Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Near-100% test coverage did not catch a CVE in my Go library
(opens in new tab)
(blog.reqproof.com)
2 points
LeonidBugaev
1mo ago
1 comments
Save
Share
1 comments
1 comments · 1 top-level
top
newest
oldest
emanuele-em
1mo ago
for parsers, malformed input probably has to be part of the actual spec, not just an edge case. A small set of bad-input tests plus fuzzing seems more useful than chasing the last few percent of line coverage
j
/
k
navigate · click thread line to collapse