[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: RE: continuing the discussion from today's meeting
Thank you very much for offering these comments. I will ask David whether this is a way we can integrate them into the minutes. From my perspective, +1 on all of this. Fingerprints are confusing. It’s hard to document/provide guarantees on what portion of SARIF is populated. It’s interesting to consider how our standards effort could help. Your thoughts on a dynamic analysis standard are clarifying. If we can create a metastandard/core as you say and extract/separate static vs dynamic, that could be very useful. Perhaps extensions for results management could be another add-on.
Finally, some sort of descriptor/manifest in the log file document what’s persisted to it could be of general value, and perhaps we could leverage that to address how to enforce SARIF consistency (as produced by diverse tools). Thanks again for taking the time to put this together. We’ll do a better job with time mgmt. next call to ensure everyone has a chance to speak. MCF From: Yekaterina O'Neil Hi all, I kept postponing making comments during the meeting, until we ran out of time :) So, I am gonna jot them down in an e-mail, so I don’t forget them before the next meeting… Micro Focus is one of those big commercial vendors referred to on the call, however we do understand the value of SARIF, and everyone at Fortify is bought into it. Most of our customers use several tools / vendors, so
it makes perfect sense for us to support the standard. In fact, our developers are excited about potentially substituting our proprietary format with SARIF eventually, considering performance gains it could bring. But of course, it’s all a matter of priority,
and, unfortunately, so far we’ve only implemented the ability to consume SARIF as opposed to produce it. But Alex Hoole and I keep pushing :) Here are a couple of pieces of feedback I heard from within the organization regarding SARIF that we might want to consider in our TC discussions going forward:
Hope this makes sense. Looking forward to working with everyone, k |
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]