Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To be a bit glib, unit tests don’t catch security vulnerabilities. Maybe I’d agree this can happen to any project, but my example might be something more like OpenBSD


Why not?

In this specific case, a unit test that checked this integer overflow seeems to prevent the vulnerability.

To be clear: This is not to admonish sqlite. They have taken testing further than any other project i've heard of, except maybe the NASA software that might cost lives if it fails.


Incidentally a lot of NASA tools use SQLite as well from what I have heard.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: