版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、Top 10 User Mistakes with Static AnalysisSate IVMarch 2012Parasoft Proprietary and ConfidentialAbout ParasoftFounded in 198727+ Patents for automated quality processesBuild quality into the processStatic Analysis tools since 1994What IS Static Analysis?Variety of methodsPeer Review / Manual Code Rev
2、iew / Code InspectionPattern-based code scannersFlow-based code scannersMetrics-based code scannersCompiler / build outputParasoft Proprietary and ConfidentialNumber 10: Developers10) Developers not included in process evolutionDeveloper InsightsRules / Issues drive needWorkflowUsabilityCorrectness
3、/ NoiseWill our engineers really adopt it and use it?Is this a long-term solution?Parasoft Proprietary and ConfidentialCode Analysis Perceptions“Static analysis is a pain”False positives has varying definitionsI dont like itIt was wrongParasoft Proprietary and ConfidentialPattern based false positiv
4、esTrue false positives generally rule deficiencyContextDoes this apply here and now?In-code suppressions to document decisionParasoft Proprietary and ConfidentialFlow Analysis False PositivesFalse positives are inevitableFinds real bugsFlow analysis is not comprehensiveParasoft Proprietary and Confi
5、dentialNumber 9: Expectations9) Wrong expectationsWhy do static analysis?Because its the right thing?Increase quality?Decrease costs?Reduce development time?Flow analysis is enoughWhen will it pay-off?How can I tell its paying off?Parasoft Proprietary and ConfidentialNumber 8: Approach8) Taking an a
6、udit approachRunning SA on all your code (Dont)Its all about the reports (Or is it?)Parasoft Proprietary and ConfidentialNumber 7: Too Much7) Starting with too many rulesStatic Analysis is about processIts incrementalAvoid biting off more than you can chewAvoid any rule you wont stop the build forPa
7、rasoft Proprietary and ConfidentialDont Get Run OverSame set of rules for everyoneSmall set of rulesLess rules that are followed is better than more that are notIf you wouldnt fix it, dont check for itParasoft Proprietary and ConfidentialNumber 6: Workflow6) Workflow integrationHas to work with your
8、 development UISame configuration for desktop and serverMinimize negative impactMinimize time to find / fix violationsParasoft Proprietary and ConfidentialParasoft Proprietary and ConfidentialResults within IDE1Results delivered as uniform view within IDE2Directly access line of code to fix3Check-in
9、Number 5: Training5) Lack of sufficient trainingHow to install the toolHow to configure the toolHow to setup the buildHow to run the toolHow to mitigate violationsHow/when to suppressParasoft Proprietary and ConfidentialNumber 4: Process4) No defined processDevelopers are not necessarily process exp
10、ertsProcess should minimize impact of SAConsistent for teams and projectsVetted in a pilot projectParasoft Proprietary and ConfidentialNumber 3: Automation3) No automated process enforcementReduce effortConsistencyComplianceParasoft Proprietary and ConfidentialNumber 2: Policy2) Lack of a clear poli
11、cyWhat teams need to do SA?What projects require SA?What rules are required?What amount of compliance?When can you suppress?How to handle legacy code?Do you ship with SA violations?Parasoft Proprietary and ConfidentialNumber 1: Management1) Lack of management buy-inRequirementsAllowed timeUnderstand
12、ing of the ROIEnforcementParasoft Proprietary and ConfidentialThe Whole Top 1010) Developers not included in process evolution9) Wrong expectations8) Taking an audit approach7) Starting with too many rules6) Workflow integration5) Lack of sufficient training4) No defined process3) No automated proce
13、ss enforcement2) Lack of a clear policy1) Lack of management buy-inParasoft Proprietary and ConfidentialHonorable Mention: The Wrong StuffWrong ToolWrong ProcessEmail reportsBlockingPainful CI workflowWrong RulesUnimportant rulesToo many rulesWrong CodeLegacy strategyDont test what you wont / cant c
14、hangeParasoft Proprietary and ConfidentialHonorable Mention: Whats LackingLack of management buy-inThe edictAllowed time & budgetLack of development buy-inWillful non-complianceLack of trainingParasoft Proprietary and ConfidentialQ&A / Further ReadingParasoft Proprietary and Confidential Automated Defect Prevention (Huizinga & Kolawa)Principles and processes to improve the software development process. Effective C+ / More Effective C+ (Meye
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2026年云南省泸水市高二生物下册期末考试检测卷附答案(轻巧夺冠)
- 2026年肇东市骨伤医院医护人员招聘笔试备考题库及答案解析
- 2026年荆州市第五医院医护人员招聘笔试备考题库及答案解析
- 2026河北保定市发展投资有限责任公司社会招聘5人笔试模拟试题及答案详解
- 2026年甘肃省天水慈康医院招聘笔试模拟试题及答案详解
- 2026年辽阳市白癜风研究所医护人员招聘笔试备考题库及答案解析
- 2026重庆机场集团有限公司博士后研究人员招聘3人笔试备考题库及答案详解
- 2026江苏南通市通州区部分事业单位(医疗卫生类岗位)招聘工作人员60人笔试备考试题及答案详解
- 2026陕西西安市雁塔区小寨路二六二社区卫生服务中心招聘3人笔试备考题库及答案详解
- 2026贵州安顺市老年大学面向社会招募兼职教师笔试备考题库及答案详解
- 2026-2030中国染发剂行业现状调查与发展前景预测分析研究报告
- 雨课堂学堂在线学堂云《自然辩证法概论(北京航空航天)》单元测试考核答案
- GB/T 15153.1-2024远动设备及系统第2部分:工作条件第1篇:电源和电磁兼容性
- 宿迁骆马湖旅游规划方案
- 腹股沟嵌顿疝的护理
- 《卫生监督协管培训》课件
- 建设单位工程通知单
- 砂浆回弹计算表(正算)
- 2022年黄陵县小升初英语考试试题及答案解析
- GB/T 34881-2017产品几何技术规范(GPS)坐标测量机的检测不确定度评估指南
- GB/T 2305-2000化学试剂五氧化二磷
评论
0/150
提交评论