• Skip to main content
  • Skip to secondary menu
  • Skip to footer

OSINT.org

Intelligence Matters

  • Sponsored Post
  • About
    • GDPR
  • Contact

DHS Funding Transitioning into Real World Collaboration through SARIF

March 9, 2020 By admin Leave a Comment

With funding from the Department of Homeland Security (DHS), GrammaTech has worked to enable open source static analysis tools to generate and consume results in the open SARIF format. Building on this work, GrammaTech has now released a tool to support SARIF-based integration of static analysis results with GitHub.

Currently, open source and commercial static analysis tools use proprietary formats to display and store their results. This makes it hard to integrate results from a static analysis tool into an Integrated Development Environment (IDE), code review tool, or a source code management and version control platform such as GitHub.

SARIF (pronounced SA-rif), which stands for Static Analysis Results Interchange Format, is a standard developed and managed by the OASIS group. SARIF makes it easier for tools to collaborate in a unified software development environment around the topic of static analysis. For more information on SARIF, you can visit the OASIS website and view the SARIF specification.

GrammaTech, with funding provided by the DHS Science & Technology Directorate Static Analysis Tools Modernization Project (STAMP) program, has previously implemented SARIF support for open-source static analyzers such as Clang Static Analyzer, Pylint, and several others. Broad SARIF support allows software development teams to pick and choose the tools that they want and integrate them into a best-of-breed DevOps environment.

In order to further support the SARIF ecosystem, GrammaTech has now released a tool that allows developers to view static analysis results as part of their code review workflow, within GitHub pull requests. Evidence from real-world industry practice indicates that such an integration significantly increases the adoption of static analysis, contributing to improved code quality and safety. The tool is available as open-source software, and was featured in a publication at the TechDebt ’19 conference.

“GrammaTech strongly believes in collaboration using open standards,” says Vince Arneja, Chief Product Officer at GrammaTech. “GrammaTech CodeSonar imports and exports SARIF, and through that, can collaborate with Microsoft’s IDEs, GitHub, Clang Static Analyzer, Pylint, ESlint and other tools that support SARIF.”

This work is based on research sponsored by the Department of Homeland Security (DHS) Science and Technology Directorate (contract numbers HHSP233201600062C 70RSAT19C00000056). The views and conclusions contained herein are those of the authors and should not be interpreted as necessarily representing the official policies or endorsements, either expressed or implied, of the Department of Homeland Security.

SOURCE GrammaTech
http://www.grammatech.com

Filed Under: Workflow Tagged With: open source, static analysis tools

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • CentralSquare Technologies Acquires FirstTwo to Advance Real-Time Intelligence for First Responders
  • IMINT Brief: Virgin Galactic–LLNL High-Altitude Sensor Collaboration
  • Palantir Renews DGSI Contract, 3 Years, France
  • Global OSINT SitRep — War Maps, Shadow Fleets, Deepfakes, and the New Intelligence Battleground
  • OSINT Watch: A Quick Sweep Through the Latest Open-Source Intelligence Headlines
  • How AI-Driven Commerce Redefined Holiday Shopping
  • The Green Boxes That Could Tip a Global Power Balance
  • Antithesis Raises $105M to Push Deterministic Simulation Into the Mainstream
  • BlighterNexus Track: Real-Time Tracking Gets a Smarter Edge
  • Feasibly, Launch Day — AI Meets Real Estate Feasibility

Media Partners

  • Analysis.org
  • Opinion.org
Cisco Is Not in a Breakthrough
Why Broadcom Is Slipping in Pre-Market Trading Today
Oracle’s Post-Earnings Selloff: What’s Really Behind the 10% Pre-Market Drop
AVAV’s Valuation Shift: From Niche UAV Supplier to Scaled Defense Systems Integrator
Adobe Buyback Momentum Fuels a Sharp Afternoon Rally
Cross-Border Private Credit Expected to Surge, but Operational Risks Loom
Salesforce Q3 FY26: A Strong AI-Driven Quarter With Big ARR Gains — And A Market Ready To Debate The Next Leg Up
Snowflake Q3 FY26: Solid AI Momentum, Healthier Margins — And A Market Struggling To Reprice The Story
Why the Suez Canal Emptied: Security Shock First, Economy Second
Broadcom’s Slide and the Shift in Market Expectations
How a Quack Ended Up Steering National Health — And Why the Hepatitis B Rollback Is a Dangerous Farce
Europe’s Telecom Awakening — The Huawei Breakup Feels a Lot Like the Russian Gas Divorce
Woke Journalism as a Camouflaged Form of Anarchism
Israel Surrounded by Failed States
It Was Qatar All Along: Qatar’s Network of Influence and the Long Campaign Against Israel and the West
Photo of the Day: Pro-Palestinian Mobs Harassing European Cities
Hamas’s “Yes” That Really Means “No”
Spain’s Boom Is a Corruption-Fueled Illusion
Europe to Erdogan: Don’t Teach Us How to Eat
Europe’s Imported Illusion: He must be an engineer

Media Partners

  • Market Analysis
  • Market Research Media
Will It Save Intel? The $1.6B SambaNova Question
Crisp’s $26M Series B1 Shows Why Vertical AI Is Pulling Ahead
Europe’s Spectrum Trap: How Smarter Policy Could Unlock a €75 Billion 5G Boost
Airwallex’s $330M Series G: The New Gravity Center of Borderless Finance
InterAcademic.com — Where Institutions Connect and Ideas Travel Further
Salesforce Q3 FY26: Agentic AI Momentum in a Slower-Growth World
Housing Inventory Stalls as Buyers Retreat and Sellers Lose Confidence
Rio Tinto’s First Nuton® Copper in Arizona Marks a Quiet Technological Turning Point for U.S. Copper Supply
Next-Gen Nuclear Could Transform Emerging Economy Power Grids
Diamond Market, November 2025 — A Cooling Curve for Small Stones, Steady Ground for Big Gems
PlayStation and the Quiet Power Center of a $200 Billion Gaming Industry
Adobe FY2025: AI Pulls the Levers, Cash Flow Leads the Story
Canva’s 2026 Creative Shift and the Rise of Imperfect-by-Design
fal Raises $140M Series D: Scaling the Core Infrastructure for Real-Time Generative Media
Gaming’s Next Expansion Wave, 2026–2030
Morphography — A Visual Language for the Next Era of AI
Netflix’s $83B Grab for Warner Bros. & HBO: A Tectonic Shift in Global Media
Clipbook Raises $3.3M Seed Round — And the PR World Just Got a Warning Shot
BrandsToShop.com — the right domain to have for Cyber Monday, Black Friday and every loud shopping season ahead
PressEspresso.com

Copyright © 2022 OSINT.org

Technologies, Market Analysis & Market Research and Exclusive Domains