When I scanned the Ubuntu package openscap-1.3.7+dfsg-1 I found many cppcheck errors. Some of the results are easy to solve memory leaks and others appear to be copy paste errors. They need their own triage and possibly assigned issues or CVEs. Here is the output of my local cppcheck scan: https://gist.github.com/eslerm/6dd060abb1a227972d8190a74f5cc684
I would like to propose adding a cppcheck GitHub action to track these and new results.
When I scanned the Ubuntu package openscap-1.3.7+dfsg-1 I found many cppcheck errors. Some of the results are easy to solve memory leaks and others appear to be copy paste errors. They need their own triage and possibly assigned issues or CVEs. Here is the output of my local cppcheck scan: https://gist.github.com/eslerm/6dd060abb1a227972d8190a74f5cc684
I would like to propose adding a cppcheck GitHub action to track these and new results.