Review Coverity scan for Drupal core one time

Created on 19 January 2017, about 8 years ago
Updated 1 April 2025, 5 days ago

Idea summary

What is the problem to solve?

Coverity is a static analysis tool which can detect problems in the drupal code, and can improve quality of the code base.
It searches for (basic) code problems. http://software.synopsys.com/rs/157-LQW-289/images/FY16%20SIG%20FB%20Let...

Who is this for?

Core developers can use this to spot possible improvements in the drupal core codebase.

Result: what will be the outcome?

A daily analysis can be run, spottin (and removing) code duplication, dead code, and other possible improvements.

How can we know the desired result is achieved?

We can update core to find and fix possible problems spotted here. And point potential clients to a report showing the quality of drupal core code.

--- Original report ---

A client of us pointed out that they use Coverity for static code analysis.
Recently this also scans PHP projects. https://scan.coverity.com/

As an open source project it is possible to get free / periodic scans of the codebase. Perhaps this is something we could do for drupal as well.
Open source projects which are already doing this are for example owncloud / nextcloud. Lots of Apache (Java) projects. Some Angular tools, some wikimedia projects.
I'm not sure what the best person / instance within the drupal community would be to apply to this. So i'm posting it here first.

πŸ“Œ Task
Status

Fixed

Version

1.0

Component

Code

Created by

πŸ‡§πŸ‡ͺBelgium mallezie Loenhout

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

  • πŸ‡ΊπŸ‡ΈUnited States greggles Denver, Colorado, USA

    It seems there was some good research into the idea so making the title about that and marking as "fixed".

Production build 0.71.5 2024