Staattisen analyysin työkalut ohjelmistokehityksessä

Kuokkala, Juha · Aaltodoc (Aalto University) · 2010

Static code analysis comprises techniques which statically examine a piece of computer program code and make inferences about its dynamic, run-time behaviour. Static analysis methods have a wide range of applications in software quality assurance. A significant amount of these are tools which can be used by software developers to test and check their code during the implementation. This thesis gives an overview of automatic code analysis techniques, with focus on static analysis methods and the use of them in assistance of software development. A review is made on the current supply of static analysis tools as well as experiences and research on the usefulness of this kind of methods and tools in software development. Finally, a case study is carried out with two automatic analysis tools attached to a Continuous Integration server used in a commercial software development process. The benefits and shortcomings of the tools are assessed, and suggestions for future development are given. The most important results of the study include:. 1. Static code analysis can be a useful tool when used wisely. The results of automated analysis should not be taken without critique, but common sense should be used. 2. Static analysis is most efficient when applied regularly on all parts of a code base from the very beginning of its development. When analysis runs are started on a code base with long history, the overwhelming number of warnings issued makes it difficult to find a starting point for making improvements. 3. Static code analysis should be made as automated and easy-to-use as possible. This involves making the analyses run as a part of the Continuous Integration process and send direct feedback to developers whose recent code changes have deteriorated the code.

Read the paper · More papers on PaperTik