DHS-sponsored audit: number of OSS code defects dropping
Coverity, in collaboration with Stanford University and under contract from the Department of Homeland Security (DHS), has just released their Open Source Report 2008 (PDF). Their environmental scan of major open source projects found that the number of defects in open source code is dramatically dropping! More detail is available on ArsTechnica. Now that we have definitive data that shows that open source software is strong on security, how can we get libraries to participate more readily on collaborative open source projects (like citation management, ILSs, CMSs...)? I'm reminded of a thought experiment posted by Joe Lucia, University Librarian @ Villanova University, in November 2007 on the NewGenCatalog list. In his post, Mr. Lucia called for a "shift of those investments from commercial software support (and staff technical support for commercial products) to a collaborative support environment for open source applications." Come on folks, let's make this shift happen!
In 2006, Coverity's scan detected an average of 0.30 defects per 1,000 lines of code, or, put differently, one code defects per every 3,333 lines. The lower boundary, in this case, was 0.02 (one defect per 50,000 lines) and the upper boundary was 1.22 defects per thousand lines of code. Two years later, the average defect density has fallen to 0.25, or one error per 4,000 lines of code. The upper boundary remains unchanged at 1.22, but the lower boundary has shrunk to 0, implying that repeated scanning has eliminated the errors from at least one program—at least all the errors that Coverity's 2006 static analysis program was able to detect. A 16 percent reduction in defect density over two years is a notable gain, and Coverity singled out certain participating projects as having an exceptionally low defect density.Continue reading
- Postfix
- Perl
- PHP
- Python
- Samba
Pentagon Audit of Iraq Spending
I always find it odd when news reports cite government documents without giving a link or good reference to them. It seems to me that this is something news web sites should do regularly. These reports are not always that easy to track down. Case in point: today's New York Times has a story about a Pentagon report:
- Iraq Spending Ignored Rules, Pentagon Says, By James Glanz, New York Times, May 23, 2008
A Pentagon audit of $8.2 billion in American taxpayer money spent by the United States Army on contractors in Iraq has found that almost none of the payments followed federal rules and that in some cases, contracts worth millions of dollars were paid for despite little or no record of what, if anything, was received.Using Google to search on the title of the report plus "site:.gov" yields nothing this morning, although the report is available from two different government web sites. The report is available at the site of the House Committee on Oversight and Government Reform, Committee Holds Hearing on Accountability Lapses in Multiple Funds for Iraq, Wednesday, May 21, 2008, along with other statements and documents.
- Internal Controls Over Payments Made in Iraq, Kuwait and Egypt, U.S. Defense Department, Office of the Inspector General, Report No. D-2008-098, (May 22, 2008).
Return of the BIA
Nextgov reports that the Bureau of Indian Affairs is free to reconnect itself to the Internet, thanks to a Washington D.C. District Court ruling earlier this month.
Interior allowed to reconnect to Internet, by Gautham Nagesh, Nextgov, May 21, 2008. District Judge James Robertson granted on May 14 motions filed by [Deparment of the] Interior requesting that the Bureau of Indian Affairs, the Office of Hearings and Appeals, the Office of the Special Trustee, and the Office of Historical Trust Accounting be allowed to reconnect their networks to the Internet.The BIA network was ordered to shut down in 2001 amid accusations of poor data security in the ongoing Cobell v. Kempthorne class action case. Security questions remain, however.
[Judge] Robertson acknowledged that Interior’s IT security may still be inadequate. “The congressional and inspector general reports indicating that the Interior Department, overall, continues to receive failing grades on its IT report card are troubling, but I have no authority to act in response to them, nor do I have any colorable suggestion that the declarations before me … were made in bad faith,” he wrote.As of this writing, the BIA site has not been fully restored. According to Interior chief information officer Michael Howell, it is expected to take a couple of months for the BIA to reconnect. -Brian Provenzale Continue reading
Think you can balance the US budget?
Go ahead and try with this online game called Budget Hero. Fun for the whole family :-) Continue reading
Good news and bad news about UK GIS data
Today, some mixed good news/bad news about the availability of free public data in the UK. As we've noted here before (e.g., Privatized Data Woes in Britain and News from abroad: UK open statutes & RFID in Canadian coins and The Semantic Web + Government Information = Serendipitous Reuse) the British government sells limited-use licences to its GIS data on a cost recovery basis. Now, as part of a proposed national geoportal, the UK would "create a single point of entry on the web to data held by public bodies such as local councils, Ordnance Survey (OS), the British Geological Survey and the Environment Agency." But, as the story says, "A new system will make geospatial information available without charge - yet we'll still have to pay."
- An Inspired debate on access, by Michael Cross, The Guardian, May 22 2008.
First, some very good news. Civil servants revealed last week that the British government has begun work on a system to make all the geospatial data it holds on the natural environment available for free inspection and re-use. Now the bad news. In this context, "free" means we will still have to pay to download much key data, especially if it is to be published or otherwise used commercially.Continue reading