Integrating Static Code Analysis Toolchains

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kern, Matthias, Erata, Ferhat, Iser, Markus, Sinz, Carsten, Loiret, Frederic, Otten, Stefan, Sax, Eric
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914709131755520
author Kern, Matthias
Erata, Ferhat
Iser, Markus
Sinz, Carsten
Loiret, Frederic
Otten, Stefan
Sax, Eric
author_facet Kern, Matthias
Erata, Ferhat
Iser, Markus
Sinz, Carsten
Loiret, Frederic
Otten, Stefan
Sax, Eric
contents This paper proposes an approach for a tool-agnostic and heterogeneous static code analysis toolchain in combination with an exchange format. This approach enhances both traceability and comparability of analysis results. State of the art toolchains support features for either test execution and build automation or traceability between tests, requirements and design information. Our approach combines all those features and extends traceability to the source code level, incorporating static code analysis. As part of our approach we introduce the "ASSUME Static Code Analysis tool exchange format" that facilitates the comparability of different static code analysis results. We demonstrate how this approach enhances the usability and efficiency of static code analysis in a development process. On the one hand, our approach enables the exchange of results and evaluations between static code analysis tools. On the other hand, it enables a complete traceability between requirements, designs, implementation, and the results of static code analysis. Within our approach we also propose an OSLC specification for static code analysis tools and an OSLC communication framework.
format Preprint
id arxiv_https___arxiv_org_abs_2403_05986
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Integrating Static Code Analysis Toolchains
Kern, Matthias
Erata, Ferhat
Iser, Markus
Sinz, Carsten
Loiret, Frederic
Otten, Stefan
Sax, Eric
Software Engineering
This paper proposes an approach for a tool-agnostic and heterogeneous static code analysis toolchain in combination with an exchange format. This approach enhances both traceability and comparability of analysis results. State of the art toolchains support features for either test execution and build automation or traceability between tests, requirements and design information. Our approach combines all those features and extends traceability to the source code level, incorporating static code analysis. As part of our approach we introduce the "ASSUME Static Code Analysis tool exchange format" that facilitates the comparability of different static code analysis results. We demonstrate how this approach enhances the usability and efficiency of static code analysis in a development process. On the one hand, our approach enables the exchange of results and evaluations between static code analysis tools. On the other hand, it enables a complete traceability between requirements, designs, implementation, and the results of static code analysis. Within our approach we also propose an OSLC specification for static code analysis tools and an OSLC communication framework.
title Integrating Static Code Analysis Toolchains
topic Software Engineering
url https://arxiv.org/abs/2403.05986