Hacker News new | ask | show | jobs
by Traubenfuchs 2470 days ago
> I would be very surprised if someone could make a business out of 3rd party code reviews, but stranger things have happened.

Depending on how you define "make a business", this already happened. There are paid for code review and vulnerability scans. Sadly, I can't remember the companies that did them. I think one of them was by IBM... I saw them applied to new software (when it was nearly done) at two big, European companies. They were mostly worthless: The insights were barely above what Sonar gives you and many findings were "never gonna happen" edge cases.