industry news
Subscribe Now

GrammaTech Releases CodeSonar 4

ITHACA, N.Y., April 3, 2014 /PRNewswire/ — GrammaTech, Inc., a leading maker of tools that improve and accelerate embedded software development, today announced the commercial availability of CodeSonar 4, the latest version of the company’s flagship software analysis tool for C/C++, Java, and machine code. Designed to meet the growing challenges of embedded app developers, CodeSonar 4 includes new capabilities for analyzing third-party code, achieving standards compliance, eliminating challenging multi-core issues, and improving code security by addressing dangerous information flows. CodeSonar advances the state of the art in automated code analysis to help embedded development teams improve code quality and security while accelerating time-to-market.

“The cost of failure in embedded systems is unlike that of any other industry due to the safety-critical role they play in our everyday lives – which is a main reason organizations who build embedded applications are early adopters of automated advanced code analysis tools like CodeSonar,” said Andre Girard, Senior Analyst at VDC. “Teams that leverage innovative technology to tackle the pressing challenges of embedded software development today such as the use of third-party code, compliance with standards, and the complexity of concurrency can realize significant business and competitive advantages.”

Designed for zero-tolerance defect environments, CodeSonar analyzes binary code and source code, to identify serious security and quality liabilities that cause system crashes, memory corruption, leaks, data races, and other unexpected vulnerabilities. New advances in CodeSonar 4 address:

  • Software Supply Chain Risk Management (SCRM) – New Integrated Binary Analysis in CodeSonar 4 empowers developers to analyze externally produced software without access to its source code. This eliminates the dangerous quality and security blind spots created by using open source or third-party components and libraries in embedded applications.
  • Standards Compliance – The increasing regulation of embedded software in the form of industry-specific standards for code quality/security continues to gain international momentum. CodeSonar 4 will include built-in analysis for MISRA C 2012, in addition to existing DO-178 analysis capabilities, to help organizations pursue and achieve relevant certifications.
  • Multi-Core Development – With growing usage of multi-core processors and greater dependence on multi-threaded software, CodeSonar 4 delivers new Java-specific concurrency defect detection capabilities to defend against errors like race conditions, deadlocks, and livelocks.
  • Embedded Security – As networking and internet-enabled capabilities continue to proliferate within embedded systems, the attack surface of traditionally isolated applications has expanded in new and unpredictable ways. In addition to robust existing security features, the new visual tainted-data analysis capability in CodeSonar 4 helps developers find and eliminate vulnerabilities caused by potentially dangerous information flows.

“CodeSonar 4 is the automated code analysis tool designed specifically for the rigorous security and quality demands of embedded software,” said Paul Anderson, Vice President of Engineering at GrammaTech. “CodeSonar 4 will address the most complex challenges facing embedded developers by using new analysis capabilities to eliminate the most costly and hard to find defects early in the application development lifecycle.”

To learn more about how CodeSonar 4 accelerates, improves, and secures the production of embedded software, download GrammaTech’s new white paper ‘Embedded Software Design: Best Practices for Static Analysis Tools.’

About GrammaTech: 

GrammaTech tools are used by software developers worldwide, spanning a myriad of embedded software industries including avionics, government, medical, military, industrial control, and other applications where reliability and security are paramount. Originally developed within Cornell University, GrammaTech is now a leading research center for software security and a commercial vendor of software-assurance tools and advanced cyber-security solutions. With both static and dynamic analysis tools that analyze source code as well as binary executables, GrammaTech continues to advance the science of superior software analysis, providing technology for developers to produce safer software. To learn more about GrammaTech, visit www.grammatech.com.

Leave a Reply

featured blogs
Apr 24, 2026
A thought experiment in curiosity, confusion, and cosmic consequences....

featured paper

Quickly and accurately identify inter-domain leakage issues in IC designs

Sponsored by Siemens Digital Industries Software

Power domain leakage is a major IC reliability issue, often missed by traditional tools. This white paper describes challenges of identifying leakage, types of false results, and presents Siemens EDA’s Insight Analyzer. The tool proactively finds true leakage paths, filters out false positives, and helps circuit designers quickly fix risks—enabling more robust, reliable chip designs. With detailed, context-aware analysis, designers save time and improve silicon quality.

Click to read more

featured chalk talk

Analog Output, Isolated Current, & Voltage Sensing Using Isolation Amplifiers
Sponsored by Mouser Electronics and Vishay
In this episode of Chalk Talk, Simon Goodwin from Vishay and Amelia Dalton chat about analog output, and isolated current and voltage sensing using isolation amplifiers. Simon and Amelia also explore the fundamental principles of current and voltage sensing and the variety of voltage and current sensing solutions offered by Vishay that can get your next design up and running in no time.
Apr 27, 2026
20 views