TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Coverity Scan Update

49 pointsby fcambusover 6 years ago

7 comments

danielhochmanover 6 years ago
Coverity Scan regularly goes down for hours or days.<p>In February of 2018 it was down for over a month with no word or ETA on when it would be fixed. I hadn&#x27;t thought about it since then (we discontinued use), but researching it now they released a statement saying that it was hacked. There was not a single status update during the outage. <a href="https:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2018&#x2F;03&#x2F;19&#x2F;coverity_scan_cryptomining&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2018&#x2F;03&#x2F;19&#x2F;coverity_scan_crypt...</a>
kstrauserover 6 years ago
I wonder who the hosting provider was. I&#x27;m not seeing much in the news about one that &quot;unexpectedly ceased operations&quot;, just the expected background news of scattered outages.
评论 #18869947 未加载
sanxiynover 6 years ago
Coverity is really good. It is a pity some of its advances, effective in practice but not really &quot;publishable&quot;, will forever remain as proprietary secret.<p>Source: I worked on static code analysis product and we extensively black-box tested Coverity.
评论 #18870547 未加载
walterbellover 6 years ago
Has anyone tried LGTM &#x2F; Semmle QL for automated code review? They claim 100K OSS projects are using the service. It&#x27;s a bit hard to find technical information on the product, but they have found CVEs in mainstream products, including iOS.<p><a href="https:&#x2F;&#x2F;lgtm.com" rel="nofollow">https:&#x2F;&#x2F;lgtm.com</a> &amp; <a href="https:&#x2F;&#x2F;semmle.com&#x2F;ql" rel="nofollow">https:&#x2F;&#x2F;semmle.com&#x2F;ql</a>
评论 #18869748 未加载
评论 #18873365 未加载
评论 #18869834 未加载
评论 #18885338 未加载
sunycover 6 years ago
I honestly thought it is gone!<p>All links are dead, and synopsis.com’s big Corp style website isn’t helping one bit.
joshstrangeover 6 years ago
&gt; Coverity Scan is a free static code analysis tool for Java, C, C++, C# and JavaScript. It analyzes every line of code and potential execution path and produces a list of potential code defects.<p>There we go, I had no clue what this even was. Do a lot of people here use it?
评论 #18869345 未加载
评论 #18869443 未加载
评论 #18870039 未加载
评论 #18869417 未加载
评论 #18869605 未加载
评论 #18869515 未加载
rurbanover 6 years ago
Wouldn&#x27;t it be great if professional websites will someday get to the level of non-professional websites? E.g. by giving this announcement page a proper title: &quot;Coverity Scan Outage&quot;.<p>Update is a change, this is an outage.