5 个仓库
Static analysis techniques that differentiate between different call sites of the same function to improve precision.
Distinct from Context-Sensitive: The candidates are focused on autocomplete or hotkeys, not static analysis precision.
Explore 5 awesome GitHub repositories matching programming languages & runtimes · Context-Sensitive Analysis. Refine with filters or upvote what's useful.
Semantic 是一个基于 Haskell 的库和命令行工具,专为多语言源代码分析而设计。它作为一个静态程序分析框架和多语言抽象语法树解析器,能够根据语法定义将多种编程语言转换为结构化的语法树。 该系统通过一个语义代码比较引擎脱颖而出,该引擎检测代码版本之间的结构和意义变化,而不是依赖文本差异。它进一步通过将表面语言转换为统一的多语言中间表示,实现了跨不同编程语法的分析。 该框架为解析 Rust、Go、Python、Ruby、PHP、TypeScript 和 TSX 等语言提供了广泛的功能。它涵盖了通过代码作用域映射、符号提取和语义图生成的语义分析,以及用于模式分析和程序行为评估的工具。 该工具集还包括用于标准化 Haskell 源代码文件布局的命令行实用程序。
Adjusts the performance and sensitivity of program analyses to balance speed against result detail.
Cppcheck 是一个用于 C 和 C++ 源代码的静态分析工具和检查器,旨在在不执行程序的情况下检测编程错误、内存泄漏和安全违规。它作为一个错误检测引擎和质量保证工具,用于识别并发问题、类型转换错误以及对安全编码标准的合规性。 该项目提供了一个用于选择文件和审查错误的图形用户界面,以及一个用于强制执行命名约定和编码标准的检查器。它支持使用正则表达式创建自定义分析规则,以识别特定的编码模式。 该工具包括增量分析、警告抑制和文件排除功能,以管理大型代码库。它还具有 HTML 报告生成功能,并与 VS Code 等编辑器集成,以便在开发过程中提供错误识别。
Allows adjusting analysis precision and depth to balance the trade-off between detection thoroughness and execution speed.
SpotBugs 是一个针对 Java 应用程序的静态分析工具和字节码分析器。它扫描编译后的类文件以识别错误、安全漏洞和性能问题,而无需执行代码。该系统既是错误检测器,也是静态应用程序安全测试 (SAST) 工具,用于定位逻辑错误和 API 滥用。 该项目凭借插件式检测器架构脱颖而出,允许集成外部库以添加自定义检测规则。它为 SQL 注入、跨站脚本 (XSS) 和路径遍历等漏洞提供了专门的安全审计,并具有用于优化分析精度和减少误报的模块化系统。 该工具涵盖了广泛的检测领域,包括并发同步错误、空指针解引用、资源泄漏和类型转换错误。它还识别死代码、性能低效以及违反序列化惯例的情况。这些功能可通过命令行界面、图形用户界面以及集成开发环境 (IDE) 的直接集成来访问。 SpotBugs 可以集成到构建流水线中以强制执行质量门禁,并生成 HTML 或 XML 格式的分析报告。
Balances memory usage and computation cost by toggling interprocedural tracking and exception modeling.
Nilaway is a static analysis tool and linter plugin for Go designed to identify potential nil pointer dereferences in source code to prevent runtime panics. It functions as an inter-procedural pointer analyzer that tracks data flow across functions and packages to detect memory safety issues. The tool differentiates itself by tracking pointer states through anonymous functions, closures, and struct initializations. It employs a pointer analysis framework that monitors how values flow through a program to determine if a variable is safe to dereference at a specific point. The analyzer can be
Implements context-sensitive modeling to differentiate between function calls and reduce false positives.
SVF is an open-source static program analysis framework and points-to analysis library that tracks memory references, variable aliases, and data dependencies across whole programs. The platform translates compiled intermediate code formats into unified internal representations, constructing constraint graphs, call graphs, and control-flow graphs to model interprocedural execution behavior and memory state. The framework incorporates specialized engines for flow-sensitive, flow-insensitive, and context-sensitive pointer analysis alongside sparse value-flow graph generation. It features memory
Determines points-to relationships using customizable data structures and algorithms such as flow-sensitive solvers.