How Open Source Projects Use Static Code Analysis Tools in Continuous Integration Pipelines

How Open Source Projects Use Static Code Analysis Tools in Continuous Integration Pipelines
复制标题

开源项目如何在持续集成管道中使用静态代码分析工具

DOI:
--
复制
发表时间:
2017
期刊:
IEEE Working Conference on Mining Software Repositories
影响因子:
--
通讯作者:
M. D. Penta
M. D. Penta
中科院分区:
--
文献类型:
--
作者:
Fiorella Zampetti;Simone Scalabrino;Rocco Oliveto;G. Canfora;M. D. Penta

文献摘要

被引文献

相似文献

软件开发人员通常会使用静态分析工具来早日检测潜在的故障,漏洞,代码气味,或评估源代码遵守编码标准和准则。同样,研究人员和从业人员提倡它们在连续集成(CI)管道中的采用。本文研究了在GitHub上托管的20个Java开源项目中使用静态分析工具的用法,并将Travis CI用作连续集成基础架构。具体而言,我们调查(i)使用哪些工具以及如何为CI配置它们,(ii)哪些类型的问题会导致构建失败或提高警告,以及(iii)是否,如何以及之后被损坏了多长时间构建和警告解决了。结果表明,在分析的项目中,由于静态分析工具而建立断裂,这主要与遵守编码标准有关,并且对丢失许可证也有一些关注。与识别潜在错误或漏洞的工具相关的构建故障发生频率较低,在某些情况下,这种工具以“较软”模式激活,而不会使构建失败。此外,该研究表明,由于静态分析工具而引起的构建断裂可以通过实际解决该问题而不是通过禁用警告来快速固定,并且经常被正确记录。
Static analysis tools are often used by software developers to entail early detection of potential faults, vulnerabilities, code smells, or to assess the source code adherence to coding standards and guidelines. Also, their adoption within Continuous Integration (CI) pipelines has been advocated by researchers and practitioners. This paper studies the usage of static analysis tools in 20 Java open source projects hosted on GitHub and using Travis CI as continuous integration infrastructure. Specifically, we investigate (i) which tools are being used and how they are configured for the CI, (ii) what types of issues make the build fail or raise warnings, and (iii) whether, how, and after how long are broken builds and warnings resolved. Results indicate that in the analyzed projects build breakages due to static analysis tools are mainly related to adherence to coding standards, and there is also some attention to missing licenses. Build failures related to tools identifying potential bugs or vulnerabilities occur less frequently, and in some cases such tools are activated in a "softer" mode, without making the build fail. Also, the study reveals that build breakages due to static analysis tools are quickly fixed by actually solving the problem, rather than by disabling the warning, and are often properly documented.