4 ms·
Is Coverity integrated into the FreeBSD build system? A quick search on FreeBSD.org shows some activity back in 2006 but not much mention of it since. I'd be
by ddp 12y ago
Is Coverity integrated into the FreeBSD build system? A quick search on FreeBSD.org shows some activity back in 2006 but not much mention of it since. I'd be interested in seeing the results in /usr/src/sys/netinet6 and netipsec. Is there a reason why the scan results require committer access?
- npsimons 12y agoI would be surprised if Coverity was integrated into any open source project's build system. All due respect to the Coverity folks, and Coverity is a great tool, it's still closed source. To be honest, I suspect the Coverity folks are getting as much (or more) out of running their tool against these projects as the projects are. I would like to see the scan results opened up too, which would be in keeping with the open nature of these projects. I'm willing to bet there's paranoia about competition duplicating features from Coverity, so that would explain why they limit it to comitter access (and required signing an NDA last I checked). EDIT: I stand corrected - Python has integrated Coverity into their builds: https://docs.python.org/devguide/coverity.html https://docs.python.org/devguide/coverity.html It still bothers me that the scan reports aren't open; it feels antithetical to the nature and spirit of open source software.
- cperciva 12y agoIs there a reason why the scan results require committer access? Coverity says that only "project members" can get access to the full bug reports. IIRC there's also a rule about not posting verbatim Coverity reports anywhere publicly visible. I assume this is "stop the competition from seeing what we're doing", but I've never asked.
- khc 12y agoI think the bigger problem is that the issues are potentially security issues.