Subject: who will contact Coverity?
To: NetBSD security list <tech-security@netbsd.org>
From: William Allen Simpson <wsimpson@greendragon.com>
List: tech-security
Date: 01/19/2005 16:16:35
I was just talking to Perry Metzger the other day about code review,
and he mentioned trying to get some free automated tools.

With all the current news this week about the Linux code review,

  http://www.coverity.com/datasheets/linux_report.pdf

and the Darwin code review,

  http://www.immunitysec.com/downloads/nukido.pdf

maybe its time for some other BSDs?

Note that the immunitysec folks held on to their review for 6 months,
according to
    
http://news.com.com/Darwin+flaws+survive+in+Apples+Mac+OS+X/2100-1002_3-5540955.html?tag=macintouch)
<http://dw.com.com/redir?destUrl=http%3A%2F%2Fwww.immunitysec.com%2Fresources-advisories.shtml&siteId=3&oId=2100-1002-5540955&ontId=1009&lop=nl.ex>
Not very nice of them.

Anyway, the last paragraph of the Linux "white paper" says:

  Coverity offers free code audits analogous to what is contained in
  this report.  If you are interested, please email sales@coverity.com
  or please visit  www.coverity.com.

-- 
William Allen Simpson
    Key fingerprint =  17 40 5E 67 15 6F 31 26  DD 0D B9 9B 6A 15 2C 32