What you are evaluating
Audit Workbench style review, false-positive handling, and the OpenText versus former Micro Focus contract and support path are operational boundaries. Language-list marketing does not prove the team's compiler and framework are modeled. Self-managed analysis is a reason teams still evaluate Fortify for regulated code.
A useful evaluation context
A plausible evaluation context is an organization with COBOL, ABAP, or other legacy languages that needs self-managed static analysis and a clear OpenText support path.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Static analysis with vendor-described breadth across languages and frameworks, including legacy languages such as COBOL and ABAP.
- Remediation assistance attached to static findings.
- Broader OpenText Application Security portfolio options for software-as-a-service and self-managed testing around the static analyzer.
Where it fits in the work
- Confirm the current contracting entity and OpenText support route, including how any former Micro Focus identifiers map to the agreement in use; do not infer a novation requirement from rebranding.
- Analyze a representative lab project in a language the team actually ships, especially if that language is legacy, and review findings with the team's audit process.
- Record false-positive handling and whether self-managed deployment is required before any cloud analysis.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
Run Fortify Static Code Analyzer on a lab project you own in a language the team cares about, including a seeded weakness. Use the self-managed or SaaS path that matches policy.
Evidence to look for
The seeded weakness is found or a modeling gap is documented, review notes capture any false-positive decision, and the evidence pack names OpenText as the current vendor.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Does the analyzer model this team's compiler, build options, and frameworks, not just list the language name?
- How are false positives reviewed and suppressed in the actual audit workflow?
- What remains of former Micro Focus contracts, and who supports the product under OpenText?
Names you may encounter: Fortify SAST · Micro Focus Fortify. Historical names do not establish current availability or feature equivalence.