Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Python Gets High Marks for Open Source Software Security: Report

Coverity, a provider of development testing solutions, announced the results of its second Coverity Scan Project Spotlight this week, which analyzed the Python open source software project, including defect density as compared to the industry average defect density for good quality software and types of defects identified.

Coverity, a provider of development testing solutions, announced the results of its second Coverity Scan Project Spotlight this week, which analyzed the Python open source software project, including defect density as compared to the industry average defect density for good quality software and types of defects identified.

“Python software has been in use for more than 20 years, enabling secure and reliable programs for industry, service sector and research and science applications,” Coverity said. “Industry-leading organizations including CERN, Google, Mozilla and YouTube, among many others, incorporate the popular programming language into their applications. Python was one of the initial projects included in the Coverity Scan service, which enables the open source community to find and fix critical quality and security defects in their code. Since 2006, Python has achieved a defect density of .005 (or .005 defects per 1,000 lines of code) and has eliminated all high-risk defects in its codebase.”

Coverity’s 2012 Scan Report found an average defect density of .69 for open source software projects that leverage the Coverity Scan service, as compared to the accepted industry standard defect density for good quality software of 1.0.

According to the security testing firm, Python’s defect density of .005 significantly surpasses this standard, and introduces a new level of quality for open source software.

Coverity said that it has analyzed nearly 400,000 lines of Python code and identified 996 new defects to date – 860 of which have been fixed by the Python community.

“Python is the model citizen of good code quality practices, and we applaud their contributors and maintainers for their commitment to quality,” said Jennifer Johnson, chief marketing officer for Coverity.

A full copy of the report is available here in PDF format.

Related: When Open Source Code Quality is Better than Proprietary Software

Advertisement. Scroll to continue reading.

RelatedFollowing Best Development Practices Does Not Always Mean Better Security

Related71% of Apps Use Components With Severe or Critical Security Flaws

RelatedExperts Debate –  Is Software Security a Waste of Time?

Related ResourceHow Secure Is Your Code? Scan, Assess and Find out Now…

Related Resource2013 Gartner Magic Quadrant for Application Security Testing Report

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.