论文标题

部署静态分析

Deploying Static Analysis

论文作者

Sheridan, Flash

论文摘要

静态源代码分析是适当部署时查找和修复错误的强大工具;但是,以表面上看起来不错的方式部署它非常容易,但是错过了重要的缺陷,显示了许多误报,并使该工具变成了不知不觉。本文是在大型组织中部署静态分析工具的过程的指南,同时避免了最糟糕的组织和技术陷阱。我的要点是要专注于确定错误的主要目标的重要性,与在此过程中会出现的所有竞争较小的目标相比。

Static source code analysis is a powerful tool for finding and fixing bugs when deployed properly; it is, however, all too easy to deploy it in a way that looks good superficially, but which misses important defects, shows many false positives, and brings the tool into disrepute. This article is a guide to the process of deploying a static analysis tool in a large organization while avoiding the worst organizational and technical pitfalls. My main point is the importance of concentrating on the main goal of getting bugs fixed, against all the competing lesser goals which will arise during the process.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源