Flawfinder version 2.0.10, (C) 2001-2019 David A. Wheeler. Number of rules (primarily dangerous function names) in C/C++ ruleset: 223 Examining data/scons-4.0.1+dfsg/doc/generated/examples/depends_include_hello.h Examining data/scons-4.0.1+dfsg/doc/generated/examples/tasks_ex1_main.cpp Examining data/scons-4.0.1+dfsg/test/packaging/sandbox-test/src/foobar.h Examining data/scons-4.0.1+dfsg/test/packaging/sandbox-test/src/foobar.c Examining data/scons-4.0.1+dfsg/test/packaging/rpm/src/main.c Examining data/scons-4.0.1+dfsg/test/Libs/bug2903/main.c Examining data/scons-4.0.1+dfsg/test/Libs/bug2903/lib.c Examining data/scons-4.0.1+dfsg/test/MSVC/MSVC_BATCH-spaces-targetdir/src/b.c Examining data/scons-4.0.1+dfsg/test/MSVC/MSVC_BATCH-spaces-targetdir/src/c.c Examining data/scons-4.0.1+dfsg/test/MSVC/MSVC_BATCH-spaces-targetdir/src/a.c Examining data/scons-4.0.1+dfsg/test/MinGW/bug_2799/shlib.c Examining data/scons-4.0.1+dfsg/test/MinGW/bug_2799/module.c Examining data/scons-4.0.1+dfsg/test/LINK/applelink_image/foo.c Examining data/scons-4.0.1+dfsg/test/SideEffect/Issues/3013/files/test.cpp Examining data/scons-4.0.1+dfsg/test/fixture/test_main.c Examining data/scons-4.0.1+dfsg/test/D/Issues/2940_Ariovistus/Project/test/test1/stuff.h Examining data/scons-4.0.1+dfsg/test/D/Issues/2940_Ariovistus/Project/test/test1/test1.cpp Examining data/scons-4.0.1+dfsg/test/D/Issues/2940_Ariovistus/Project/test/test1/stuff.cpp Examining data/scons-4.0.1+dfsg/test/D/Issues/2939_Ariovistus/Project/test/test1/stuff.h Examining data/scons-4.0.1+dfsg/test/D/Issues/2939_Ariovistus/Project/test/test1/test1.cpp Examining data/scons-4.0.1+dfsg/test/D/Issues/2939_Ariovistus/Project/test/test1/stuff.cpp Examining data/scons-4.0.1+dfsg/test/D/HSTeoh/SingleStringCannotBeMultipleOptions/cmod.c Examining data/scons-4.0.1+dfsg/test/D/HSTeoh/LinkingProblem/cprog.c Examining data/scons-4.0.1+dfsg/test/D/HSTeoh/LinkingProblem/ncurs_impl.c Examining data/scons-4.0.1+dfsg/test/D/MixedDAndC/Image/cmod.c Examining data/scons-4.0.1+dfsg/test/Actions/pre-post-fixture/work1/bar.c Examining data/scons-4.0.1+dfsg/test/Actions/pre-post-fixture/work1/foo.c Examining data/scons-4.0.1+dfsg/test/Actions/addpost-link-fixture/test1.c Examining data/scons-4.0.1+dfsg/test/Actions/addpost-link-fixture/test_lib.c Examining data/scons-4.0.1+dfsg/test/Actions/append-fixture/foo.c Examining data/scons-4.0.1+dfsg/test/Batch/changed_sources_main.cpp Examining data/scons-4.0.1+dfsg/test/CC/CC-fixture/test2.C Examining data/scons-4.0.1+dfsg/test/CC/CC-fixture/bar.c Examining data/scons-4.0.1+dfsg/test/CC/CC-fixture/test1.c Examining data/scons-4.0.1+dfsg/test/CC/CC-fixture/foo.c Examining data/scons-4.0.1+dfsg/timings/CPPPATH/include/foo.h Examining data/scons-4.0.1+dfsg/timings/CPPPATH/foo.c FINAL RESULTS: ANALYSIS SUMMARY: No hits found. Lines analyzed = 225 in approximately 0.37 seconds (608 lines/second) Physical Source Lines of Code (SLOC) = 179 Hits@level = [0] 10 [1] 0 [2] 0 [3] 0 [4] 0 [5] 0 Hits@level+ = [0+] 10 [1+] 0 [2+] 0 [3+] 0 [4+] 0 [5+] 0 Hits/KSLOC@level+ = [0+] 55.8659 [1+] 0 [2+] 0 [3+] 0 [4+] 0 [5+] 0 Dot directories skipped = 5 (--followdotdir overrides) Minimum risk level = 1 There may be other security vulnerabilities; review your code! See 'Secure Programming HOWTO' (https://dwheeler.com/secure-programs) for more information.