From #CentOSConnect: František Lachman and Siteshwar Vashisht talked about using OpenScanHub and Packit for static analysis.

https://www.youtube.com/watch?v=XYCh1hkCo-o&list=PLuRtbOXpVDjDCM16tT5KHPbz3_Fy0vNzR&index=7

#OpenScanHub #Packit

OpenScanHub and Packit: Fully automated static analysis of RPM-based distributions

YouTube
I would be talking about OpenScanHub and Packit at CentOS Connect 2025 https://cfp.fedoraproject.org/centos-connect-2025/talk/L3DAQL/ #CentOS #CentOSConnect #FOSDEM #OpenScanHub #packit
OpenScanHub and Packit: Fully automated static analysis of RPM-based distributions CentOS Connect

What if detecting bugs and vulnerabilities in RPM-based distributions could be seamless and fully automated? OpenScanHub is a service for static and dynamic code analysis. It was internally used inside Red Hat to scan releases of RHEL for more than a decade and was open-sourced in 2023. OpenScanHub can fully automatically scan RPMs and has the ability to do differential scans that helps in finding bugs that may be introduced on package updates and new distribution releases. By default, it supports static analyzers embedded in GCC, Cppcheck, ShellCheck, find-unicode-control, Clippy and is extensible to support other analyzers. It can collect reports from various analyzers at a single place to make it easy to analyze them. OpenScanHub was recently integrated with Packit, a CI/CD solution for automating RPM package builds, tests, and distribution releases. This new integration performs differential scans on pull requests, so potential bugs may be found during the pull request review process and would not be introduced into the codebase. In this talk, we will share ideas about how CentOS Stream and its derivatives may benefit from OpenScanHub.

Siteshwar Vashisht: OpenScanHub: A Brief Introduction - GNU Tools Cauldron 2024

YouTube

Are you coming to GNU Tools Cauldron 2024 conference this year?

@siteshwarv is going to present OpenScanHub and static analysis via Packit! 🔎

https://gcc.gnu.org/wiki/cauldron2024#cauldron2024talks.openscanhub_a_brief_introduction

#gnu #openscanhub #fedora #sast #packit

cauldron2024 - GCC Wiki

When watching the talk about OpenScanHub, I couldn't help but to think about the posts by
@usgraphics about keeping the UI simple, easy to use and without any unnecessary bloat :) (bit late to party, but nice screenshots)
#DevConf_CZ #opensource #DefineFuture #OpenScanHub #Fedora