On CHOW: Did you leave a huge tip?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Mar 28, 2007 1:06:00 AM

A year after its original launch, a U.S. government-backed project that scans open-source code for flaws is expanding.

The effort, supported by a research contract from the U.S. Department of Homeland Security, is now scanning code of 150 open-source projects, up from the original 50.

"This allows open-source developers to find and resolve defects introduced into the project," David Maxwell, open-source strategist for Coverity, said in a statement. Coverity makes source-code analysis tools and shares the DHS contract with Stanford University and Symantec.

Since the start of the project, 6,000 bugs that were found have been fixed, according to Coverity. About 700 developers are now registered to access the bug data and 35 million lines of code are scanned every day, the company said.

New open-source projects added to the bug hunt effort include "zlib," a compression program used in many applications, as well as FreeRadius, an application that provides authentication.

Coverity has updated its scan.coverity.com Web site to give a graphical overview of the flaws that were found. The company plans to further increase the number of open-source projects it scans. It has yet to decide which ones.

The bug hunt is part of a three-year "Open Source Hardening Project" dedicated to helping make such software as secure as possible. In January 2006, the U.S. Department of Homeland Security awarded $1.24 million to Stanford, Coverity and Symantec to find vulnerabilities in open-source projects.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 6 Talkback(s)
MS, Apple and Sun
can compete with their wholly to partially proprietary commercial software/OS because of public knowledge of their products (through work usage and advertisement which OSS can rarely do), momentum ove... (Read the rest)
Posted by: Boot_Agnostic Posted on: 03/30/07 You are currently: a Guest | | Terms of Use
Isn't open-source bug an oximoron?  A.Typical Zork | 03/28/07
no no no smear campaign  Boot_Agnostic | 03/28/07
No  zkiwi | 03/28/07
Open leverage  Dr.C | 03/28/07
open source and competition  merc2dogs` | 03/29/07
MS, Apple and Sun  Boot_Agnostic | 03/30/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and
advertisement
Click Here