search menu icon-carat-right cmu-wordmark

October/November 2014 Edition of the Secure Coding Newsletter

Newsletter
The Secure Coding Team releases SCALe demo videos and a free version of Java Coding Guidelines, and also describes its work on the CERT C++ Secure Coding Standard.
Publisher

Software Engineering Institute

Abstract

 In the October/November 2014 edition of the newsletter, the team announces that the Java Coding Guidelines are available for free online. These guidelines are available online to promote more widespread adoption of secure coding standards and as a note of appreciation to the software security and software development communities that have collaborated with the CERT Secure Coding team to make sure coding a success. 

The team also describes its work to

  • evolve the CERT C++ Secure Coding Standard, including describing a substantial list of added, changed, and removed rules
  • publish demonstration videos that illustrate the process of auditing a small C codebase using the Source Code Analysis Laboratory (SCALe)
  • improve DidFail, the team’s static taint flow analyzer for Android app sets