explorer software.