PofoliaPofolia ile paylaşıldı

ACM Transactions on Software Engineering and Methodology· 2026Q1

Statik Kod Analizörleri Hataları Gözden Kaçırıyor: Tarihsel Sorunlar Zayıflıkları Ortaya Koyuyor

An Empirical Study of False Negatives and Positives of Static Code Analyzers From the Perspective of Historical Issues

Han Cui, Jingjing Liang, Menglei Xie, Jiahao Peng ve diğerleri

Kısa özet

Dört Java statik kod analizöründen (PMD, SpotBugs, SonarQube, ErrorProne) elde edilen 1257 tarihsel yanlış negatif ve pozitifin incelenmesi, gözden kaçan hataların temel nedenlerini ve özelliklerini ortaya koyarak, 9'u zaten düzeltilmiş 15 yeni sorun bulan yeni bir test stratejisine yol açtı.

Yapay zekâ ile başlık ve abstract'tan üretildi; tam metin okunmaz.

Ana noktalar

  • PMD, SpotBugs, SonarQube ve ErrorProne'dan doğrulanmış ve düzeltilmiş 1257 yanlış negatif/pozitif analiz edildi.
  • Bu statik analiz hataları için temel nedenler ve sorun tetikleyen programların özellikleri araştırıldı.
  • Çalışma bulgularına dayanan bir metamorfik test stratejisi geliştirildi.
  • Yeni strateji, geliştiriciler tarafından zaten düzeltilmiş olan 9'u dahil 15 yeni yanlış negatif/pozitif buldu.

Yapay zekâ ile başlık ve abstract'tan üretildi; tam metin okunmaz.

Özet (abstract)

Static code analyzers are widely used to help find program flaws. However, in practice the effectiveness and usability of such analyzers is affected by the problems of false negatives (FNs) and false positives (FPs). This paper aims to investigate the FNs and FPs of such analyzers from a new perspective, i.e. , examining the historical issues of FNs and FPs of these analyzers reported by their maintainers, users and researchers in their issue repositories — each of these issues manifested as a FN or FP of these analyzers in the history and has already been confirmed and fixed by the analyzers’ developers. To this end, we conduct the first systematic study on a broad range of 1257 historical issues of FNs/FPs from four popular rule-based static code analyzers for Java ( i.e. , PMD , SpotBugs , SonarQube , and ErrorProne ). All these issues have been confirmed and fixed by the developers. We investigated these issues’ root causes and the characteristics of the corresponding issue-triggering programs. It reveals several new interesting findings and implications on mitigating FNs and FPs. Furthermore, guided by some findings of our study, we designed a metamorphic testing strategy to find FNs and FPs. This strategy successfully found 15 new issues of FNs/FPs, 12 of which have been confirmed and 9 have already been fixed by the developers. Our further manual investigation of the studied analyzers revealed one rule specification issue and additional three FNs/FPs due to the weaknesses of the implemented static analysis. We have made all the artifacts (datasets and tools) publicly available at https://zenodo.org/doi/10.5281/zenodo.11525129 .

Yazarların özeti; kaynağından alınmıştır. ACM Transactions on Software Engineering and Methodology, 2026 · DOI ↗

ÇıkarımlarPremium
Makaleye SorÜcretsiz hesapla

Ücretsiz hesapla devam et

Makaleye Sor ile bu makaleye günde 3 soru ücretsiz; makaleyi kaydet, kaynakçasını al, ilgi alanına göre her gün yeni özetler. Çıkarımlar Premium.

Web'de ücretsiz devam et

Google ya da Apple hesabınla giriş; kart istemez. Bu makaleye geri dönersin.

Telefonda:

Alan: Yazılım

SoftwareComputer Science