I wonder if that kind of coding standards can be part of ISO standards.
I wonder if that kind of coding standards can be part of ISO standards.
The rules specified in this Technical Specification apply to analyzers, including static analysis tools and C language compiler vendors that wish to diagnose insecure code beyond the requirements of the language standard. All rules are meant to be enforceable by static analysis.
I wrote an article putting all this in some context at: http://www.informit.com/articles/article.aspx?p=2088511
Many developers think that they don't need static analyzers.
Actually lint was part of the original UNIX, but since it took some effort to configure and not everyone agreed with the rules, it was seldom ported to other systems, and it became part of the C culture not to use it.
I think we have to thank the LLVM project that now static analyzers are welcome in C.
Basically, the CERT rules all must be analyzable (though some require dynamic analysis instead of static analysis).