Requires Free Membership to View
When you register, you'll receive targeted emails designed to keep you informed of the most relevant information on Agile development, application security, testing & QA, software requirements, and more.
Hannah Smalltree, Editorial Director
|
The open source or freely available tools in this space do tend to be more focused on a single language. For example, FindBugs and PMD do static analysis for Java. They are mostly focused on quality issues, but they also find some security defects. For .NET environments, FxCop from Microsoft checks for quality and security issues.
The OWASP Orizon project is intended to be a cross-language framework for security source code review. It is currently in the early stages, but support for both Java and .NET is planned.
This was first published in November 2008
Join the conversationComment
Share
Comments
Results
Contribute to the conversation