Security Basics mailing list archives

Re: Code reviews


From: David Felio <david () ark org>
Date: Thu, 19 Feb 2009 17:16:33 -0600

Don't know what features you are looking for, but have you looked at CAT and FxCop? Both free from MS. Both do static code analysis.

FxCop: http://msdn.microsoft.com/en-us/library/bb429476(VS.80).aspx
CAT: http://blogs.msdn.com/cisg/archive/2008/12/22/security-code-review-using-cat-net-part-1.aspx


On Feb 18, 2009, at 5:29 AM, Alex Fiuvertiz wrote:

Hi there,

Are there any open source tools that are worth using when it comes to
source code reviews against .NET/C#?
Or is a commercial way the only good way?

Thanks, Alex


Current thread: