静态代码分析中可能存在的10大错误_第1页
静态代码分析中可能存在的10大错误_第2页
静态代码分析中可能存在的10大错误_第3页
静态代码分析中可能存在的10大错误_第4页
静态代码分析中可能存在的10大错误_第5页
已阅读5页,还剩17页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

1、Top 10 User Mistakes with Static AnalysisSate IVMarch 2012Parasoft Proprietary and ConfidentialAbout ParasoftFounded in 198727+ Patents for automated quality processesBuild quality into the processStatic Analysis tools since 1994What IS Static Analysis?Variety of methodsPeer Review / Manual Code Rev

2、iew / Code InspectionPattern-based code scannersFlow-based code scannersMetrics-based code scannersCompiler / build outputParasoft Proprietary and ConfidentialNumber 10: Developers10) Developers not included in process evolutionDeveloper InsightsRules / Issues drive needWorkflowUsabilityCorrectness

3、/ NoiseWill our engineers really adopt it and use it?Is this a long-term solution?Parasoft Proprietary and ConfidentialCode Analysis Perceptions“Static analysis is a pain”False positives has varying definitionsI dont like itIt was wrongParasoft Proprietary and ConfidentialPattern based false positiv

4、esTrue false positives generally rule deficiencyContextDoes this apply here and now?In-code suppressions to document decisionParasoft Proprietary and ConfidentialFlow Analysis False PositivesFalse positives are inevitableFinds real bugsFlow analysis is not comprehensiveParasoft Proprietary and Confi

5、dentialNumber 9: Expectations9) Wrong expectationsWhy do static analysis?Because its the right thing?Increase quality?Decrease costs?Reduce development time?Flow analysis is enoughWhen will it pay-off?How can I tell its paying off?Parasoft Proprietary and ConfidentialNumber 8: Approach8) Taking an a

6、udit approachRunning SA on all your code (Dont)Its all about the reports (Or is it?)Parasoft Proprietary and ConfidentialNumber 7: Too Much7) Starting with too many rulesStatic Analysis is about processIts incrementalAvoid biting off more than you can chewAvoid any rule you wont stop the build forPa

7、rasoft Proprietary and ConfidentialDont Get Run OverSame set of rules for everyoneSmall set of rulesLess rules that are followed is better than more that are notIf you wouldnt fix it, dont check for itParasoft Proprietary and ConfidentialNumber 6: Workflow6) Workflow integrationHas to work with your

8、 development UISame configuration for desktop and serverMinimize negative impactMinimize time to find / fix violationsParasoft Proprietary and ConfidentialParasoft Proprietary and ConfidentialResults within IDE1Results delivered as uniform view within IDE2Directly access line of code to fix3Check-in

9、Number 5: Training5) Lack of sufficient trainingHow to install the toolHow to configure the toolHow to setup the buildHow to run the toolHow to mitigate violationsHow/when to suppressParasoft Proprietary and ConfidentialNumber 4: Process4) No defined processDevelopers are not necessarily process exp

10、ertsProcess should minimize impact of SAConsistent for teams and projectsVetted in a pilot projectParasoft Proprietary and ConfidentialNumber 3: Automation3) No automated process enforcementReduce effortConsistencyComplianceParasoft Proprietary and ConfidentialNumber 2: Policy2) Lack of a clear poli

11、cyWhat teams need to do SA?What projects require SA?What rules are required?What amount of compliance?When can you suppress?How to handle legacy code?Do you ship with SA violations?Parasoft Proprietary and ConfidentialNumber 1: Management1) Lack of management buy-inRequirementsAllowed timeUnderstand

12、ing of the ROIEnforcementParasoft Proprietary and ConfidentialThe Whole Top 1010) Developers not included in process evolution9) Wrong expectations8) Taking an audit approach7) Starting with too many rules6) Workflow integration5) Lack of sufficient training4) No defined process3) No automated proce

13、ss enforcement2) Lack of a clear policy1) Lack of management buy-inParasoft Proprietary and ConfidentialHonorable Mention: The Wrong StuffWrong ToolWrong ProcessEmail reportsBlockingPainful CI workflowWrong RulesUnimportant rulesToo many rulesWrong CodeLegacy strategyDont test what you wont / cant c

14、hangeParasoft Proprietary and ConfidentialHonorable Mention: Whats LackingLack of management buy-inThe edictAllowed time & budgetLack of development buy-inWillful non-complianceLack of trainingParasoft Proprietary and ConfidentialQ&A / Further ReadingParasoft Proprietary and Confidential Automated Defect Prevention (Huizinga & Kolawa)Principles and processes to improve the software development process. Effective C+ / More Effective C+ (Meye

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

最新文档

评论

0/150

提交评论