https://issues.apache.org/bugzilla/show_bug.cgi?id=56681

Mark Thomas <ma...@apache.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
         Resolution|---                         |INVALID

--- Comment #17 from Mark Thomas <ma...@apache.org> ---
Blindly copying the output from some random code analysis tool into a bug
without validating the results is not going to generate a useful bug report.

I looked at the first few of these and they were all false positives. I did
manage to find one valid issue and a couple of possibles but the false positive
rate is significant.

The Tomcat project does use carefully selected code analysis tools and one of
the criteria for selection is the false positive rate. The false positive rate
of the tool used for this analysis is far too high to be useful.

-- 
You are receiving this mail because:
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to