Press release
Coverity: Open Source Software improving continually
Coverity™, Inc., the leader in improving software quality and security, today announced the availability of the Scan Report on Open Source Software 2008. The Coverity Scan site was developed with support from the U.S. Department of Homeland Security as part of the federal government’s ‘Open Source Hardening Project.’ The report is based on 2 years of analysis of more than 55 million lines of code on a recurring basis from over 250 popular open source projects with Coverity Prevent™, the industry-leading static source code analysis solution.“The continued improvement of projects that already possess strong code quality and security underscores the commitment of open source developers to create software of the highest integrity,” said David Maxwell, open source strategist for Coverity. “Working with the open source community over the past two years has been an exceptional opportunity for researchers at both the Scan site and Coverity. Based on preliminary feedback from preview readers, the report contains thought provoking information about defect density and code complexity and provides a strong foundation for future research on the nature of software.”
Open source projects analyzed at the Scan site include some of the worlds most widely used applications, including the Apache web server and the Linux operating system. Source code analysis from the Scan site is freely available to qualified open source projects at: http://scan.coverity.com
“Close collaboration between Coverity and the FreeBSD Project over three years has been both exciting and remarkably valuable,” said Robert Watson, FreeBSD foundation president. “Coverity has had a positive impact on the correctness of our source code and has helped improve our software development methodology.”
The breadth and volume of analysis data presented in the Scan Report on Open Source Software 2008 is unlike any other collection of code analysis data in existence, representing 14,238 individual project analysis runs for a total of nearly 10 billion lines of code analyzed over 2 years.
The report also draws conclusions that may apply equally to open source and commercial software regarding the relationship between variables such as code base size, defect density, function length, Cyclomatic complexity and Halstead effort. In summary, the Scan Report on Open Source Software 2008 contains the following findings:
• The quality and security of open source software is improving – Researchers at the Scan site observed a 16% reduction in static analysis defect density over the last 2 years, which reflects the elimination of more than 8,500 individual defects
• Prevalence of specific defect types – The report shows a clear distinction between the frequencies of defect types across the scan database. ‘NULL pointer dereference’ was the most common defect while ‘Use before test of negative values’ was the least common defect
• Average project function length and static analysis defect density – Data in the report contradicts conventional wisdom, indicating that projects with large average function length are not prone to higher defect densities
• Cyclomatic complexity and Halstead effort – Research indicates these two measures of code complexity are significantly correlated to code base size
• False positive results – The average rate of false positives identified by open source developers on the Scan site is below 14%
Detailed data and analysis of these and other findings are available in the complete Scan Report on Open Source Software 2008, which is freely available for download in the research library at www.coverity.com
“The use of open-source technologies to enhance and evolve commercial products has become a common strategy. Vendors will continue to leverage this movement by embedding open source into products, while end-user organizations will use stable open-source projects as a competitive differentiator against companies that refuse to acknowledge that open source is now enterprise-ready. By 2012, 80% or more of all commercial software will include elements of open-source technology,” according to analyst Mark Driver in his recent Gartner report ‘Open Source in Vendor Business Strategies, 2008,’ published March 31, 2008.
Results of the Scan Report on Open Source Software 2008 will also be discussed during a complimentary webinar on Wednesday, May 21, 2008 by David Maxwell, Coverity’s open source strategist. Registration is available at: http://w.on24.com/r.htm?e=107874&s=1&k=41E3686F9B655D193F894D4A844EBBC6
About the Scan site http://scan.coverity.com
The Scan site was developed by Coverity with support from the U.S. Department of Homeland Security as part of the federal government’s ‘Open Source Code Hardening Project’. The site divides open source projects into rungs based on the progress each project makes in resolving defects. Projects at higher rungs receive access to additional analysis capabilities and configuration options. Projects are promoted as they resolve the majority of defects identified at their current rung.
# # #
Press contacts:
Coverity Inc., Jim Shissler, Director Public Relations; Tel: +1 (0) 415 694 5342, jshissler@coverity.com
Agentur Lorenzoni GmbH, Public Relations, Beate Lorenzoni; Tel.: +49 (0) 8122 / 55917-22, beate@lorenzoni.de
About Coverity Coverity (www.coverity.com), the leader in improving software integrity, is a privately held company headquartered in San Francisco. Coverity’s groundbreaking technology enables developers to control complexity in the development process by automatically finding and helping to repair critical software defects and security vulnerabilities throughout the application lifecycle. More than 450 leading companies including ARM, Phillips, RIM, Rockwell-Collins, Samsung and UBS rely on Coverity to help them ensure the delivery of superior software.
Coverity is a registered trademark, and Coverity Extend and Coverity Prevent are trademarks of Coverity, Inc. All other company and product names are the property of their respective owners.
This release was published on openPR.
Permanent link to this press release:
Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.
You can edit or delete your press release Coverity: Open Source Software improving continually here
News-ID: 45140 • Views: …
More Releases from Coverity, Inc.
Coverity To Participate in Free and Open Source Learning Centre (FOSSLC) Debate
Coverity Open Source Strategist David Maxwell Joins Open Source Licensing Debate with Eclipse Foundation and Alfresco on August 31st
San Francisco – Coverity® announced today that open source strategist David Maxwell will debate the merits of popular and often competing open source licenses with leading open source advocates Mike Milinkovich of the Eclipse Foundation and Matt Asay of Alfresco. The event, sponsored by the Free and Open Source Software Learning Centre…

Coverity: European Growth Surges 39 Percent in Last Year
Coverity, Inc., the leader in improving software quality and security automatically in C/C++/C# and Java, today announced Danny McLaughlin has joined the company as Director of European Sales to manage the company’s continued success and accelerated growth in Europe. In the past year, the size of Coverity’s world wide customer base eclipsed 500. In Europe, Coverity™ grew 39% in the last year, and now has over 100 European customers including…
Coverity Architecture Analyzer delivers advanced visualization of software syste …
Coverity, Inc., the leader in improving software quality and security automatically, today announced the availability of Coverity Architecture Analyzer™. This new version of Coverity’s architecture product incorporates the company’s patented Software DNA Map analysis system to provide development teams with the ability to ensure the integrity of application architecture across development teams, analyze the complexity and dependencies of software systems, and identify errors that can create crash causing defects or…
Coverity™ Introduces Software Readiness Manager for Java
Coverity, Inc., the leader in improving software quality and security, today announced the availability of Coverity Software Readiness Manager for Java. The product allows development managers, release managers and executives to objectively assess the release readiness of their critical code by combining essential data from multiple sources including Prevent, Coverity’s industry-leading static analysis product. Software Readiness Manager helps development teams deliver high-integrity code that successfully meets quality standards to align…
More Releases for Coverity
Coverity: European Growth Surges 39 Percent in Last Year
Coverity, Inc., the leader in improving software quality and security automatically in C/C++/C# and Java, today announced Danny McLaughlin has joined the company as Director of European Sales to manage the company’s continued success and accelerated growth in Europe. In the past year, the size of Coverity’s world wide customer base eclipsed 500. In Europe, Coverity™ grew 39% in the last year, and now has over 100 European customers including…
Coverity™ Introduces Software Readiness Manager for Java
Coverity, Inc., the leader in improving software quality and security, today announced the availability of Coverity Software Readiness Manager for Java. The product allows development managers, release managers and executives to objectively assess the release readiness of their critical code by combining essential data from multiple sources including Prevent, Coverity’s industry-leading static analysis product. Software Readiness Manager helps development teams deliver high-integrity code that successfully meets quality standards to align…
Coverity Aquires Build Management Vendor Codefast
Coverity™, Inc., the leader in automatically improving software quality and security in C/C++ and Java, today announced the acquisition of Codefast. Coverity’s first acquisition provides the company with engineering talent and advanced technology from Codefast to help developers understand and accelerate the software build process. The product acquired from Codefast will be enhanced to take advantage of Coverity’s patented Software DNA Map™ analysis system, further expanding the company’s platform of…
Coverity Thread Analyzer Detects Concurrency Defects in Multithreaded Applicatio …
Coverity™, Inc., the leader in automatically improving software quality and security in C/C++ and Java, today announced the release of Coverity Thread Analyzer for Java. The product is the first dynamic analysis tool for multi-threaded applications that automatically detects concurrency defects that can cause data corruption and application failures. Coverity Thread Analyzer can also be used in concert with Coverity Prevent, the industry-leading static analysis tool, to create a powerful…
Coverity: Dynamic stand-alone tool Thread Analyzer for Java
Dynamic Analysis Tool Detects Concurrency Defects and Accelerates Migration to Multi-core Environments
London/San Francisco – May 7, 2008 – Coverity™, Inc., the leader in automatically improving software quality and security in C/C++ and Java, today announced the release of Coverity Thread Analyzer for Java. The product is the first dynamic analysis tool for multi-threaded applications that automatically detects concurrency defects that can cause data corruption and application failures. Coverity Thread Analyzer…
Coverity Code Analysis to Improve Symbian Code Quality
Coverity, Inc., the leader in improving software quality and security automatically in C/C++ and Java, today announced plans to release new Symbian C++ software defect detection capabilities in its Coverity Prevent SQS solution. Coverity Prevent SQS is the leading static source code analysis solution that will enable the automatic detection of code defects that can occur during Symbian OS development. Symbian OS is the market-leading operating system for advanced, data-enabled…