skip to main content
10.1145/1137983.1138014acmconferencesArticle/Chapter ViewAbstractPublication PagesicseConference Proceedingsconference-collections
Article

Tracking defect warnings across versions

Published:22 May 2006Publication History

ABSTRACT

Various static analysis tools will analyze a software artifact in order to identify potential defects, such as misused APIs, race conditions and deadlocks, and security vulnerabilities. For a number of reasons, it is important to be able to track the occurrence of each potential defect over multiple versions of a software artifact understudy: in other words, to determine when warnings reported in multiple versions of the software all correspond the same underlying issue. One motivation for this capability is to remember decisions about code that has been reviewed and found to be safe despite the occurrence of a warning. Another motivation is constructing warning deltas between versions, showing which warnings are new, which have persisted,and which have disappeared. This allows reviewers to focus their efforts on inspecting new warnings. Finally, tracking warnings through a series of software versions reveals where potential defects are introduced and fixed, and how long they persist, exposing interesting trends and patterns.We will discuss two different techniques we have implemented in FindBugs (a static analysis tool to find bugs in Java programs) for tracking defects across versions, discuss their relative merits and how they can be incorporated into the software development process, and discuss the results of tracking defect warnings across Sun's Java runtime library.

References

  1. Bug tracking across multiple code streams? http://ask.slashdot.org/article.pl?sid=05/10/06/2248259&tid=128, 2006.Google ScholarGoogle Scholar
  2. bugzilla.org. http://www.bugzilla.org/, 2006.Google ScholarGoogle Scholar
  3. FindBugs--Find Bugs in Java Programs. http://findbugs.sourceforge.net, 2006.Google ScholarGoogle Scholar
  4. Fortify Software. http://www.fortifysoftware.com, 2006.Google ScholarGoogle Scholar
  5. D. Hovemeyer and W. Pugh. Finding Bugs is Easy. In Companion of the 19th ACM Conference on Object-Oriented Programming, Systems, Languages, and Applications, Vancouver, BC, October 2004. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. Tracking defect warnings across versions

              Recommendations

              Comments

              Login options

              Check if you have access through your login credentials or your institution to get full access on this article.

              Sign in
              • Published in

                cover image ACM Conferences
                MSR '06: Proceedings of the 2006 international workshop on Mining software repositories
                May 2006
                191 pages
                ISBN:1595933972
                DOI:10.1145/1137983

                Copyright © 2006 ACM

                Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

                Publisher

                Association for Computing Machinery

                New York, NY, United States

                Publication History

                • Published: 22 May 2006

                Permissions

                Request permissions about this article.

                Request Permissions

                Check for updates

                Qualifiers

                • Article

                Upcoming Conference

                ICSE 2025

              PDF Format

              View or Download as a PDF file.

              PDF

              eReader

              View online with eReader.

              eReader