• Skip to main content
  • Skip to secondary menu
  • Skip to footer

OSINT.org

Intelligence Matters

  • Sponsored Post
    • Make a Contribution
  • Market Intelligence
    • Technologies
    • Events
  • Domain Intelligence
  • About
    • GDPR
  • Contact

DHS Funding Transitioning into Real World Collaboration through SARIF

March 9, 2020 By admin Leave a Comment

With funding from the Department of Homeland Security (DHS), GrammaTech has worked to enable open source static analysis tools to generate and consume results in the open SARIF format. Building on this work, GrammaTech has now released a tool to support SARIF-based integration of static analysis results with GitHub.

Currently, open source and commercial static analysis tools use proprietary formats to display and store their results. This makes it hard to integrate results from a static analysis tool into an Integrated Development Environment (IDE), code review tool, or a source code management and version control platform such as GitHub.

SARIF (pronounced SA-rif), which stands for Static Analysis Results Interchange Format, is a standard developed and managed by the OASIS group. SARIF makes it easier for tools to collaborate in a unified software development environment around the topic of static analysis. For more information on SARIF, you can visit the OASIS website and view the SARIF specification.

GrammaTech, with funding provided by the DHS Science & Technology Directorate Static Analysis Tools Modernization Project (STAMP) program, has previously implemented SARIF support for open-source static analyzers such as Clang Static Analyzer, Pylint, and several others. Broad SARIF support allows software development teams to pick and choose the tools that they want and integrate them into a best-of-breed DevOps environment.

In order to further support the SARIF ecosystem, GrammaTech has now released a tool that allows developers to view static analysis results as part of their code review workflow, within GitHub pull requests. Evidence from real-world industry practice indicates that such an integration significantly increases the adoption of static analysis, contributing to improved code quality and safety. The tool is available as open-source software, and was featured in a publication at the TechDebt ’19 conference.

“GrammaTech strongly believes in collaboration using open standards,” says Vince Arneja, Chief Product Officer at GrammaTech. “GrammaTech CodeSonar imports and exports SARIF, and through that, can collaborate with Microsoft’s IDEs, GitHub, Clang Static Analyzer, Pylint, ESlint and other tools that support SARIF.”

This work is based on research sponsored by the Department of Homeland Security (DHS) Science and Technology Directorate (contract numbers HHSP233201600062C 70RSAT19C00000056). The views and conclusions contained herein are those of the authors and should not be interpreted as necessarily representing the official policies or endorsements, either expressed or implied, of the Department of Homeland Security.

SOURCE GrammaTech
http://www.grammatech.com

Filed Under: Workflow Tagged With: open source, static analysis tools

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • The Collapse of Assad’s Regime: The Beginning of the End for Iran’s So-Called Axis of Resistance
  • Cognyte Intelligence Summit 2024: Transforming Global Security with AI-Powered Insights
  • Strategic Concerns Over Peru’s New Port: A Growing Debate on China’s Influence
  • Entry instructions to Nasrallah’s bunker containing more than half a billion dollars in gold and dollars
  • The former Obama AG suing U.S. government on behalf of Chinese military company DJI
  • The Cowardice of Sinwar: Fleeing Accountability and Meeting a Fitting End
  • Deployment of missile interceptor system to Israel in preparation for strike on Iran
  • In 2024, Qatar pledged to invest €10B in the French economy.
  • Eliminated the terrorist Hader Ali Taweel, who served as the Kfarkela Company Commander of the Hezbollah
  • The IDF and ISA Eliminated Rawhi Mushtaha, Head of Hamas Government in Gaza Strip

Media Partners

  • Analysis.org
  • Opinion.org
Apple’s Strategic Pivot: Reshaping Its Supply Chain from China to India
Asana’s Q4 2025 Results Signal Strengthened Financials and Strategic Gains from AI Integration
Snowflake Reports Fourth Quarter and Full-Year Fiscal 2025 Financial Results
Dropbox, Inc. Reports Fourth Quarter and Full Year 2024 Financial Results
Circle’s Digital Dollar: A New Era in Stable Cryptocurrencies
Cloudflare as a Pillar of AI Infrastructure: Paving the Way to $240 and Beyond
monday.com Posts Strong Q4 and Fiscal Year 2024 Results with Bold AI Ambitions for 2025
Economic Forecasts in Flux: Blue Chip Indicators Highlight Post-Election Uncertainty and AI Disruption
Americans Grapple with the True Cost of Living
Pyramid Analytics Secures $50M in Financing from BlackRock to Accelerate AI-Driven Analytics
Understanding the Concept of a Deep State
Bessent Urges Canada to Follow Mexico in Adopting China Tariffs
Europe’s Empty Words Will Not Save Ukraine
Zelensky Stands Firm Against White House Pressure
Shifting Trade Winds: The Uncertain Future of U.S.-China Economic Ties
Iran’s Strategic Dilemma After the Fall of Assad
The Unraveling of Putin’s Geopolitical Strategy in the Wake of Assad’s Fall
The Collapse of the Assad Regime: A Turning Point for Syria and the Region
Family of Journalist Dong Yuyu Condemns Espionage Conviction as a Grave Injustice
Putin’s Economic House of Cards: The Slow Collapse of a Despotic Gamble

Media Partners

  • Market Analysis
  • Market Research Media
China’s Strategic Shift to RISC-V: Market Implications and Growth Prospects
Understanding Transfer Pricing: A Key Component of Multinational Business Operations
A Comprehensive Tour of Project Management Tools and Integration Platforms
Implementing Odoo ERP in a Small Manufacturing Enterprise: Costs and Considerations
Economic Optimism Meets Uncertainty: Blue Chip Indicators Highlight Post-Election Fiscal Concerns and AI’s Looming Impact
The Future of Connectivity: Insights from Ericsson’s November 2024 Mobility Report
Platinum Market Faces Sustained Deficit Amidst Strong Demand and Constrained Supply
Breaking Beijing’s Grip: U.S. and Australia Unite Against China’s Rare Earth Monopoly
Global AI-Powered Accounting and Audit Services Market Analysis 2023-2030: Growth, Trends, and Forecast
The Re-Emergence of PHP
The Rise of Headless Content Frameworks in Distributed Media Projects
Developing Web Projects: From Concept to Launch
The Rise of APS-C Cameras: A Professional Renaissance in Photography
Market Brief: Disruption in Spanish Orange Supply Chain and Strategic Response by UK Retailers
Global AI-Powered Movie Scenario Market Analysis 2023-2030: Growth, Trends, and Forecast
Market Research Report: US Government Cybersecurity Market in 2024
Market Research Report: Global Advertising Revenue Projections and Trends in the Entertainment & Media Industry
Social Media: The Rise of Formulaic Content
Netflix’s Creative Decline: The Rise of Formulaic Content
The Transformation of Media: Navigating the Waning Allure of Social Platforms

Copyright © 2022 OSINT.org

Technologies, Market Analysis & Market Research and Exclusive Domains