NEW REFCARD

Variant Analysis

The same bugs often appear in multiple places – and in multiple variations – in a code base. Some bugs are just a bother. But when those code flaws create a potential security vulnerability, the price can be high. Performing variant analysis with pattern matching tools like grep is fine when you've found a simple flaw, but it can be time-consuming, tedious, and error prone.

So, what's the alternative?

Download this Refcard for an overview of LGTM and QL, variant analysis tools that are free for open source projects. Learn how to write queries that find code patterns that are semantically similar to the bug you found, automate alerts, and prevent the flawed code from being re-introduced in the code base. The author guides you through common use cases with a "cookbook-style approach."

Download Refcard

BROUGHT TO YOU IN PARTNERSHIP WITH