10
I Use This!
Inactive
Analyzed about 3 hours ago. based on code collected 1 day ago.

Project Summary

Newlib is a C library intended for use on embedded systems. It is a conglomeration of several library parts, all under free software licenses that make them easily usable on embedded products.

Newlib is only available in source form. It can be compiled for a wide array of processors, and will usually work on any architecture with the addition of a few low-level routines.

Newlib is the C Library used by Cygwin and RTEMS.

Tags

c embedded libc malloc standard-library static

BSD 3-clause "New" or "Revised" License
Permitted

Commercial Use

Modify

Distribute

Place Warranty

Forbidden

Hold Liable

Use Trademarks

Required

Include Copyright

Include License

These details are provided for information only. No information here is legal advice and should not be used as such.

Project Security

Vulnerabilities per Version ( last 10 releases )

Project Vulnerability Report

Security Confidence Index

Poor security track-record
Favorable security track-record

Vulnerability Exposure Index

Many reported vulnerabilities
Few reported vulnerabilities

Did You Know...

  • ...
    nearly 1 in 3 companies have no process for identifying, tracking, or remediating known open source vulnerabilities
  • ...
    data presented on the Open Hub is available through our API
  • ...
    65% of companies leverage OSS to speed application development in 2016
  • ...
    search using multiple tags to find exactly what you need
About Project Security

Languages

C
60%
C++
15%
Make
9%
17 Other
16%

30 Day Summary

Sep 28 2025 — Oct 28 2025

12 Month Summary

Oct 28 2024 — Oct 28 2025
  • 1028 Commits
    Up + 266 (34%) from previous 12 months
  • 57 Contributors
    Up + 15 (35%) from previous 12 months
 

Static Analysis ( Generated by Coverity Scan for RTEMS-Newlib )

Repository URL: https://sourceware.org/git/newlib-cygwin.git

Version: c43ec5f59

2025-10-29
Last Analyzed
92,784
Lines of Code Analyze
1.44
Defect Density

Defects by status for current build

196
Total defects
134
Outstanding
61
Fixed

CWE Top 25 defects

ID CWE-Name Number of Defects
120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') 4
190 Integer Overflow or Wraparound 20
676 Use of Potentially Dangerous Function 1