Can static analysis tools find more defects?: A qualitative study of design rule violations found by code review

Can static analysis tools find more defects?: A qualitative study of design rule violations found by code review
复制标题

静态分析工具能否发现更多缺陷?:对代码审查发现的设计规则违规的定性研究

DOI:
10.1007/s10664-022-10232-4
复制
发表时间:
2023
影响因子:
4.1
通讯作者:
LaToza, Thomas D.
LaToza, Thomas D.
中科院分区:
计算机科学2区
文献类型:
--
作者:
Mehrpour, Sahar;LaToza, Thomas D.

文献摘要

相似文献

静态分析工具发现代码中的缺陷,对照规则检查代码以揭示潜在的缺陷。许多研究通过测量它们检测代码中已知缺陷的能力来评估这些工具。但这些研究衡量的是工具的当前状态,而不是它们未来发现更多缺陷的潜力。为了调查工具发现更多缺陷的前景,我们进行了一项研究,其中我们将代码审查者提出的每个问题都表述为违反规则,然后将其与静态分析工具可能检查的内容进行比较。我们首先收集了通过代码审查发现的1323个缺陷的语料库。通过定性分析过程,对于每个缺陷,我们确定了违反的规则和可能检查该规则的静态分析工具(SAT)的类型。我们发现,原则上,SAT可能被用来检测多达76%的代码评审缺陷,这比目前已被证明能够成功检测的工具要多得多。在各种类型的SAT中,样式检查器和AST模式检查器的缺陷覆盖面最广,每一种都有可能检测到所有代码审查缺陷的25%。我们发现,通过更好地支持创建特定于项目的规则,静态分析工具可能能够检测到更多的代码审查缺陷。我们还研究了传统静态分析技术无法检测到的代码审查缺陷的特征,要检测这些缺陷可能需要模拟人类对代码的判断的工具。
Static analysis tools find defects in code, checking code against rules to reveal potential defects. Many studies have evaluated these tools by measuring their ability to detect known defects in code. But these studies measure the current state of tools rather than their future potential to find more defects. To investigate the prospects for tools to find more defects, we conducted a study where we formulated each issue raised by a code reviewer as a violation of a rule, which we then compared to what static analysis tools might potentially check. We first gathered a corpus of 1323 defects found through code review. Through a qualitative analysis process, for each defect we identified a violated rule and the type of Static Analysis Tool (SAT) which might check this rule. We found that SATs might, in principle, be used to detect as many as 76% of code review defects, considerably more than current tools have been demonstrated to successfully detect. Among a variety of types of SATs, Style Checkers and AST Pattern Checkers had the broadest coverage of defects, each with the potential to detect 25% of all code review defects. We found that static analysis tools might be able to detect more code review defects by better supporting the creation of project-specific rules. We also investigated the characteristics of code review defects not detectable by traditional static analysis techniques, which to detect might require tools which simulate human judgements about code.