Skip to main content
Author headshot

Stuart Foster

Klocwork and Helix QAC Product Manager

Latest Content from Stuart Foster

Blog

What Is CVE? Common Vulnerabilities and Exposures Overview

The most trusted and complete list of software security vulnerabilities is the Common Vulnerability Exposures (CVE) list. Here, we explain what is the CVE list and how it can help ensure that your software is secure.
Security & Compliance, DevOps
Blog

What Is CERT? Overview of CERT and CERT Secure Coding

It is essential that you use a secure coding standard — like CERT— to ensure that your software is protected against potential security vulnerabilities. Here, we explain what is CERT C and why CERT secure coding is important.
Security & Compliance, Software Quality
Blog

What Is CWE? Overview + CWE Top 25

One of the most efficient and effective ways to safeguard your code against potential vulnerabilities is to use secure coding practices — like CWE. Here we explain what is CWE and the CWE Top 25.
Security & Compliance, Software Quality
Blog

What Are Machine Learning Uses to Improve Static Analysis?

As code is being written, static analysis tools — such as Helix QAC and Klocwork — identify coding defects, vulnerabilities, and compliance issues. However, static analysis can also produce a great deal of results, and depending on your perspective and goals, not all results will be relevant or interesting in all cases. Here, we explain three machine learning uses to help improve the relevance of static analysis results.
DevOps
Blog

What Is IEC 62443? Overview + Security Levels

Get an overview and security level of IEC 62443 and how to comply with the IEC 62443 standard.
Security & Compliance, Software Quality
Blog

Top 10 Software Vulnerabilities

Software vulnerabilities impact software performance and security. Here we offer vulnerabilities definition and guidance on how to prevent the top 10 most common software vulnerabilities.
Security & Compliance, Software Quality
Blog

How to Use DevSecOps Automation for Safety-Critical Software Development

Get an overview of DevSecOps automation.
DevOps
Blog

What Is EN 50128?

EN 50128 is a functional safety standard tailored for the particular demands of the rail industry. It’s titled “Railway applications — Communication, signaling, and processing systems — Software for railway control and protection systems”.
Software Quality, Security & Compliance
Blog

Why Eclipse Iceoryx Uses Helix QAC

It’s important that automotive software developers have safe inter-process communication for autonomous cars, which is why Eclipse Iceoryx was developed. And, why Eclipse Iceoryx chose to use Helix QAC to help ensure that autonomous vehicle software is safe and high quality.
DevOps, Security & Compliance