https://scan.coverity.com/ has been down for more than a few days now.
-
https://scan.coverity.com/ has been down for more than a few days now. At first it was "planned maintenance" and now it's "some upgrades" -- does anyone have any idea what's going on with Coverity these days?
Since the Black Duck acquisition a few years ago the Coverity experience has got worse and worse -- it doesn't *feel* like it has a long term future. Apart from PVS-Studio (which I also use) is there anything else people use for C-code static analysis?
-
https://scan.coverity.com/ has been down for more than a few days now. At first it was "planned maintenance" and now it's "some upgrades" -- does anyone have any idea what's going on with Coverity these days?
Since the Black Duck acquisition a few years ago the Coverity experience has got worse and worse -- it doesn't *feel* like it has a long term future. Apart from PVS-Studio (which I also use) is there anything else people use for C-code static analysis?
-
@zeenix is this is just a rewrite-it-in-rust comment please don't bother.
-
https://scan.coverity.com/ has been down for more than a few days now. At first it was "planned maintenance" and now it's "some upgrades" -- does anyone have any idea what's going on with Coverity these days?
Since the Black Duck acquisition a few years ago the Coverity experience has got worse and worse -- it doesn't *feel* like it has a long term future. Apart from PVS-Studio (which I also use) is there anything else people use for C-code static analysis?
@hughsie we use codeql in the systemd repo, here's the GHA yaml: https://github.com/systemd/systemd/blob/main/.github/workflows/codeql.yml
-
https://scan.coverity.com/ has been down for more than a few days now. At first it was "planned maintenance" and now it's "some upgrades" -- does anyone have any idea what's going on with Coverity these days?
Since the Black Duck acquisition a few years ago the Coverity experience has got worse and worse -- it doesn't *feel* like it has a long term future. Apart from PVS-Studio (which I also use) is there anything else people use for C-code static analysis?
@hughsie probably doesn't come even close but what about gcc's -fanalyzer or clang's scan-build as a stopgap? Definitely going to watch the replies to this post though to see what's out there
-
@hughsie probably doesn't come even close but what about gcc's -fanalyzer or clang's scan-build as a stopgap? Definitely going to watch the replies to this post though to see what's out there
-
@zeenix is this is just a rewrite-it-in-rust comment please don't bother.
@hughsie i didn't. π
-
https://scan.coverity.com/ has been down for more than a few days now. At first it was "planned maintenance" and now it's "some upgrades" -- does anyone have any idea what's going on with Coverity these days?
Since the Black Duck acquisition a few years ago the Coverity experience has got worse and worse -- it doesn't *feel* like it has a long term future. Apart from PVS-Studio (which I also use) is there anything else people use for C-code static analysis?
@hughsie In libssh we use csbuild in addition. This is from https://github.com/csutils/csmock/ and runs clang cppcheck etc. It offers plugins even to things like synk.
Setup is here:
https://gitlab.com/libssh/libssh-mirror/-/blob/master/.gitlab-ci.yml?ref_type=heads#L429 -
undefined oblomov@sociale.network shared this topic on