Developers fast to fix open-source bugs

By Joris Evers, CNET News.com
Wednesday, April 05, 2006 11:16 AM

Developers have quickly fixed many bugs in popular open-source packages that were flagged as part of a U.S. government-sponsored bug hunt.

More than 900 flaws were repaired in the two weeks after Coverity, which makes tools to analyze source code, announced the results of its first scan of 32 open-source projects. As a result, some of the software is now entirely bug free, Coverity said in a statement on Monday.

"My impression is that the open-source community is producing software defect patches at an extremely fast rate," Ben Chelf, the chief technology officer at Coverity, said in the statement.

The open-source bug hunt is part of a three-year "Open Source Hardening Project," dedicated to helping make such software as secure as possible. In January, the U.S. Department of Homeland Security awarded US$1.24 million to Stanford University, Coverity and Symantec to find vulnerabilities in open-source projects.

In its initial analysis on March 6, Coverity scanned more than 17.5 million lines of code from 32 open-source projects. On average, 0.434 bugs per 1,000 lines of code were found, the company said at the time.

More than 200 developers registered for access to the online defect database in the week after the first results were published. Since then, programmers for the Samba, Amanda and XMMS projects eliminated all the defects that the initial analysis detected, Coverity said Monday.

Samba, a popular open-source project used to connect Linux and Microsoft Windows networks, showed the fastest developer response, Coverity said. The number of flaws was reduced from 216 to 18 in one week and to zero in two weeks.

Amanda, a backup tool, was the worst performer in Coverity's first analysis. It had the highest number of bugs per 1,000 lines of code, with a bug density of 1.237. The Amanda developers fixed 108 defects in a couple of weeks, according to Coverity.

XMMS, an audio player, had the lowest bug density, with 0.051 defects per 1,000 lines of code. A total of six holes have now been fixed, Coverity said.

As part of the government-funded effort, Stanford and Coverity have built a system that does daily scans of the code contributed to popular open-source projects. The resulting database of bugs is accessible to developers, so they can get the details they need to fix the flaws, Coverity said.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Mainsoft: Opening options for Java, .NET developers

Java

Mainsoft provides tools for running .NET code on the Java platform.


Read more »


Tags

  1. against
  2. antivirus
  3. apple
  4. asia
  5. asian
  6. attacks
  7. by
  8. critical
  9. cyber
  10. data
  11. flaws
  12. google
  13. issues
  14. malware
  15. microsoft
  16. online
  17. over
  18. pledges
  19. security
  20. software
  21. spore
  22. symantec
  23. threats
  24. uk
  25. updates
  26. us
  27. vista
  28. web
  29. windows
  30. word
 
Increase performance with eco-technology innovations
Simplify your infrastructure and unify management, while lowering power and cooling costs of your datacenter.
» Maximum flexibility with powerful blade technolgy
» Bring new services and applications online faster
» Lower energy use and cost
Oracle SOA Business Software Centre
Many companies are recognizing the need to adopt standards in their efforts to build service-oriented applications.
Secure the "Next-Gen SOA Infrastructure" & "Bringing SOA Value Patterns to Life" whitepapers here

» Visit the Power Center

Up close and personal with a merger

Blog thumbnail

What can you get for 13.9 billion buckaroos? For Hewlett-Packard, US$13.9 billion would allow you to buy your way into becoming the second biggest IT services company in the industry...... by Eileen Yu

Read more »