8 ms·
FindBugs project in its current form is dead
- riffraff 10y agoThis is sad, I've enjoyed using findbugs when I was doing java. Fingers crossed that this can lead to a rebirth of the project.
- dangoldin 10y agoWhat a shame - it caught a few bugs in my code and has definitely made me a better programmer. One of the reasons is that the code is hard to maintain with most open source contributions being small improvements. How have other open source projects handled large scale refactors? Is it as simple as someone creating something new from scratch and then duplicating functionality? Are there examples of large open source projects that have had ground up rewrites?
- gst 10y agoThe nice thing about FindBugs is that you can, e.g., automatically run it in a Jenkins pipeline. Just for ad-hoc analysis in Java IntelliJ's code inspector IMO works quite well. It's also available in the community edition, so all of that code is open source: https://www.jetbrains.com/help/idea/2016.2/code-inspection.html https://www.jetbrains.com/help/idea/2016.2/code-inspection.h...
- pdexter 10y agoGHC has had a few major rewrites of key components.
- stefs 10y ago> Are there examples of large open source projects that have had ground up rewrites? well, netscape navigator turned into firefox. it cost them dearly (in terms of market share), but there wasn't much of an alternative (joel spolsky might not agree on that).
- wtracy 10y agoArguably two major rewrites: one early in the life of the Mozilla project, when the FOSS community deemed the original Netscape code dump to be nearly unmaintainable, and the second during the creation of Firefox itself (although that was mostly a re-do of the browser chrome, while the core was left untouched).
- batbomb 10y agoIt was Phoenix -> Firebird -> Firefox.
- icebraining 10y agoThose were just name changes, the rewrites were Netscape → Mozilla Suite → Phoenix/Firebird/Firefox.
- nickpsecurity 10y agoA million downloads, commercial deployments by 3rd parties, and basically no contributions coming in. The status quo of the open-source model. They should start selling it to companies to finance their own work on it. Or encourage others interested in static analysis to do the same.
- pjmlp 10y agoThis is what kind of changed my view on FOSS as a way to make a living. In all the companies I have worked through my career thus far, not a single one has contributed back in any form to the pile of FOSS libraries that they were using.
- jknoepfler 10y agoAs with insistence on code quality, useful and careful testing, infrastructure automation, and good design and review practices, I think the culture of giving back has to come from developers who care about their professional ethos. My team at EvilCorp contributes fixes to several open-source libraries. The reason this happens, though, is that two of our stronger devs said "the correct thing to do is to take the time to get these fixes into mainline," which they did. The answer to the question of "why" we do it isn't "because it increases our team velocity," but because we're software engineers, and that's what good software engineers do whenever possible.
- pjmlp 10y ago> I think the culture of giving back has to come from developers who care about their professional ethos. On my case that would be the path to be fired. In none of the companies I worked for, doing that would work without going though legal and all the necessary layers to green light it.
- pm215 10y agoYou definitely can't skip the step of getting managerial and legal signoff (and no sensible open source project wants a patch that the developer doesn't have the right and authorisation from the employer to contribute). But in better companies it is possible to make that case and get the agreement.
- sdegutis 10y agoInterestingly, the spirit of the FindBugs project lives on in the development of languages like Rust and Swift, considering the purpose of the FindBugs project is to fix inherent flaws in Java, e.g. not having a way to determine whether something will be null, or not telling you whether you checked whether something will be null at runtime, etc.
- surfmike 10y agoClang static analyzer is another great tool that didn't exist back then.
- scarmig 10y agoStatic analysis is not about fixing the "inherent flaws in Java." Findbugs does help mitigate issues from language design, but most things that it does would be silly to try to figure out a way to bake into the language itself. http://findbugs.sourceforge.net/bugDescriptions.html http://findbugs.sourceforge.net/bugDescriptions.html
- amaranth 10y agoI think if you could say that about any language it'd be Kotlin. It seems to take all of the best practices guidelines from Java and just bake them in to the language.
- Afty 10y agoYou're getting some flack for this, but I agree with you based on what we've seen with Error Prone. The people who design programming languages are human, and they make mistakes. Unfortunately, if your language becomes successful, it becomes nearly impossible to fix these mistakes while retaining backwards compatibility. Many of our checks are essentially working around problems with the language or API design. For example, our ForOverride checker (http://errorprone.info/bugpattern/ForOverride http://errorprone.info/bugpattern/ForOverride) addresses the fact that existing Java visibility modifiers are not expressive enough for some things the Guava team wanted to do. Our HashtableContains checker (http://errorprone.info/bugpattern/HashtableContains http://errorprone.info/bugpattern/HashtableContains) addresses an issue with a poorly-named method in the old Hashtable API, which really should be deprecated but is infeasible given the old code that uses it.
- mabbo 10y agoWhat a shame. I work for a fortune 100 company that enables findbugs on all projects by default. I cannot fathom how many serious issues it's prevented.
- deleted 10y ago[deleted]
- timruffles 10y agoCould you ask the company to help out?
- mabbo 10y agoYeah, they aren't really big on the 'contributing to open source' thing.
- mikecb 10y agoThey're about to lose a valuable tool that they'll have to pay money to replace anyhow. It's not hard to make a business case for.
- analognoise 10y agoYou're assuming they're rational actors. They aren't - at some places (big defense) it's easier to get tens of thousands of dollars of software and compute resources than it is to get OSS approved.
- justin66 10y agoI don't have a Twitter account, so maybe I'm missing something about the difficulty here. But the author spent paragraphs describing how the fate of this major thing is largely in the hands of Bill Pugh, he can't reach Bill Pugh via email, maybe his email is expired, etc. etc. can someone please help contact him via phone or twitter or whatever? Why not just create a twitter account and do it yourself? WTF? edit: presumably one of the downvoters is working right this minute to contact Bill Pugh via Twitter and put him in touch with the author, because that totally makes sense
- deleted 10y ago[deleted]
- aardvark179 10y agoI think the problem is that there are numerous ways to contact him, he's just not replying (or not to the current findbugs committers).
- raphman 10y agoApparently, some people have been trying this (but only after the e-mail was sent): https://twitter.com/search?f=tweets&vertical=default&q=%22%40wpugh%22&src=typd https://twitter.com/search?f=tweets&vertical=default&q=%22%4...
- Macha 10y agoNot the first attempt, see this one august 15: https://mobile.twitter.com/HaydenPJones/status/765286881181466626 https://mobile.twitter.com/HaydenPJones/status/7652868811814...
- unreal37 10y agoIf he's avoiding thinking about this, then it doesn't matter what the communications channel is except "in person" or "email from a close friend".
- wodencafe 10y agoBill actually replied to this HN thread.
- jknoepfler 10y agoFor those looking for an alternative, I've had reasonable success with PMD: https://pmd.github.io/ https://pmd.github.io/
- 80x25 10y agoPMD and FindBugs really complement each other: http://stackoverflow.com/questions/4297014/what-are-the-differences-between-pmd-and-findbugs http://stackoverflow.com/questions/4297014/what-are-the-diff...
- CraigJPerry 10y agoSonar, or SonarQube as it's called now, does need more initial config than findbugs. To get a liveable configuration anyway. Once setup though, the quality of analysis is absolutely outstanding.
- rompic 10y agoSonarlint on the client is nice as well.
- masklinn 10y agoI guess it depends on the language, or possibly the setup, the python projects I've been part of using SonarQube its reports were worthless busywork (e.g. requirements of docstrings to every method, resolved by adding """ fuck off sonar """ everywhere).
- michaelt 10y agoAt least with Java, SonarQube checkers can be individually turned on and off at the project level. Isn't that possible with Python?
- tom9729 10y agoIt's possible with all of the languages. Perhaps static analysis is just difficult with Python?
- icebraining 10y agoStatic analysis is certainly difficult in Python, but you can still do a lot better than "missing docstring".
- gaul 10y agoGoogle error-prone is a good alternative to FindBugs: https://github.com/google/error-prone https://github.com/google/error-prone http://errorprone.info/bugpatterns http://errorprone.info/bugpatterns Pros: * has faster cycle times and integrates into compilation workflow * emits fewer false positives * active maintainers fix issues * releases several times per year Cons: * FindBugs has a greater breadth of checks * current error-prone releases only work with Java 8
- justinsb 10y agoIt also seems to be automatically run automatically by bazel when building Java code, which was a pleasant surprise.
- nothrabannosir 10y ago> current error-prone releases only work with Java 8 I'm assuming that means it will only run on the JVM8, but it can analyze any version of Java code?
- jbangert 10y agoError-prone is somewhat tied to a specific version of the Java compiler -- so you need Javac 8, but you can set --source to an older version of the language. If the newer Javac does not emit bytecode that works with your runtime, you can run two compiles (one error-prone for the errors, one production compile with whatever compiler you need).
- needusername 10y agoHaven't we learnt several times in the past that this is a bad idea? Eg. with Android or GAE/J. This is going to require a lot of effort for every upcoming Java release delaying support for a long time, again see Android or GAE/J. It also makes integration with Eclipse difficult at best.
- Seol 10y ago
- aardvark179 10y agoThat's a real shame as I've found FindBugs to be much clearer in its output than many of the commercial offerings (some of which simply wrap FB's output). I hope they can get a new project off the ground and can start rebuilding. We're approaching a time where JVM static analysis tools are going to have to start making some big changes to support upcoming features, and it will be a pity if some version of FB or a successor isn't there.
- taeric 10y agoCoverity was rather impressive. It did merely wrap a subset of FindBugs errors, but that was mainly to show that they were adding to what FindBugs could do. The points of the code that they spotted were always much more clearly explained for why they were problems.
- mkobit 10y agoFurther on in the email chain, it looks like there is momentum for hard forking under another project named 'SpotBugs' [1, 2]. I hope to see the project live on as it has been useful. Other tools like Google's Error Prone and IntelliJ's inspection toolset are awesome, and FindBugs is complimentary to them. [1] https://mailman.cs.umd.edu/pipermail/findbugs-discuss/2016-November/004330.html https://mailman.cs.umd.edu/pipermail/findbugs-discuss/2016-N... [2] https://github.com/spotbugs/spotbugs https://github.com/spotbugs/spotbugs
- TD-Linux 10y agoSide note: "hard fork" has a special meaning for Bitcoin and derivatives, but no meaning for a software fork. I've seen that phrase used several times in the comments though - is this a new trend?
- mkobit 10y agoI'm not familiar with Block chain terminology, so I was not aware of the collision. A previous response in the thread [1] also contains "hard fork", which is probably why I and possibly others have repeated it here. It could be a trend, but my differentiation (here at least) is that a "hard" fork means that the maintainers themselves are splitting from the original project while also forking the original code base. It would probably make more sense to just call it a "fork" :). [1]: https://mailman.cs.umd.edu/pipermail/findbugs-discuss/2016-November/004329.html https://mailman.cs.umd.edu/pipermail/findbugs-discuss/2016-N...
- sam_lowry_ 10y agoCoverity makes a shitload of money off FindBugs. It's annoying they don't contribute back while my organisation pays their most expensive license.
- frugalmail 10y agoTalk them out of renewing and be sure to let the salesperson know that you don't appreciate their ethics. With all the alternatives it's not like you'll be left high and dry.
- achou 10y agoUm, Coverity contributes a lot to the open source community through Scan[1]. While Coverity does incorporate Findbugs results, it also has its own analyzer that does much more interprocedural analysis and tends to be tuned better for fewer false positives and more accurate error messages. Historically at least, part of the reason for incorporating Findbugs was to make it easier to directly compare what Findbugs found with what Coverity's analyzer found. Because every customer wanted to know that. I have no idea of current figures but historically Java was not a big business for Coverity. Other vendors had much more Java business (and incidentally also incorporated Findbugs results). Finally, as you can see from the message the Findbugs leadership does not seem unified and easy to collaborate with. So forgive me but I find your comment and its tone a bit unfair. [1] https://scan.coverity.com https://scan.coverity.com
- unreal37 10y agoI see you are the founder of Coverity. It might seem unfair, but you stated that "every customer wanted to know that". So that project has value to you.
- achou 10y agoI should be more clear: every customer using Java wanted to know how our custom developed analysis compared with what Findbugs could find. There weren't all that many such customers though (again, historically). A more typical customer was developing in C/C++.
- billpugh 10y agoFindBugs isn’t dead (although my participation had been in hibernation for a while). I’ve been juggling far too many projects, but I’m now working to move FindBugs back into the active rotation. I also want announce I'll be working with GrammaTech as part of the Swamp Project, and they will be helping with rebooting the FindBugs project. This has been in the works for a long time (almost a year), and although I’ve known that GrammaTech was likely to win an award, this hasn’t been official and something I could talk about until recently. Was hoping to have something a little more concrete to talk about as far as that goes; but I don’t yet have the information I wanted to share. Thanks to all the FindBugs fans and supporters who lobbied for me to return to active maintenance of FindBugs. Give me a week to get up to speed on current project needs. Bill Pugh
- unreal37 10y agoIt's still not a good sign that it took this level of public attention to get you to reply to the active community on their urgent needs.
- kinow 10y agoIndeed. Probably having more people with admin access would help making sure that the project's bus factor is greater than 1 :)
- dmuth 10y ago^ this. There is absolutely no reason to not be answering emails, even if to say, "I'm really swamped, and need help." I don't mean to denigrate you, but I must be candid here: hoarding admin rights so that only you have them and no one else can get any work done is simply not acceptable in a team environment. Going forward, I would recommend taking a look through other projects you may be involved with, and make sure that you are not the only person with admin access. If nothing else, it would increase the "bus factor" to greater than 1: https://en.wikipedia.org/wiki/Bus_factor https://en.wikipedia.org/wiki/Bus_factor Good luck.
- danielheath 10y ago
- pm215 10y agoIf you're an open source project that's expanded to more than a few people, it's worth going through and making a list of all the various "admin" items your project has accumulated (website? domain name? github? bug tracker? mailing lists? etc) and making sure that for each of them there are at least two people with admin rights and that how to add/remove admins is documented. People do drift away from open source projects (or get run over by the proverbial bus) and single points of failure can make things very awkward.
- smoyer 10y agoI'd like to echo the sentiment of everyone else here that would be sad to see the death of Findbugs - When the draft of JSR-305 was released, I was hoping to see an array of tools that would almost be "standardized" around the static code analysis annotations. I'm working on reviving that JSR and will see if I can chat with Dr. Pugh as well.
- nstj 10y agoI just had a quick look at the repo and I'm not particularly familiar with the project but what's the issue with just doing a hard fork if there are enough people who want this to keep going?
- rincebrain 10y agoThis is addressed in the link, but basically, the extant codebase is extremely crufty, to the point that a rewrite would be the suggested course forward (and, indeed, the other formerly-active major contributor started his own clean codebase to implement similar functionality). So one of the two active contributors left to start his own rewrite of the project, and this post is the other active contributor saying he definitely doesn't have enough time to keep doing this on his own. If there's no association with the old project's name or references from it to the new project, then whatever came from it would probably not use the name "FindBugs", and either way, the original project ends up dead.