• Skip to main content
  • Skip to secondary menu
  • Skip to footer

OSINT.org

Intelligence Matters

  • Sponsored Post
    • Make a Contribution
  • Market Intelligence
    • Technologies
    • Events
  • Domain Intelligence
  • About
    • GDPR
  • Contact

DHS Funding Transitioning into Real World Collaboration through SARIF

March 9, 2020 By admin Leave a Comment

With funding from the Department of Homeland Security (DHS), GrammaTech has worked to enable open source static analysis tools to generate and consume results in the open SARIF format. Building on this work, GrammaTech has now released a tool to support SARIF-based integration of static analysis results with GitHub.

Currently, open source and commercial static analysis tools use proprietary formats to display and store their results. This makes it hard to integrate results from a static analysis tool into an Integrated Development Environment (IDE), code review tool, or a source code management and version control platform such as GitHub.

SARIF (pronounced SA-rif), which stands for Static Analysis Results Interchange Format, is a standard developed and managed by the OASIS group. SARIF makes it easier for tools to collaborate in a unified software development environment around the topic of static analysis. For more information on SARIF, you can visit the OASIS website and view the SARIF specification.

GrammaTech, with funding provided by the DHS Science & Technology Directorate Static Analysis Tools Modernization Project (STAMP) program, has previously implemented SARIF support for open-source static analyzers such as Clang Static Analyzer, Pylint, and several others. Broad SARIF support allows software development teams to pick and choose the tools that they want and integrate them into a best-of-breed DevOps environment.

In order to further support the SARIF ecosystem, GrammaTech has now released a tool that allows developers to view static analysis results as part of their code review workflow, within GitHub pull requests. Evidence from real-world industry practice indicates that such an integration significantly increases the adoption of static analysis, contributing to improved code quality and safety. The tool is available as open-source software, and was featured in a publication at the TechDebt ’19 conference.

“GrammaTech strongly believes in collaboration using open standards,” says Vince Arneja, Chief Product Officer at GrammaTech. “GrammaTech CodeSonar imports and exports SARIF, and through that, can collaborate with Microsoft’s IDEs, GitHub, Clang Static Analyzer, Pylint, ESlint and other tools that support SARIF.”

This work is based on research sponsored by the Department of Homeland Security (DHS) Science and Technology Directorate (contract numbers HHSP233201600062C 70RSAT19C00000056). The views and conclusions contained herein are those of the authors and should not be interpreted as necessarily representing the official policies or endorsements, either expressed or implied, of the Department of Homeland Security.

SOURCE GrammaTech
http://www.grammatech.com

Filed Under: Workflow Tagged With: open source, static analysis tools

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • Cognyte Wins $5M Contract to Power Tactical SIGINT for Major EMEA Military Intelligence Agency
  • Huawei Africa Night 2025: Vision for “New Africa” or Blueprint for Dependency?
  • Longeye Raises $5M to Bring AI-Powered Investigations to Law Enforcement
  • Jared Kushner’s Bid for Electronic Arts: Soft Power, FIFA Politics, and the Israel Question
  • U.S. Preparations to Overthrow the Maduro Regime
  • Qatar Buys Influence Through AI Infrastructure: QIA–Blue Owl $3B Data Center Deal
  • Israel’s Strategic Position Beyond Public Opinion
  • Poland’s Calculated Bet: Bolstering Ukraine’s Long-Range Strike Capabilities
  • Is the U.S. Actually Planning an Invasion or Coup in Venezuela?
  • Tadaweb Secures $20M to Expand Human-Centric OSINT Platform

Media Partners

  • Analysis.org
  • Opinion.org
AMD’s Pullback Looks More Like a Pause — And Nvidia’s Beat May Be the Turning Point
PayPal Pay in 4 Arrives in Canada for the Holiday Rush
NuScale Power: The SMR Bet Moves From Concept to Commercial Deployment
The Waiting Game at the Bank of England
Maersk Q3 2025: The Quiet Rebuild of a Global Trade Powerhouse
Tempus AI: Scaling Into an Inflection Point
Palantir’s Explosive Q3: When “AI Leverage” Becomes a Revenue Machine
Nexperia, China, Netherlands: A Semiconductor Flashpoint in Europe’s Geopolitical Balancing Act
Jensen Huang and the AI Virtuous Cycle: The Economics of Infinite Acceleration
Cloudflare’s Q3 Beat, Reacceleration, and the Quiet Cash Engine Powering the “Connectivity Cloud”
Europe’s Telecom Awakening — The Huawei Breakup Feels a Lot Like the Russian Gas Divorce
Woke Journalism as a Camouflaged Form of Anarchism
Israel Surrounded by Failed States
It Was Qatar All Along: Qatar’s Network of Influence and the Long Campaign Against Israel and the West
Photo of the Day: Pro-Palestinian Mobs Harassing European Cities
Hamas’s “Yes” That Really Means “No”
Spain’s Boom Is a Corruption-Fueled Illusion
Europe to Erdogan: Don’t Teach Us How to Eat
Europe’s Imported Illusion: He must be an engineer
Erdogan’s Possible Collapse

Media Partners

  • Market Analysis
  • Market Research Media
U.S. Housing Market Turns Sharply in Favor of Buyers, But Affordability Remains a Wall
Europe’s Turning Point: Why Cutting Out Chinese Tech Isn’t Just Necessary — It’s Long Overdue
Nvidia Q3 FY2026 Earnings: Still the Center of Gravity in the AI Super-Cycle
Ghost Kitchens as Infrastructure: The Shift from Restaurants to Intelligent Food Networks
Why are AI stocks falling if Anthropic is buying $30B of Azure capacity?
Sony’s Spark, and the Strange Quiet That Followed
Celero Communications Secures $140M to Push the Optical Frontier of AI Infrastructure
NTT R&D Forum 2025, Tokyo — When Quantum Stops Being Theory
IIFES 2025, November 19–21, 2025, Tokyo Big Sight
China Played Trump, Again: Soybeans, Strategy, and Leverage
AppCoding.com — A Clear, Flexible Identity at the Center of the Software-Everywhere Economy
APIcoding.com — A Digital Asset Aligned With the Infrastructure of the Modern Software Economy
NewsInstances.com — A Digital Identity Built for Event-Driven Media and AI-Generated Reporting
Marketing Content Creation Services in 2025
Visual Storytelling and the Rise of Gamma in the AI Productivity Stack
The Trade Desk: Durable Growth, Wider Moats, and a Faster Flywheel on the Open Internet
Expedia Group: Reacceleration in Core Travel Demand and Strong B2B Tailwinds Push Results Above Expectations
BuzzFeed, Inc. – Q3 2025 Analytical Report
The Rise of the Micro-Series Phenomenon
Canva’s Creative Operating System: A Strategic Shockwave for the Design Industry

Copyright © 2022 OSINT.org

Technologies, Market Analysis & Market Research and Exclusive Domains