Changes between Version 29 and Version 30 of SponsoringPrograms/STF/2024


Ignore:
Timestamp:
Feb 8, 2024, 8:32:15 PM (3 years ago)
Author:
Michael Niedermayer
Comment:

update Coverity

Legend:

Unmodified
Added
Removed
Modified
  • SponsoringPrograms/STF/2024

    v29 v30  
    5656
    5757
    58 == Classify Coverity Issues ==
    59 
    60 '''Description:''' Coverity is a static code analysis system that is used to analyze FFmpeg code to find bugs with an emphasis on quality and security issues. There are currently 674 open issues.
    61 This project proposes to pay ? € per issue classified.
    62 
    63 '''Expected results:''' all easy classifyable issues become classified, it is understood that a small number of issues will be very difficult to classify without fixing them, these will stay unclassified
     58== Coverity Issues ==
     59
     60'''Description:'''
     61Coverity is a static code analysis system that is used to analyze FFmpeg code
     62to find bugs with an emphasis on quality and security issues. There are currently
     63673 outstanding issues identified by Coverity. Some of these
     64issues are false positives while others could open the door to
     65security vulnerabilities.
     66
     67'''Milestones:''' There will be 3 pairs of milestones, the first of each pair will be about Fixing the outstanding real issues, improve code where simple shortcommings have been noticed and patches will be submitted. The 2nd of each pair will be about merging the patches to git master
     68
     69'''Expected results:''' all issues become classified, most real issues become fixed, tangentially related things found in the work will also be fixed. it is understood that some issues may be too difficult to classify or fix and that a small number of patches may be rejected and not merged for reasons outside the scope of this work
    6470
    6571'''Duration:''' whatever time it takes
    6672
    67 '''Payment:''' X€ for all 674 issues are classified or proportionally less for a subset.
    68 
    69 '''Developer:'''
    70 
    71 
    72 == Resolve Coverity Bugs ==
    73 
    74 '''Description:''' Coverity is a static code analysis system that is used to analyze FFmpeg code to find bugs with an emphasis on quality and security issues. Once issues are classified as bugs, they need to be closed, we esitimate that 1/3 of the issues will be bugs, that is we expect 225 bugs will need fixes.
    75 This project proposes to pay XX € per issue resolved.
    76 
    77 '''Expected results:''' close to 0 remaining issues
    78 
    79 '''Duration:''' whatever time it takes
    80 
    81 '''Payment:''' X€ for all issues fixed or proportionally less for a subset.
     73'''Payment:'''
    8274
    8375'''Developer:'''