Since a lot of OpenBSD users are curious about improving the quality of software out there, here is a brief list of secure programming resources. Mind you it's biased towards C and static analysis, but this should be helpful. Nothing replaces a good, thorough manual code audit by knowledgable eyes, but this can be a start. Also be sure to follow many of the links from these references, these are just some places to start.

  1. By Anonymous Coward () on

    Of the tools for scanning code listed in the Sardonix link, RATS is currently the strongest/most complete.

    There is another list of resources at the Shmoo Group's website.


