The linked blog post [0] and the new security marketing page [1] both have a little more detail on what this actually means. Basically, Semmle offers a static analysis tool that operates on your source code as a graph (from what I understand) and points out bugs and security holes in your code. Github is now offering that for free on repos at all tiers. [0] https://github.blog/2019-09-18-securing-software-together/ […
Welcoming Semmle to GitHub
21–30 of 110 posts
Re: Welcoming Semmle to GitHub
#22Earlier quoted context omitted.
Semmle is basically datalog over source code. For what it works for, it works nice. But it is not a pancaea. Security vulnerability finding is almost certainly the wrong target for Semmle - I am unsure why they are trying to push that angle. There are much better stories in things like refactoring and understanding. (I say this having overseen a number of deployments for various reasons, some successful, some not)
Nothing is a panacea. Things that help move the needle without requiring tons of time or effort are useful and valuable. I'm really glad to see more efforts in this area.
Re: Welcoming Semmle to GitHub
#23Earlier quoted context omitted.
To be fair, if a “parent corporation” is a thing, then logically it has children and can be a corporate family.
Welp, guess it's time to bust out the "I'm offended and we need to change this lingo" card because corporations aren't people and we should stop referring to them that way
Re: Welcoming Semmle to GitHub
#24The linked blog post [0] and the new security marketing page [1] both have a little more detail on what this actually means. Basically, Semmle offers a static analysis tool that operates on your source code as a graph (from what I understand) and points out bugs and security holes in your code. Github is now offering that for free on repos at all tiers. [0] https://github.blog/2019-09-18-securing-software-together/ […
Am I reading that right that it's only on public repositories though? For private repositories I guess you have to buy through Semmle directly (via call us pricing)?
Re: Welcoming Semmle to GitHub
#25(Non native speaker here). Am I misunderstanding something, or is the author explaining that humanity can not progress without the open source community?
Re: Welcoming Semmle to GitHub
#26Earlier quoted context omitted.
Am I reading that right that it's only on public repositories though? For private repositories I guess you have to buy through Semmle directly (via call us pricing)?
This would make sense since Semmle would likely need access.
Re: Welcoming Semmle to GitHub
#27> Human progress depends on the open source community. (Non native speaker here). Am I misunderstanding something, or is the author explaining that humanity can not progress without the open source community?
Re: Welcoming Semmle to GitHub
#28I hate that these kinds of Orwellian phrases "Welcoming X to the Y Family" have now become idiomatic of corporate English. Ugh, no. There is no "family" involved here, not by any stretch of the word.
Re: Welcoming Semmle to GitHub
#29> Human progress depends on the open source community. (Non native speaker here). Am I misunderstanding something, or is the author explaining that humanity can not progress without the open source community?
Re: Welcoming Semmle to GitHub
#30Earlier quoted context omitted.
To be fair, if a “parent corporation” is a thing, then logically it has children and can be a corporate family.
Intent matters. The phrase "parent corporation" has no PR or emotional intent. "Welcoming X to Y family" has a clear emotive intent.
That's also not mutually exclusive of the emotive intent you are describing. What makes that Orwellian though?