• Skip to main content
  • Skip to secondary menu
  • Skip to footer

OSINT.org

Intelligence Matters

  • Sponsored Post
  • About
    • GDPR
  • Contact

DHS Funding Transitioning into Real World Collaboration through SARIF

March 9, 2020 By admin Leave a Comment

With funding from the Department of Homeland Security (DHS), GrammaTech has worked to enable open source static analysis tools to generate and consume results in the open SARIF format. Building on this work, GrammaTech has now released a tool to support SARIF-based integration of static analysis results with GitHub.

Currently, open source and commercial static analysis tools use proprietary formats to display and store their results. This makes it hard to integrate results from a static analysis tool into an Integrated Development Environment (IDE), code review tool, or a source code management and version control platform such as GitHub.

SARIF (pronounced SA-rif), which stands for Static Analysis Results Interchange Format, is a standard developed and managed by the OASIS group. SARIF makes it easier for tools to collaborate in a unified software development environment around the topic of static analysis. For more information on SARIF, you can visit the OASIS website and view the SARIF specification.

GrammaTech, with funding provided by the DHS Science & Technology Directorate Static Analysis Tools Modernization Project (STAMP) program, has previously implemented SARIF support for open-source static analyzers such as Clang Static Analyzer, Pylint, and several others. Broad SARIF support allows software development teams to pick and choose the tools that they want and integrate them into a best-of-breed DevOps environment.

In order to further support the SARIF ecosystem, GrammaTech has now released a tool that allows developers to view static analysis results as part of their code review workflow, within GitHub pull requests. Evidence from real-world industry practice indicates that such an integration significantly increases the adoption of static analysis, contributing to improved code quality and safety. The tool is available as open-source software, and was featured in a publication at the TechDebt ’19 conference.

“GrammaTech strongly believes in collaboration using open standards,” says Vince Arneja, Chief Product Officer at GrammaTech. “GrammaTech CodeSonar imports and exports SARIF, and through that, can collaborate with Microsoft’s IDEs, GitHub, Clang Static Analyzer, Pylint, ESlint and other tools that support SARIF.”

This work is based on research sponsored by the Department of Homeland Security (DHS) Science and Technology Directorate (contract numbers HHSP233201600062C 70RSAT19C00000056). The views and conclusions contained herein are those of the authors and should not be interpreted as necessarily representing the official policies or endorsements, either expressed or implied, of the Department of Homeland Security.

SOURCE GrammaTech

Securing the Software that Secures the World

Filed Under: Workflow Tagged With: open source, static analysis tools

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • ICC War Crimes Complaint Against Spanish PM Sánchez
  • Textron Aviation Defense Wins $150M Follow-On Contract to Sustain T-6 Texan II Fleet
  • Beijing Stages a Reunion, on Its Own Terms
  • Russia’s Security Operations in Africa — Brief Overview
  • Rubio Criticizes Saudi Crown Prince Over Ukraine Defense Deal Without U.S. Approval
  • Five Eyes, Fractured: When Allies Start Acting Like Strangers
  • Chinese Firms Are Selling U.S. Military Positions in the Middle East — Washington Needs to Treat It as Hostile Support
  • The Weapon Gap: Why North Korea May Not Have What It Claims
  • NORTH KOREA NUCLEAR PROGRAM — MILITARY ASSESSMENT
  • Minu Island and the Hidden Geometry of Targets in Southwest Iran

Media Partners

  • Analysis.org
  • Opinion.org
Cloudflare Shares Are Poised for a Jump — Here Is Why the Setup Is Compelling
Nvidia, AMD, and Broadcom Are Rising Again — and the Market Is Telling You Something
OPEC+ in a Blocked Market: Why 200,000 Barrels Don’t Matter
Oil Shock 2026: Hormuz Risk Premium Rewrites the Curve
Why ServiceNow, Salesforce, and Atlassian Fell on the Anthropic Mythos Announcement
Broadcom’s Quiet Power Play: Strong AI Tailwinds, Yet a Stock Caught Between Cycles
Nvidia’s AI Dominance Is Real—So Why Doesn’t the Stock Feel Untouchable?
The Cost of Winning AI: Why Microsoft’s Stock Is Stuck Between Growth and Doubt
Memory Market Reality Check: Micron’s Drop Ripples Across the Sector
The Rise of China’s Hottest New Commodity: AI Tokens
Rama Dawaji: A Late Apology and the Question of Timing
Ada Shelby on Zohran Mamdani’s Grocery Stores
Hochul’s Second Home Tax Is a Press Release, Not a Policy
JD Vance’s Pride in Abandoning Ukraine Is a Confession, Not a Boast
France’s Irrelevance in Lebanon Diplomacy
Why Islamabad
A Ceasefire Is Not a Deal
Why Europe Is Dangerously Shortsighted About Gaza, Iran, and Hezbollah
Hungary Under Magyar: A Policy Forecast Across Seven Dimensions
No Ceasefire for Iran’s Repression

Media Partners

  • Market Analysis
  • Market Research Media
Synera’s $40M Series B: What the Press Release Isn’t Saying
Amazon’s Globalstar Acquisition Is a Spectrum War Dressed as a Satellite Deal
The End of Manual Audits: Why AI-Native Accounting Is Not Optional Anymore
Raspberry Pi’s Earnings Beat Signals a Shift From Hobbyist Hardware to Embedded Infrastructure
Betting the Backbone: A Multi-Year Positioning on AMD, Broadcom, and Nvidia
Nvidia’s Groq 3 LPX: The $20B Bet That Could Define the Inference Era
Why Arm’s New AI Chip Changes the Rules of the Game
A Map Without Hormuz: Rewiring Global Oil Flows Through Fragmented Corridors
RoboForce’s $52 Million Raise Signals That Physical AI Is Moving From Demo Stage to Industrial Scale
The Hormuz Crisis: Winners and Losers in the Global Energy Shock
Canva Acquires Simtheory and Ortto to Build End-to-End Work Platform
Netflix Price Hikes, The Economics of Dominance in a Saturated Streaming Market
America’s Brands Keep Winning Even as America Itself Slips
Kioxia’s Storage Gambit: Flash Steps Into the AI Memory Hierarchy
Mamdani Strangling New York
The Rise of Faceless Creators: Picsart Launches Persona and Storyline for AI Character-Driven Content
Apple TV Arrives on The Roku Channel, Expanding the Streaming Platform Wars
Why Attraction-Grabbing Stations Win at Tech Events
Why Nvidia Let Go of Arm, and Why It Matters Now
When the Market Wants a Story, Not Numbers: Rethinking AMD’s Q4 Selloff

Copyright © 2022 OSINT.org

Technologies, Market Analysis & Market Research and Exclusive Domains