HZGN.COM
welcome to my space
X
Welcome to:hzgn.com
Search:  
 HOME   FindBugs Finds Fortify

FindBugs Finds Fortify

Published by: wktd 2009-01-08

InternetNews Realtime IT News - Thieves Bag Data on 26.5M Vets::
VA launches efforts to inform veterans while FBI begins probe. FindBugs Finds Fortify. Microsoft Secures Mobile Access With Whale Buy
http://www.internetnews.com/security/article.php/3608031
HOME
With over 200,000 downloads to date, the open source FindBugs project is already a reasonably popular Java bug-hunting tool, but it hasn't found its way into large enterprise deployments. Not yet anyway.

Thanks to a new sponsorship and bundling effort with Fortify Software, that may well be about to change.

The FindBugs project is run out of the University of Maryland by Professor William Pugh. Pugh explained to internetnews.com that the general idea behind FindBugs is to identify bug patterns in Java and to identify the things the developers are doing wrong in their code.

Until recently, the FindBugs project had been a mostly academic effort. But last year, the Ph.D. student that was doing the development for the FindBugs project as part of a grad thesis graduated.

Pugh was concerned about how to continue the project since there were likely few additional research paper possibilities from the project and, as such, unlikely that another student could pick up the work.

Iron Chef Black Hat::
this method works very well within a matter of minutes, it finds all the (for .NET) and FindBugs (for Java) are gaining popularity.
http://www.blackhat.com/presentations/bh-usa-07/Chess_West_Fay_anest_fay_and_kureha-WP.pdf
HOME
That's where Fortify comes in. Fortify is now going to sponsor the project as well as integrate FindBugs into its commercial product.

Fortify is a commercial software developer with its own source code analysis framework that looks for code vulnerabilities among other flaws. Barmak Meftah, vice president of engineering and operations at Fortify, explained that the FindBugs project is a body of open source that is completely aligned with what Fortify does.

"Our main objective is really for the good of the software development community out there," Meftah said. "Here's a piece of code that's been widely adopted; the install base is huge. Why not support and enhance it?"

Fortify is not contributing any source code or intellectual property to FindBugs. Fortify's enterprise user base is expected to be a ripe proving ground for FindBugs that Pugh hopes will yield much feedback that will help the project.

Pugh noted that the Fortify sponsorship gives FindBugs the support it needs to be a tool that continues to improve and be supported, as well as provides the ability to get feedback from more industrial-strength users.

"The thing that was interesting to us is how many really stupid bugs exist in production code," Pugh said.

Pugh said a favorite of his errors that FindBugs has detected is a particular method that, if it is ever invoked, will invoke itself again in an infinite recursive loop.

"You find methods like this, -- one-line methods that do nothing but call themselves -- and you wonder how this actually happened," Pugh said. "In Sun's JDK we found five of them. JBoss, Websphere, Eclispse they all have numerous examples of this particular bug."

Fortify's software will invoke FindBugs as a plug-in, which from a legal point of view is possible, thanks to the LGPL (define) (Lesser GNU General Public License) where FindBugs is available.

LGPL allows for commercial libraries to be linked against it, which is something that isn't always possible with the GPL (define).

"We definitely don't want to go to GPL because I think that's too limited to people that might want to do various tings with it," Pugh explained. "If anything the discussion has been 'Do we want to move to a looser open source license?"

Pugh wants more commercial usage of FindBugs, and that's where the GPL may present a problem.

"There are all sorts of issues that I don't entirely understand with the GPL about what happens with plug-ins," Pugh said. "Certainly we don't want people to think because they're using the FindBugs plug-in that they have to GPL-license their own code.

"We want to allow FindBugs to be used within commercial code-sourced tools."

FindBugs is expected to release its 1.0 version, in a week or so according to Pugh. The 1.0 version will mark a significant milestone for the project.

"The main thing is that we have now moved beyond the stage where this is an academic project," Pugh said. "I think that with 1.0 we can now say that this is something that is useful and has real support."




W3C Turns Up 'Dial' For Mobile Content
Adieu FrontPage, Hello Expression

You are looking at:hzgn.com's FindBugs Finds Fortify, click hzgn.com to home
  • what is a good way to train if i want to lose weight and gain speed for mma
  • cutting weight for high school wrestling
  • does anyone know where to get cheap motocross equipment
  • where can i find a place that sells all kinds of ufc stuff in toronto ontario
  • are you an atv or dirtbike rider or lover
  • an excuse letter about karate for theschool
  • how can i know what discipline of martial arts to take
  • tae kwon do help
  • how do i get my parents to let me ride motocross
  • punching bag workout question
  • fight tomorrow help fast
  • when it comes time to fight
  • does anybody no these guys next fight fedor emelianko alksander emelianko shane carwin and brock lesnar
  • choosing my first bike
  • all you with your ear to the ground or eye on the screen
  • i am 20 interested in kung fu though i have no martial arts experience can i yet became an expert fighter
  • what would be a good dirt bike
  • do you think that it is more challenging to fence with certain weapons than others
  • looking for a off track sports bike
  • sorry if this is not much of a martial arts question
  • why do you kihai shout in martial arts
  • s w a n ninjitsu camp in colorado
  • tornado punch or roundhouse kick to the face
  • what is the best dirtbike set up and brand of gear to ride for
  • do you think stamina can come in handy in a street fight
  • dirtbike racing and boys
  • look at previous jab q and a 039 s first
  • #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info about FindBugs Finds Fortify , Please add it free.

    About us -Site map -Advertisement -Jion us -Contact usExchange linksSponsor us
    Copyright© 2008 hzgn.com All Rights Reserved
    Site made&Support support@hzgn.com    E-mail: web@hzgn.com