• Skip to main content
  • Skip to secondary menu
  • Skip to footer

OSINT.org

Intelligence Matters

  • Sponsored Post
  • About
    • GDPR
  • Contact

DHS Funding Transitioning into Real World Collaboration through SARIF

March 9, 2020 By admin Leave a Comment

With funding from the Department of Homeland Security (DHS), GrammaTech has worked to enable open source static analysis tools to generate and consume results in the open SARIF format. Building on this work, GrammaTech has now released a tool to support SARIF-based integration of static analysis results with GitHub.

Currently, open source and commercial static analysis tools use proprietary formats to display and store their results. This makes it hard to integrate results from a static analysis tool into an Integrated Development Environment (IDE), code review tool, or a source code management and version control platform such as GitHub.

SARIF (pronounced SA-rif), which stands for Static Analysis Results Interchange Format, is a standard developed and managed by the OASIS group. SARIF makes it easier for tools to collaborate in a unified software development environment around the topic of static analysis. For more information on SARIF, you can visit the OASIS website and view the SARIF specification.

GrammaTech, with funding provided by the DHS Science & Technology Directorate Static Analysis Tools Modernization Project (STAMP) program, has previously implemented SARIF support for open-source static analyzers such as Clang Static Analyzer, Pylint, and several others. Broad SARIF support allows software development teams to pick and choose the tools that they want and integrate them into a best-of-breed DevOps environment.

In order to further support the SARIF ecosystem, GrammaTech has now released a tool that allows developers to view static analysis results as part of their code review workflow, within GitHub pull requests. Evidence from real-world industry practice indicates that such an integration significantly increases the adoption of static analysis, contributing to improved code quality and safety. The tool is available as open-source software, and was featured in a publication at the TechDebt ’19 conference.

“GrammaTech strongly believes in collaboration using open standards,” says Vince Arneja, Chief Product Officer at GrammaTech. “GrammaTech CodeSonar imports and exports SARIF, and through that, can collaborate with Microsoft’s IDEs, GitHub, Clang Static Analyzer, Pylint, ESlint and other tools that support SARIF.”

This work is based on research sponsored by the Department of Homeland Security (DHS) Science and Technology Directorate (contract numbers HHSP233201600062C 70RSAT19C00000056). The views and conclusions contained herein are those of the authors and should not be interpreted as necessarily representing the official policies or endorsements, either expressed or implied, of the Department of Homeland Security.

SOURCE GrammaTech
http://www.grammatech.com

Filed Under: Workflow Tagged With: open source, static analysis tools

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • Georgia, Sanctions Backdoor, and the Machinery of Russia’s Shadow Fleet
  • Markets Close, Missiles Open? Why the Iran War Rumor Keeps Returning
  • The Tanker Surge That Signals U.S. Military Readiness in the Iran Theater
  • Trump’s Greenland Distraction: A Kremlin-Style Wedge That Pays in Ukraine
  • Why I Think a U.S. Attack on Iran Is Imminent
  • Why Authoritarian Regimes Hate Starlink: China, Iran, and the Fear of Uncontrolled Connectivity
  • Signals, Noise, and Late-Night Pizza: OSINT Readings on a Possible U.S. Strike on Iran
  • Switzerland Freezes Maduro-Linked Assets After Arrest
  • CentralSquare Technologies Acquires FirstTwo to Advance Real-Time Intelligence for First Responders
  • IMINT Brief: Virgin Galactic–LLNL High-Altitude Sensor Collaboration

Media Partners

  • Analysis.org
  • Opinion.org
Cloudflare’s 13% Jump Was About Virality, Timing, and a Perfect AI Fit
When AI Growth Starts Eating the Margins: Why Broadcom’s Warning Matters More Than the Stock Drop
Intel Q4 2025: Stabilization Without Momentum, AI Narrative Doing the Heavy Lifting
PR Bubbles and Forgotten Deals: Why Greenland Will Join Trump’s Archive of Vanishing Announcements
Nvidia’s $150 Million Bet on Baseten Is About Control, Not Just Compute
Maersk Downgraded, Shares Slide — and the Market’s Discomfort With Normality
Why Beam Therapeutics Inc. Jumped 27%: A Market Reading Beyond the Headline
Tempus AI Signals Platform Leverage as Diagnostics and Data Scale in Tandem
Why AMD, Nvidia, and Broadcom Are Pulling Back Today
Why Broadcom, AMD, and Nvidia Are Rising Again in 2026
OFAC Tightens the Net: Inside the U.S. Sanctions on Iran’s Shadow Fleet
Stop Treating the Kurds as a Temporary Tool: The West’s Strategic Blind Spot in Syria
Stale Democracies and the Rise of the Grotesque
The Next Bubble: Trump’s “Alternative UN” and the Politics of Imaginary Institutions
Treasury Exposes Hamas’s Charity Fronts, and the Mask Finally Slips
Why Saudi Arabia Turned Against Israel: The Specific Reasons Behind the Shift
Trump’s Greenland Bluff
Europe’s Moral Collapse on Iran
Why a 2026 Impeachment of Trump Is Unlikely, but Not Impossible
Iran’s $8 Billion Crypto Economy, Stress Signal or System Adaptation?

Media Partners

  • Market Analysis
  • Market Research Media
Baseten Raises $300M to Dominate the Inference Layer of AI, Valued at $5B
Nvidia’s China Problem Is Self-Inflicted, and Washington Should Stop Pretending Otherwise
USPS and the Theater of Control: How Government Freezes Failure in Place
Skild AI Funding Round Signals a Shift Toward Platform Economics in Robotics
Saks Sucks: Luxury Retail’s Debt-Fueled Mirage Collapses
Alpaca’s $1.15B Valuation Signals a Maturity Moment for Global Brokerage Infrastructure
The Immersive Experience in the Museum World
The Great Patent Pause: 2025, the Year U.S. Innovation Took a Breath
OpenAI Acquires Torch, A $100M Bet on AI-Powered Health Records Analytics
Iran’s Unreversible Revolt: When Internal Rupture Meets External Signals
BBC and the Gaza War: How Disproportionate Attention Reshapes Reality
Parallel Museums: Why the Future of Art Might Be Copies, Not Originals
ClickHouse Series D, The $400M Bet That Data Infrastructure, Not Models, Will Decide the AI Era
AI Productivity Paradox: When Speed Eats Its Own Gain
Voice AI as Infrastructure: How Deepgram Signals a New Media Market Segment
Spangle AI and the Agentic Commerce Stack: When Discovery and Conversion Converge Into One Layer
PlayStation and the Quiet Power Center of a $200 Billion Gaming Industry
Adobe FY2025: AI Pulls the Levers, Cash Flow Leads the Story
Canva’s 2026 Creative Shift and the Rise of Imperfect-by-Design
fal Raises $140M Series D: Scaling the Core Infrastructure for Real-Time Generative Media

Copyright © 2022 OSINT.org

Technologies, Market Analysis & Market Research and Exclusive Domains