4 ms·
How about a version where the monetary amounts are normalized by the number of lines of code?
by keketi 3y ago
How about a version where the monetary amounts are normalized by the number of lines of code?
- Cthulhu_ 3y agoWhy do you ask? Genuinely curious, because lines of code is a moot point in software and security.
- matsemann 3y agoBecause it's interesting. If "X" is 1000 lines of code and has cost $20k in bounties, and "Y" is 1 000 000 lines of code and has also cost $20k in bounties, it's interesting to see that feature X has relatively more high profile bugs when it probably does much less.
- worldsayshi 3y agoI wouldn't say that it's a moot point in every context. The metric we'd get here would amount to "given that this developer made a loc change, what is the monetary risk involved". Developers that are high on this metric might want to allow down and think twice next time they commit. Or not. Metrics are likely not very useful in general.
- dsabanin 3y agoIt’s a valid measure of the amount of code. 10 bugs in 100k LOC speaks of a very different quality than 10 bugs in 1k LOC.
- phyzome 3y agoIt's the same as the idea of per-capita normalization.
- quickthrower2 3y agoOr normalize by number of word spilt on the bug (as a proxy for complexity)
- deleted 3y ago[deleted]