Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
maratb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
maratb
8y ago
That's fair. Although there are pretty tight internal controls on what Google can do on your Cloud Shell, you have to put a certain level of trust into Google here. Getting your own GCE VM and using SSH-in-the-browser is arguably mor
2.
▲
by
maratb
8y ago
What about using Google Cloud Shell ( https://cloud.google.com/shell/docs/; free, open to anyone with a Google account) as a jump host to your servers? Or using GCE's ssh-in-the-browser feature ( https:/
3.
▲
by
maratb
12y ago
There's a bit more to it. It's not enough to point Code Spotter / Coverity to a pile of code, it needs to observe the actual build in order to know precisely what is built and how it is built. While for some projects you ca
4.
▲
by
maratb
12y ago
Only if it comes from a repo that's hosted somewhere (i.e., not behind a firewall). Code Spotter is not restricted to GitHub, git, or any other particular SCM. If the code can be built, it can be analyzed.
5.
▲
by
maratb
12y ago
Sonar used to be just about running other open source tools, such as FindBugs, PMD, and Checkstyle. (BTW, Code Spotter runs FindBugs alongside Coverity analysis to complement the results). Sonar later added its own rule engine (Squid).
6.
▲
by
maratb
12y ago
You can run on a hosted continuous integration service, such as Travis CI. The documentation is a little thin right now, but we will add this to the docs soon.
7.
▲
by
maratb
12y ago
Why? It is a new product (though based on the existing technology), a new model (cloud-based vs traditional Coverity on-premise), it is in free and unlimited beta, and we are soliciting feedback. Seems like a reasonable "Show HN"
8.
▲
Show HN: Cloud-based Static Code Analysis for Java
(code-spotter.com)
27 points
by
maratb
12y ago
|
15 comments