2019 IEEE/ACM 16th International Conference on Mining Software Repositories (MSR) 2019
DOI: 10.1109/msr.2019.00049
|View full text |Cite
|
Sign up to set email alerts
|

Challenges with Responding to Static Analysis Tool Alerts

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
17
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
5
3

Relationship

0
8

Authors

Journals

citations
Cited by 33 publications
(17 citation statements)
references
References 17 publications
0
17
0
Order By: Relevance
“…Researchers have also studied the topics developers talk about; including analysis with natural language processing techniques (NLP) [5,16,18,56,71,76] and manual qualitative techniques [18,36,43,44,47,48,52,55,71]. For example, an analysis of questions about Puppet, a configuration language tool, shows a need to support Puppet syntax error finding [55].…”
Section: Stack Overflowmentioning
confidence: 99%
“…Researchers have also studied the topics developers talk about; including analysis with natural language processing techniques (NLP) [5,16,18,56,71,76] and manual qualitative techniques [18,36,43,44,47,48,52,55,71]. For example, an analysis of questions about Puppet, a configuration language tool, shows a need to support Puppet syntax error finding [55].…”
Section: Stack Overflowmentioning
confidence: 99%
“…The experience the organisation has had with program analysis is similar to that described in the literature [1]- [3]. This has lead to practices where teams reduce the noise by a limited selection of analyzers (Finding 2).…”
Section: III Discussionmentioning
confidence: 79%
“…Program analysis tools can provide useful information to help software developers improve performance, make code more maintainable, fix bugs and perform many other tasks. However, the use of program analysis results is hindered by a number of usability issues [1]- [3]. These include distracting false positives, incomprehensible messages, and poor integration into developer's workflows.…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…To select which SATs to use in the study, we made a list of SATs that appeared in: (1) SAT benchmark papers [43,79], (2) developer studies [6,88], and (3) Stack Overflow discussions about SATs [47]. Then, we filtered for SATs that appeared in more than one source and had pre-written security rules capable of detecting a range of vulnerabilities.…”
Section: Tool Selectionmentioning
confidence: 99%