3 ms·
We at rsyslog use it as part of our CI pipeline. It's a pretty cool tool, done by awesome folks. A real big plus is the responsiveness to questions and when som
by rgerhards 8y ago
We at rsyslog use it as part of our CI pipeline. It's a pretty cool tool, done by awesome folks. A real big plus is the responsiveness to questions and when something needs attention. When we came to LGTM (at that time in beta for C), we already had a pretty clean code base. The reason is that we use other static analysis tools. LGTM did nevertheless find some new and interesting things, include a real vulnerability[1]. We don't use custom QL right now (time is soo short), but opt in to some extra canned queries. For example, we prevent commented-out code via them. LGTM is a check REQUIRED to pass CI [2, sample PR].
We are really happy with both the product and the team and I can recommend diving into it. Nevertheless, don't rely on a single static analysis tool, no matter how good it is. If you use C/C++, you should at least also have clang's static analyzer in use.
[1] https://rainer.gerhards.net/2018/06/how-we-found-and-fixed-cve-in-librelp.html https://rainer.gerhards.net/2018/06/how-we-found-and-fixed-c...
[2] https://github.com/rsyslog/rsyslog/pull/3403 https://github.com/rsyslog/rsyslog/pull/3403