Source

cpython-withatomic / Misc / README.klocwork

Klocwork has a static analysis tool (K7) which is similar to Coverity.
They will run their tool on the Python source code on demand.
The results are available at:

     https://opensource.klocwork.com/

Currently, only Neal Norwitz has access to the analysis reports.  Other
people can be added by request.

K7 was first run on the Python 2.5 source code in mid-July 2006.
This is after Coverity had been making their results available.
There were originally 175 defects reported.  Most of these
were false positives.  However, there were numerous real issues 
also uncovered.

Each warning has a unique id and comments that can be made on it.
When checking in changes due to a K7 report, the unique id
as reported by the tool was added to the SVN commit message.
A comment was added to the K7 warning indicating the SVN revision
in addition to any analysis.

False positives were also annotated so that the comments can
be reviewed and reversed if the analysis was incorrect.

A second run was performed on 10-Aug-2006.  The tool was tuned to remove
some false positives and perform some additional checks.  ~150 new
warnings were produced, primarily related to dereferencing NULL pointers.

Contact python-dev@python.org for more information.
Tip: Filter by directory path e.g. /media app.js to search for public/media/app.js.
Tip: Use camelCasing e.g. ProjME to search for ProjectModifiedEvent.java.
Tip: Filter by extension type e.g. /repo .js to search for all .js files in the /repo directory.
Tip: Separate your search with spaces e.g. /ssh pom.xml to search for src/ssh/pom.xml.
Tip: Use ↑ and ↓ arrow keys to navigate and return to view the file.
Tip: You can also navigate files with Ctrl+j (next) and Ctrl+k (previous) and view the file with Ctrl+o.
Tip: You can also navigate files with Alt+j (next) and Alt+k (previous) and view the file with Alt+o.