Skip to content

Conversation

@lovesegfault
Copy link
Member

Motivation

Coverity is a really powerful C/++ static analysis tool that is free for FOSS, this is just to see if it could work for us at all.

This will fail while the secret is not added to the repo, which is pending discussion in today's team meeting.

Context


Add 👍 to pull requests you find important.

The Nix maintainer team uses a GitHub project board to schedule and track reviews.

@lovesegfault lovesegfault force-pushed the coverity branch 2 times, most recently from 378afac to 782b6ec Compare October 29, 2025 20:32
@Mic92
Copy link
Member

Mic92 commented Nov 6, 2025

not planned.

@Mic92 Mic92 closed this Nov 6, 2025
@lovesegfault lovesegfault deleted the coverity branch November 6, 2025 19:52
@lovesegfault
Copy link
Member Author

For additional future context, we investigated and got this working, but the output was too noisy. The recommended way to reduce false-positives is by writing so-called modeling files, which are poorly documented and must be manually uploaded on the Coverity website.

Moreover, the analysis took a very long time to run with us spending multiple days in the queue, which further discouraged us from attempting to write modeling files, and new builds are needed for them to take effect.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants