A synopsis of static analysis alerts on open source software

Proceedings of the 6th Annual Symposium on Hot Topics in the Science of Security(2019)

引用 2|浏览68
暂无评分
摘要
Static application security testing (SAST) tools detect potential code defects (alerts) without having to execute the code. SASTs are now widely used in practice by both commercial and open source software (OSS). Prior work found that half of the state-of-the-art OSS projects have already employed automated static analysis [1]. However, little public information is available regarding the actionability (important to developers to act upon) of SAST alerts.
更多
查看译文
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要