Static Analysis Deployment Pitfalls

02/26/2022
by   Flash Sheridan, et al.
0

Organizational, political, and configuration mistakes in the deployment of a static source code analysis tool within a software development organization can result in most of the value of the tool being lost, even while apparently meeting management goals. A list of pitfalls encountered as a static analysis consultant is presented, with discussion of techniques for avoiding or mitigating them. This is part of a work in progress, tentatively entitled "Handbook of Static Analysis Deployment."

READ FULL TEXT

page 1

page 2

page 3

research
02/24/2022

Deploying Static Analysis

Static source code analysis is a powerful tool for finding and fixing bu...
research
05/23/2018

Evaluation of Static Analysis Tools for Finding Vulunerbailities in Java and C/C++ Source Code

It is quite common for security testing to be delayed until after the so...
research
05/04/2021

Interactive Static Software Performance Analysis in the IDE

Detecting performance issues due to suboptimal code during the developme...
research
09/29/2020

Automatically Tailoring Static Analysis to Custom Usage Scenarios

In recent years, there has been significant progress in the development ...
research
10/27/2021

From Complexity Measurement to Holistic Quality Evaluation for Automotive Software Development

In recent years, the role and the importance of software in the automoti...
research
03/22/2021

ConfInLog: Leveraging Software Logs to Infer Configuration Constraints

Misconfigurations have become the dominant causes of software failures i...
research
07/22/2018

Adaptive Target Tracking with a Mixed Team of Static and Mobile Guards: Deployment and Activation Strategies

This work explores a variation of the art gallery problem in which a tea...

Please sign up or login with your details

Forgot password? Click here to reset