Auditing for third party code?

A contracting firm provided some sample code for a thing at work a few weeks back. I got it running in a tool, provided binaries of that tool, and they went about their development. What the code is or does isn't important here.

Today, I noticed that it needed some tweaks so I started adding those in. The coded uses BouncyCastle to handle encryption, so I started looking for an example of doing a specific thing in BC. The first result I found? The code the contracting firm provided me. Thankfully, the license that code is released under isn't problematic, but it very well could have been.

Are there any tools that I could use where I throw an application's source tree at it and it looks for third-party code on the internet?

submitted by /u/rossnelson
[link] [comments]

from Software Development – methodologies, techniques, and tools. Covering Agile, RUP, Waterfall + more! https://ift.tt/iW5SkMg

Leave a comment

Design a site like this with WordPress.com
Get started
search previous next tag category expand menu location phone mail time cart zoom edit close