Program verification is not all-or-nothinglawrencecpaulson.github.io1 point·tempodox··0 commentsOpen articleSaveView on HN