{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,6]],"date-time":"2026-07-06T00:14:19Z","timestamp":1783296859618,"version":"3.54.6"},"reference-count":75,"publisher":"Walter de Gruyter GmbH","issue":"1","license":[{"start":{"date-parts":[[2024,6,1]],"date-time":"2024-06-01T00:00:00Z","timestamp":1717200000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,6,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:sec>\n                    <jats:title>Context<\/jats:title>\n                    <jats:p>The primary expectation from a software system revolves around its functionality. However, as the software development process advances, equal emphasis is placed on the quality of the software system for non-functional attributes like maintainability and performance. Tools are available to aid in this endeavour, assessing the quality of a software system from multiple perspectives.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Objective<\/jats:title>\n                    <jats:p>This study aims to perform a comprehensive analysis of a particular set of source code analytical tools by examining diverse perspectives found in the literature and documentations. Given the vast array of programming languages available today, selecting appropriate source-code analytical tools presents a significant challenge. Therefore, this analysis aims to provide general insights to aid in selecting a more suitable analytical tool tailored to specific requirements.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Method<\/jats:title>\n                    <jats:p>Seven prominent static analysis tools, namely SonarQube, Coverty, CodeSonar, Snyk Code, ESLint, Klocwork, and PMD, were chosen based on their prevalence in the literature and recognition in the software development community. To systematically categorise and organise their distinctive features and capabilities, a taxonomy was developed. This taxonomy covers crucial dimensions, including input support, technology employed, extensibility, user experience, rules, configurability, and supported languages.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Results<\/jats:title>\n                    <jats:p>The comparative analysis highlights the distinctive strengths of each tool. SonarQube stands out as a comprehensive solution with a hybrid approach supporting static and dynamic code evaluations, accommodating multiple languages and integrating with popular Integrated Development Environments (IDEs). Coverity excels in identifying security vulnerabilities and defects, making it an excellent choice for security -focused development. CodeSonar prioritises code security and safety, offering a robust analysis. Snyk Code and ESLint, focusing on JavaScript, emphasise code quality and standards adherence. Klocwork is exceptional in defect detection and security analysis for C, C++, and Java. Lastly, PMD specialises in Java, emphasising code style and best practices.<\/jats:p>\n                  <\/jats:sec>","DOI":"10.2478\/acss-2024-0013","type":"journal-article","created":{"date-parts":[[2024,8,15]],"date-time":"2024-08-15T03:25:52Z","timestamp":1723692352000},"page":"98-111","source":"Crossref","is-referenced-by-count":10,"title":["Analysing the Analysers: An Investigation of Source Code Analysis Tools"],"prefix":"10.2478","volume":"29","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3565-2581","authenticated-orcid":false,"given":"Vikram","family":"Bhutani","sequence":"first","affiliation":[{"name":"Department of Computer Science , Munster Technological University , Cork , Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1105-4819","authenticated-orcid":false,"given":"Farshad Ghassemi","family":"Toosi","sequence":"additional","affiliation":[{"name":"Department of Computer Science , Munster Technological University , Cork , Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6928-6746","authenticated-orcid":false,"given":"Jim","family":"Buckley","sequence":"additional","affiliation":[{"name":"Lero and CSIS, University of Limerick , Limerick , Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"374","published-online":{"date-parts":[[2024,8,15]]},"reference":[{"key":"2026070522564081544_j_acss-2024-0013_ref_001","doi-asserted-by":"crossref","unstructured":"D. Baca, K. Petersen, B. Carlsson, and L. Lundberg, \u201cStatic code analysis to detect software security vulnerabilities \u2013 does experience matter?\u201d in 2009 International Conference on Availability, Reliability and Security, Fukuoka, Japan, Mar. 2009, pp. 804\u2013810. https:\/\/doi.org\/10.1109\/ARES.2009.163","DOI":"10.1109\/ARES.2009.163"},{"key":"2026070522564081544_j_acss-2024-0013_ref_002","unstructured":"A. G. Bardas et al., \u201cStatic code analysis,\u201d Journal of Information Systems & Operations Management, vol. 4, no. 2, pp. 99\u2013107, 2010."},{"key":"2026070522564081544_j_acss-2024-0013_ref_003","doi-asserted-by":"crossref","unstructured":"B. A. Kitchenham, T. Dyba, and M. Jorgensen, \u201cEvidence-based software engineering,\u201d in Proceedings. 26th International Conference on Software Engineering, Edinburgh, UK, Jun. 2004, pp. 273\u2013281. https:\/\/doi.org\/10.1109\/ICSE.2004.1317449","DOI":"10.1109\/ICSE.2004.1317449"},{"key":"2026070522564081544_j_acss-2024-0013_ref_004","doi-asserted-by":"crossref","unstructured":"T. B. C. Arias, P. Avgeriou, and P. America, \u201cAnalyzing the actual execution of a large software-intensive system for determining dependencies,\u201d in 2008 15th Working Conference on Reverse Engineering, Antwerp, Belgium, Oct. 2008, pp. 49\u201358. https:\/\/doi.org\/10.1109\/WCRE.2008.11","DOI":"10.1109\/WCRE.2008.11"},{"key":"2026070522564081544_j_acss-2024-0013_ref_005","doi-asserted-by":"crossref","unstructured":"F. Angerer, \u201cVariability-aware change impact analysis of multi-language product lines,\u201d in Proceedings of the 29th ACM\/IEEE International Conference on Automated Software Engineering, Sep. 2014, pp. 903\u2013906. https:\/\/doi.org\/10.1145\/2642937.2653472","DOI":"10.1145\/2642937.2653472"},{"key":"2026070522564081544_j_acss-2024-0013_ref_006","doi-asserted-by":"crossref","unstructured":"G. Booch, \u201cObject-oriented development,\u201d IEEE Transactions on Software Engineering, vol. SE-12, no. 2, pp. 211\u2013221, Feb. 1986. https:\/\/doi.org\/10.1109\/TSE.1986.6312937","DOI":"10.1109\/TSE.1986.6312937"},{"key":"2026070522564081544_j_acss-2024-0013_ref_007","doi-asserted-by":"crossref","unstructured":"D. De Champeaux, A. Anderson, and E. Feldhousen, \u201cCase study of object-oriented software development,\u201d ACM SIGPLAN Notices, vol. 27, no. 10, pp. 377\u2013391, Oct. 1992. https:\/\/doi.org\/10.1145\/141937.141967","DOI":"10.1145\/141937.141967"},{"key":"2026070522564081544_j_acss-2024-0013_ref_008","doi-asserted-by":"crossref","unstructured":"K. Lieberherr and C. Xiao, \u201cObject-oriented software evolution,\u201d IEEE Transactions on Software Engineering, vol. 19, no. 4, pp. 313\u2013343, Apr. 1993. https:\/\/doi.org\/10.1109\/32.223802","DOI":"10.1109\/32.223802"},{"key":"2026070522564081544_j_acss-2024-0013_ref_009","doi-asserted-by":"crossref","unstructured":"M. Gabbrielli and S. Martini, Programming Languages: Principles and Paradigms. Springer Nature, 2023.","DOI":"10.1007\/978-3-031-34144-1"},{"key":"2026070522564081544_j_acss-2024-0013_ref_010","doi-asserted-by":"crossref","unstructured":"M. Mantere, I. Uusitalo, and J. Roning, \u201cComparison of static code analysis tools,\u201d in 2009 Third International Conference on Emerging Security Information, Systems and Technologies, Athens, Greece, Jun. 2009, pp. 15\u201322. https:\/\/doi.org\/10.1109\/SECURWARE.2009.10","DOI":"10.1109\/SECURWARE.2009.10"},{"key":"2026070522564081544_j_acss-2024-0013_ref_011","doi-asserted-by":"crossref","unstructured":"R. Lammel, M. Leinberger, T. Schmorleiz, and A. Varanovich, \u201cComparison of feature implementations across languages, technologies, and styles,\u201d in 2014 Software Evolution Week-IEEE Conference on Software Maintenance, Reengineering, and Reverse Engineering (CSMRWCRE), Antwerp, Belgium, Feb. 2014, pp. 333\u2013337. https:\/\/doi.org\/10.1109\/CSMR-WCRE.2014.6747188","DOI":"10.1109\/CSMR-WCRE.2014.6747188"},{"key":"2026070522564081544_j_acss-2024-0013_ref_012","doi-asserted-by":"crossref","unstructured":"N. F. Schneidewind, \u201cThe state of software maintenance,\u201d IEEE Transactions on Software Engineering, vol. SE-13, no. 3, pp. 303\u2013310, Mar. 1987. https:\/\/doi.org\/10.1109\/TSE.1987.233161","DOI":"10.1109\/TSE.1987.233161"},{"key":"2026070522564081544_j_acss-2024-0013_ref_013","doi-asserted-by":"crossref","unstructured":"G. A. Di Lucca, A. R. Fasolino, F. Pace, P. Tramontana, and U. De Carlini, \u201cWare: A tool for the reverse engineering of web applications,\u201d in Proceedings of the Sixth European Conference on Software Maintenance and Reengineering, 2002, pp. 241\u2013250.","DOI":"10.1109\/CSMR.2002.995811"},{"key":"2026070522564081544_j_acss-2024-0013_ref_014","doi-asserted-by":"crossref","unstructured":"L. Coyle, M. Hinchey, B. Nuseibeh, and J. L. Fiadeiro, \u201cGuest editors\u2019 introduction: Evolving critical systems,\u201d Computer, vol. 43, no. 05, pp. 28\u201333, May 2010. https:\/\/doi.org\/10.1109\/MC.2010.139","DOI":"10.1109\/MC.2010.139"},{"key":"2026070522564081544_j_acss-2024-0013_ref_015","doi-asserted-by":"crossref","unstructured":"S. Olbrich, D. S. Cruzes, V. Basili, and N. Zazworka, \u201cThe evolution and impact of code smells: A case study of two open source systems,\u201d in 2009 3rd international symposium on empirical software engineering and measurement, Lake Buena Vista, FL, USA, Oct. 2009, pp. 390\u2013400. https:\/\/doi.org\/10.1109\/ESEM.2009.5314231","DOI":"10.1109\/ESEM.2009.5314231"},{"key":"2026070522564081544_j_acss-2024-0013_ref_016","doi-asserted-by":"crossref","unstructured":"A. S. Cairo, G. d. F. Carneiro, and M. P. Monteiro, \u201cThe impact of code smells on software bugs: A systematic literature review,\u201d Information, vol. 9, no. 11, Nov. 2018, Art. no. 273. https:\/\/doi.org\/10.3390\/info9110273","DOI":"10.3390\/info9110273"},{"key":"2026070522564081544_j_acss-2024-0013_ref_017","doi-asserted-by":"crossref","unstructured":"D. Binkley, \u201cSource code analysis: A road map,\u201d in Future of Software Engineering (FOSE\u201907), Minneapolis, MN, USA, May 2007, pp. 104\u2013 119. https:\/\/doi.org\/10.1109\/FOSE.2007.27","DOI":"10.1109\/FOSE.2007.27"},{"key":"2026070522564081544_j_acss-2024-0013_ref_018","doi-asserted-by":"crossref","unstructured":"J. Cruz-Benito, S. Vishwakarma, F. Martin-Fernandez, and I. Faro, \u201cAutomated source code generation and auto-completion using deep learning: Comparing and discussing current language model-related approaches,\u201d AI, vol. 2, no. 1, pp. 1\u201316, Jan. 2021. https:\/\/doi.org\/10.3390\/ai2010001","DOI":"10.3390\/ai2010001"},{"key":"2026070522564081544_j_acss-2024-0013_ref_019","doi-asserted-by":"crossref","unstructured":"N. Harrison, Code Generation with Roslyn. Springer, 2017.","DOI":"10.1007\/978-1-4842-2211-9"},{"key":"2026070522564081544_j_acss-2024-0013_ref_020","doi-asserted-by":"crossref","unstructured":"F. Nagel, G. M. Bierman, and S. D. Viglas, \u201cCode generation for efficient query processing in managed runtimes,\u201d Proceedings of the VLDB Endowment (PVLDB), vol. 7, no. 12, pp. 1095\u20131106, Aug. 2014. https:\/\/doi.org\/10.14778\/2732977.2732984","DOI":"10.14778\/2732977.2732984"},{"key":"2026070522564081544_j_acss-2024-0013_ref_021","doi-asserted-by":"crossref","unstructured":"D. Steidl, B. Hummel, and E. Juergens, \u201cQuality analysis of source code comments,\u201d in 2013 21st International Conference on Program Comprehension (ICPC), San Francisco, CA, USA, May 2013, pp. 83\u201392. https:\/\/doi.org\/10.1109\/ICPC.2013.6613836","DOI":"10.1109\/ICPC.2013.6613836"},{"key":"2026070522564081544_j_acss-2024-0013_ref_022","doi-asserted-by":"crossref","unstructured":"R. Plosch, H. Gruber, A. Hentschel, G. Pomberger, and S. Schiffer, \u201cOn the relation between external software quality and static code analysis,\u201d in 2008 32nd annual IEEE software engineering workshop, Kassandra, Greece, Oct. 2008, pp. 169\u2013174. https:\/\/doi.org\/10.1109\/SEW.2008.17","DOI":"10.1109\/SEW.2008.17"},{"key":"2026070522564081544_j_acss-2024-0013_ref_023","doi-asserted-by":"crossref","unstructured":"D. Singh, V. R. Sekar, K. T. Stolee, and B. Johnson, \u201cEvaluating how static analysis tools can reduce code review effort,\u201d in 2017 IEEE symposium on visual languages and human-centric computing (VL\/HCC), Raleigh, NC, USA, Oct. 2017, pp. 101\u2013105. https:\/\/doi.org\/10.1109\/VLHCC.2017.8103456","DOI":"10.1109\/VLHCC.2017.8103456"},{"key":"2026070522564081544_j_acss-2024-0013_ref_024","doi-asserted-by":"crossref","unstructured":"I. Stamelos, L. Angelis, A. Oikonomou, and G. L. Bleris, \u201cCode quality analysis in open source software development,\u201d Information Systems Journal, vol. 12, no. 1, pp. 43\u201360, Jan. 2002. https:\/\/doi.org\/10.1046\/j.1365-2575.2002.00117.x","DOI":"10.1046\/j.1365-2575.2002.00117.x"},{"key":"2026070522564081544_j_acss-2024-0013_ref_025","doi-asserted-by":"crossref","unstructured":"M. Harman, \u201cWhy source code analysis and manipulation will always be important,\u201d in 2010 10Th IEEE working conference on source code analysis and manipulation, Timisoara, Romania, Sep. 2010, pp. 7\u201319. https:\/\/doi.org\/10.1109\/SCAM.2010.28","DOI":"10.1109\/SCAM.2010.28"},{"key":"2026070522564081544_j_acss-2024-0013_ref_026","doi-asserted-by":"crossref","unstructured":"S. Mukherjee, Source Code Analytics with Roslyn and JavaScript Data Visualization. Springer, 2016.","DOI":"10.1007\/978-1-4842-1925-6"},{"key":"2026070522564081544_j_acss-2024-0013_ref_027","unstructured":"T. W. Thomas, H. Lipford, B. Chu, J. Smith, and E. Murphy-Hill, \u201cWhat questions remain? An examination of how developers understand an interactive static analysis tool,\u201d in Twelfth Symposium on Usable Privacy and Security (SOUPS 2016), Jun. 2016."},{"key":"2026070522564081544_j_acss-2024-0013_ref_028","doi-asserted-by":"crossref","unstructured":"A. R. Yazdanshenas and L. Moonen, \u201cCrossing the boundaries while analyzing heterogeneous component-based software systems,\u201d in 2011 27th IEEE International Conference on Software Maintenance (ICSM), Williamsburg, VA, USA, Sep. 2011, pp. 193\u2013202. https:\/\/doi.org\/10.1109\/ICSM.2011.6080786","DOI":"10.1109\/ICSM.2011.6080786"},{"key":"2026070522564081544_j_acss-2024-0013_ref_029","doi-asserted-by":"crossref","unstructured":"P. Emanuelsson and U. Nilsson, \u201cA comparative study of industrial static analysis tools,\u201d Electronic Notes in Theoretical Computer Science, vol. 217, pp. 5\u201321, Jul. 2008. https:\/\/doi.org\/10.1016\/j.entcs.2008.06.039","DOI":"10.1016\/j.entcs.2008.06.039"},{"key":"2026070522564081544_j_acss-2024-0013_ref_030","doi-asserted-by":"crossref","unstructured":"P. Louridas, \u201cStatic code analysis,\u201d IEEE Software, vol. 23, no. 4, pp. 58\u2013 61, Jul.\u2013Aug.2006. https:\/\/doi.org\/10.1109\/MS.2006.114","DOI":"10.1109\/MS.2006.114"},{"key":"2026070522564081544_j_acss-2024-0013_ref_031","doi-asserted-by":"crossref","unstructured":"N. E. Fenton and M. Neil, \u201cSoftware metrics: roadmap,\u201d in Proceedings of the Conference on the Future of Software Engineering, May 2000, pp. 357\u2013370. https:\/\/doi.org\/10.1145\/336512.336588","DOI":"10.1145\/336512.336588"},{"key":"2026070522564081544_j_acss-2024-0013_ref_032","doi-asserted-by":"crossref","unstructured":"F. G. Toosi, J. Buckley, and A. R. Sai, \u201cSource-code divergence diagnosis using constraints and cryptography,\u201d in Proceedings of the 13th European Conference on Software Architecture, ECSA \u201919, vol. 2, New York, NY, USA, Sep. 2019, pp. 205\u2013208. https:\/\/doi.org\/10.1145\/3344948.3344983","DOI":"10.1145\/3344948.3344983"},{"key":"2026070522564081544_j_acss-2024-0013_ref_033","doi-asserted-by":"crossref","unstructured":"Z. Zhioua, S. Short, and Y. Roudier, \u201cStatic code analysis for software security verification: Problems and approaches,\u201d in 2014 IEEE 38th International Computer Software and Applications Conference Workshops, Vasteras, Sweden, Jul. 2014, pp. 102\u2013109. https:\/\/doi.org\/10.1109\/COMPSACW.2014.22","DOI":"10.1109\/COMPSACW.2014.22"},{"key":"2026070522564081544_j_acss-2024-0013_ref_034","doi-asserted-by":"crossref","unstructured":"A. Hovsepyan, R. Scandariato, W. Joosen, and J. Walden, \u201cSoftware vulnerability prediction using text analysis techniques,\u201d in Proceedings of the 4th international workshop on Security measurements and metrics, Sep. 2012, pp. 7\u201310. https:\/\/doi.org\/10.1145\/2372225.2372230","DOI":"10.1145\/2372225.2372230"},{"key":"2026070522564081544_j_acss-2024-0013_ref_035","doi-asserted-by":"crossref","unstructured":"M. Gegick, L. Williams, J. Osborne, and M. Vouk, \u201cPrioritizing software security fortification throughcode-level metrics,\u201d in Proceedings of the 4th ACM workshop on Quality of protection, Oct. 2008, pp. 31\u201338. https:\/\/doi.org\/10.1145\/1456362.1456370","DOI":"10.1145\/1456362.1456370"},{"key":"2026070522564081544_j_acss-2024-0013_ref_036","doi-asserted-by":"crossref","unstructured":"I. Stamelos, L. Angelis, A. Oikonomou, and G. L. Bleris, \u201cCode quality analysis in open source software development,\u201d Information systems journal, vol. 12, no. 1, pp. 43\u201360, 2002.","DOI":"10.1046\/j.1365-2575.2002.00117.x"},{"key":"2026070522564081544_j_acss-2024-0013_ref_037","doi-asserted-by":"crossref","unstructured":"E. L. Vargas, J. Hejderup, M. Kechagia, M. Bruntink, and G. Gousios, \u201cEnabling real-time feedback in software engineering,\u201d in Proceedings of the 40th International Conference on Software Engineering: New Ideas and Emerging Results, Sydney, NSW, Australia, May 2018, pp. 21\u201324. https:\/\/doi.org\/10.1145\/3183399.3183416","DOI":"10.1145\/3183399.3183416"},{"key":"2026070522564081544_j_acss-2024-0013_ref_038","doi-asserted-by":"crossref","unstructured":"W. Maalej and D. Pagano, \u201cOn the socialness of software,\u201d in 2011 IEEE Ninth International Conference on Dependable, Autonomic and Secure Computing, Dec. 2011, pp. 864\u2013871. https:\/\/doi.org\/10.1109\/DASC.2011.146","DOI":"10.1109\/DASC.2011.146"},{"key":"2026070522564081544_j_acss-2024-0013_ref_039","doi-asserted-by":"crossref","unstructured":"E. Soares, G. Sizilio, J. Santos, D. A. da Costa, and U. Kulesza, \u201cThe effects of continuous integration on software development: a systematic literature review,\u201d Empirical Software Engineering, vol. 27, no. 3, Mar. 2022, Art. no. 78. https:\/\/doi.org\/10.1007\/s10664-021-10114-1","DOI":"10.1007\/s10664-021-10114-1"},{"key":"2026070522564081544_j_acss-2024-0013_ref_040","doi-asserted-by":"crossref","unstructured":"M. Shahin, M. A. Babar, and L. Zhu, \u201cContinuous integration, delivery and deployment: a systematic review on approaches, tools, challenges and practices,\u201d IEEE Access, vol. 5, pp. 3909\u20133943, Mar. 2017. https:\/\/doi.org\/10.1109\/ACCESS.2017.2685629","DOI":"10.1109\/ACCESS.2017.2685629"},{"key":"2026070522564081544_j_acss-2024-0013_ref_041","doi-asserted-by":"crossref","unstructured":"S. Arachchi and I. Perera, \u201cContinuous integration and continuous delivery pipeline automation for agile software project management,\u201d in 2018 Moratuwa Engineering Research Conference (MERCon), Moratuwa, Sri Lanka, May\u2013Jun. 2018, pp. 156\u2013161. https:\/\/doi.org\/10.1109\/MERCon.2018.8421965","DOI":"10.1109\/MERCon.2018.8421965"},{"key":"2026070522564081544_j_acss-2024-0013_ref_042","doi-asserted-by":"crossref","unstructured":"Y. Oda, H. Fudaba, G. Neubig, H. Hata, S. Sakti, T. Toda, and S. Nakamura, \u201cLearning to generate pseudo-code from source code using statistical machine translation,\u201d in 2015 30th IEEE\/ACM International Conference on Automated Software Engineering (ASE), Lincoln, NE, USA, Nov. 2015, pp. 574\u2013584. https:\/\/doi.org\/10.1109\/ASE.2015.36","DOI":"10.1109\/ASE.2015.36"},{"key":"2026070522564081544_j_acss-2024-0013_ref_043","doi-asserted-by":"crossref","unstructured":"D. A. Plaisted, \u201cSource-to-source translation and software engineering,\u201d Journal of Software Engineering and Applications, vol. 6, no. 4A, pp. 30\u2013 40, Apr. 2013. https:\/\/doi.org\/10.4236\/jsea.2013.64A005","DOI":"10.4236\/jsea.2013.64A005"},{"key":"2026070522564081544_j_acss-2024-0013_ref_044","unstructured":"M. Harsu, \u201cIdentifying object-oriented features from procedural software,\u201d Nordic Journal of Computing, vol. 7, no. 2, pp. 126\u2013142, 2000."},{"key":"2026070522564081544_j_acss-2024-0013_ref_045","unstructured":"S. Corporation, \u201cCoverty: Static analysis tool,\u201d Synopsys Documentation Portal. [Online]. Available: https:\/\/www.synopsys.com\/software-integrity\/static-analysis-tools-sast\/coverity.html"},{"key":"2026070522564081544_j_acss-2024-0013_ref_046","unstructured":"I. Gomes, P. Morgado, T. Gomes, and R. Moreira, \u201cAn overview on the static code analysis approach in software development,\u201d Faculdade de Engenharia da Universidade do Porto, Portugal, 2009. https:\/\/citeseerx.ist.psu.edu\/document?repid=rep1&type=pdf&doi=ce3c584c906eea668954f6a1a0ddbb295c6ec5a2"},{"key":"2026070522564081544_j_acss-2024-0013_ref_047","doi-asserted-by":"crossref","unstructured":"T. D. Oyetoyan, B. Milosheska, M. Grini, and D. Soares Cruzes, \u201cMyths and facts about static application security testing tools: An action research at telenor digital,\u201d in Agile Processes in Software Engineering and Extreme Programming. XP 2018. Lecture Notes in Business Information Processing, J. Garbajosa, X. Wang, and A. Aguiar, Eds., vol 314. Springer, Cham. https:\/\/doi.org\/10.1007\/978-3-319-91602-6_6","DOI":"10.1007\/978-3-319-91602-6_6"},{"key":"2026070522564081544_j_acss-2024-0013_ref_048","unstructured":"M. Zitser, \u201cSecuring software: An evaluation of static source code analyzers,\u201d Master\u2019s Thesis, Massachusetts Institute of Technology, Cambridge, MA, 2003."},{"key":"2026070522564081544_j_acss-2024-0013_ref_049","unstructured":"T. Hofer, \u201cEvaluating static source code analysis tools,\u201d Tech. Rep., Ecole Polytechnique F\u00e9d\u00e9rale de Lausanne, 2010. [Online]. Available: https:\/\/core.ac.uk\/download\/pdf\/147963417.pdf"},{"key":"2026070522564081544_j_acss-2024-0013_ref_050","doi-asserted-by":"crossref","unstructured":"M. Ashouri, \u201cPractical dynamic taint tracking for exploiting input sanitization error in java applications,\u201d in Information Security and Privacy: 24th Australasian Conference, ACISP 2019, Christchurch, New Zealand, Jul. 2019, pp. 494\u2013513. https:\/\/doi.org\/10.1007\/978-3-030-21548-4_27","DOI":"10.1007\/978-3-030-21548-4_27"},{"key":"2026070522564081544_j_acss-2024-0013_ref_051","doi-asserted-by":"crossref","unstructured":"N. Manzoor, H. Munir, and M. Moayyed, \u201cComparison of static analysis tools for finding concurrency bugs,\u201d in 2012 IEEE 23rd international symposium on software reliability engineering workshops, Dallas, TX, USA, Nov. 2012, pp. 129\u2013133. https:\/\/doi.org\/10.1109\/ISSREW.2012.28","DOI":"10.1109\/ISSREW.2012.28"},{"key":"2026070522564081544_j_acss-2024-0013_ref_052","doi-asserted-by":"crossref","unstructured":"F. Thung, Lucia, D. Lo, L. Jiang, F. Rahman, and P. T. Devanbu, \u201cTo what extent could we detect field defects? An empirical study of false negatives in static bug finding tools,\u201d in Proceedings of the 27th IEEE\/ACM International Conference on Automated Sof tware Engineering, Sep. 2012, pp. 50\u201359. https:\/\/doi.org\/10.1145\/2351676.2351685","DOI":"10.1145\/2351676.2351685"},{"key":"2026070522564081544_j_acss-2024-0013_ref_053","doi-asserted-by":"crossref","unstructured":"M. G. Nanda, M. Gupta, S. Sinha, S. Chandra, D. Schmidt, and P. Balachandran, \u201cMaking defect-finding tools work for you,\u201d in Proceedings of the 32Nd ACM\/IEEE International Conference on Software Engineering, vol. 2, May 2010, pp. 99\u2013108. https:\/\/doi.org\/10.1145\/1810295.1810310","DOI":"10.1145\/1810295.1810310"},{"key":"2026070522564081544_j_acss-2024-0013_ref_054","unstructured":"E. E. Schultz Jr, D. S. Brown, and T. A. Longstaff, \u201cResponding to computer security incidents: Guidelines for incident handling,\u201d Tech. Rep., Lawrence Livermore National Lab., CA (USA), 1990."},{"key":"2026070522564081544_j_acss-2024-0013_ref_055","unstructured":"A. S. S. C. A. T. K. SonarQube, \u201cCode Quality Tool & Secure Analysis with SonarQube.\u201d https:\/\/www.sonarsource.com\/products\/sonarqube\/"},{"key":"2026070522564081544_j_acss-2024-0013_ref_056","unstructured":"J. Novak, A. Krajnc, and R. Zontar, \u201cTaxonomy of static code analysis tools,\u201d in The 33rd International Convention MIPRO, 2010, pp. 418\u2013422. [Online]. Available: https:\/\/www.researchgate.net\/publication\/251940397_Taxonomy_of_static_code_analysis_tools"},{"key":"2026070522564081544_j_acss-2024-0013_ref_057","doi-asserted-by":"crossref","unstructured":"E. E. Mills, Software Metrics. Software Engineering Institute, 1988.","DOI":"10.21236\/ADA236140"},{"key":"2026070522564081544_j_acss-2024-0013_ref_058","unstructured":"L. Rosenberg, T. Hammer, and J. Shaw, \u201cSoftware metrics and reliability,\u201d in 9th international symposium on software reliability engineering, Nov. 1998."},{"key":"2026070522564081544_j_acss-2024-0013_ref_059","doi-asserted-by":"crossref","unstructured":"S. R. Chidamber and C. F. Kemerer, \u201cA metrics suite for object oriented design,\u201d IEEE Transactions on Software Engineering, vol. 20, no. 6, pp. 476\u2013493, Jun. 1994. https:\/\/doi.org\/10.1109\/32.295895","DOI":"10.1109\/32.295895"},{"key":"2026070522564081544_j_acss-2024-0013_ref_060","unstructured":"MacDonell, S.G., Buckingham, D., Gray, A.R. and Sallis, P.J., 2002. Software forensics: extending authorship analysis techniques to computer programs. Journal of Law and Information Science, 13, pp.34-69. https:\/\/openrepository.aut.ac.nz\/server\/api\/core\/bitstreams\/963770a7-cd78-4105-8385-99c6b0c4f64e\/content"},{"key":"2026070522564081544_j_acss-2024-0013_ref_061","unstructured":"\u201cPYPL PopularitY of Programming Language index.\u201d [Online]. Available: https:\/\/pypl.github.io\/PYPL.html"},{"key":"2026070522564081544_j_acss-2024-0013_ref_062","doi-asserted-by":"crossref","unstructured":"J. Zheng, L. Williams, N. Nagappan, W. Snipes, J. Hudepohl, and M. Vouk, \u201cOn the value of static analysis for fault detection in software,\u201d IEEE Transactions on Software Engineering, vol. 32, no. 4, pp. 240\u2013253, Apr. 2006. https:\/\/doi.org\/10.1109\/TSE.2006.38","DOI":"10.1109\/TSE.2006.38"},{"key":"2026070522564081544_j_acss-2024-0013_ref_063","unstructured":"D. Guaman, P. Sarmiento, L. Barba-Guaman, P. Cabrera, and L. Enciso, \u201cSonarQube as a tool to identify software metrics and technical debt in the source code through static analysis,\u201d in 7th International Workshop on Computer Science and Engineering, WCSE, Jan. 2017, pp. 171\u2013175."},{"key":"2026070522564081544_j_acss-2024-0013_ref_064","doi-asserted-by":"crossref","unstructured":"J. Garc\u00eda-Munoz, M. Garc\u00eda-Valls, and J. Escribano-Barreno, \u201cImproved metrics handling in SonarQube for software quality monitoring,\u201d in Distributed Computing and Artificial Intelligence, 13th International Conference, S. Omatu et al., Eds., Springer Cham, Jun. 2016, pp. 463\u2013 470. https:\/\/doi.org\/10.1007\/978-3-319-40162-1_50","DOI":"10.1007\/978-3-319-40162-1_50"},{"key":"2026070522564081544_j_acss-2024-0013_ref_065","doi-asserted-by":"crossref","unstructured":"V. Lenarduzzi, F. Lomio, H. Huttunen, and D. Taibi, \u201cAre SonarQube rules inducing bugs?\u201d in 2020 IEEE 27th international conference on software analysis, evolution and reengineering (SANER), London, ON, Canada, Feb. 2020, pp. 501\u2013511. https:\/\/doi.org\/10.1109\/SANER48275.2020.9054821","DOI":"10.1109\/SANER48275.2020.9054821"},{"key":"2026070522564081544_j_acss-2024-0013_ref_066","doi-asserted-by":"crossref","unstructured":"C. Vassallo, F. Palomba, A. Bacchelli, and H. C. Gall, \u201cContinuous code quality: are we (really) doing that?\u201d in Proceedings of the 33rd ACM\/IEEE International Conference on Automated Software Engineering, Sep. 2018, pp. 790\u2013795. https:\/\/doi.org\/10.1145\/3238147.3240729","DOI":"10.1145\/3238147.3240729"},{"key":"2026070522564081544_j_acss-2024-0013_ref_067","doi-asserted-by":"crossref","unstructured":"D. Marcilio, R. Bonifacio, E. Monteiro, E. Canedo, W. Luz, and G. Pinto, \u201cAre static analysis violations really fixed? A closer look at realistic usage of SonarQube,\u201d in 2019 IEEE\/ACM 27th International Conference on Program Comprehension (ICPC), Montreal, Canada, May 2019, pp. 209\u2013 219. https:\/\/doi.org\/10.1109\/ICPC.2019.00040","DOI":"10.1109\/ICPC.2019.00040"},{"key":"2026070522564081544_j_acss-2024-0013_ref_068","unstructured":"M. A. Al Mamun, A. Khanam, H. Grahn, and R. Feldt, \u201cComparing four static analysis tools for java concurrency bugs,\u201d in Third Swedish Workshop on Multi-Core Computing (MCC-10), 2010, pp. 18\u201319."},{"key":"2026070522564081544_j_acss-2024-0013_ref_069","doi-asserted-by":"crossref","unstructured":"V. Lenarduzzi, F. Pecorelli, N. Saarimaki, S. Lujan, and F. Palomba, \u201cA critical comparison on six static analysis tools: Detection, agreement, and precision,\u201d Journal of Systems and Software, vol. 198, Apr. 2023, Art. no. 111575. https:\/\/doi.org\/10.1016\/j.jss.2022.111575","DOI":"10.1016\/j.jss.2022.111575"},{"key":"2026070522564081544_j_acss-2024-0013_ref_070","doi-asserted-by":"crossref","unstructured":"R. P. Jetley, P. L. Jones, and P. Anderson, \u201cStatic analysis of medical device software using CodeSonar,\u201d in Proceedings of the 2008 workshop on Static analysis, Jun. 2008, pp. 22\u201329. https:\/\/doi.org\/10.1145\/1394504.1394507","DOI":"10.1145\/1394504.1394507"},{"key":"2026070522564081544_j_acss-2024-0013_ref_071","doi-asserted-by":"crossref","unstructured":"M. Beller, R. Bholanath, S. McIntosh, and A. Zaidman, \u201cAnalyzing the state of static analysis: A large-scale evaluation in open source software,\u201d in 2016 IEEE 23rd International Conference on Software Analysis, Evolution, and Reengineering (SANER), vol. 1, Osaka, Japan, Mar. 2016, pp. 470\u2013481. https:\/\/doi.org\/10.1109\/SANER.2016.105","DOI":"10.1109\/SANER.2016.105"},{"key":"2026070522564081544_j_acss-2024-0013_ref_072","unstructured":"Snyk, \u201cSnyk analysis tool for code security & code quality scanning,\u201d 2023. [Online]. Available: https:\/\/snyk.io\/product\/snyk-code\/"},{"key":"2026070522564081544_j_acss-2024-0013_ref_073","doi-asserted-by":"crossref","unstructured":"S. A. Licorish and M. Wagner, \u201cCombining GIN and PMD for code improvements,\u201d in Proceedings of the Genetic and Evolutionary Computation Conference Companion, Jul. 2022, pp. 790\u2013793. https:\/\/doi.org\/10.1145\/3520304.3528772","DOI":"10.1145\/3520304.3528772"},{"key":"2026070522564081544_j_acss-2024-0013_ref_074","doi-asserted-by":"crossref","unstructured":"N. Ayewah and W. Pugh, \u201cThe Google FindBugs fixit,\u201d in Proceedings of the 19th international symposium on Software testing and analysis, Trento Italy, Jul. 2010, pp. 241\u2013252. https:\/\/doi.org\/10.1145\/1831708.1831738","DOI":"10.1145\/1831708.1831738"},{"key":"2026070522564081544_j_acss-2024-0013_ref_075","unstructured":"T. Sharma, M. Kechagia, S. Georgiou, R. Tiwari, I. Vats, H. Moazen, and F. Sarro, \u201cA survey on machine learning techniques for source code analysis,\u201d arXiv preprint arXiv:2110.09610, 2021."}],"container-title":["Applied Computer Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/reference-global.com\/pdf\/10.2478\/acss-2024-0013","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,5]],"date-time":"2026-07-05T23:21:14Z","timestamp":1783293674000},"score":1,"resource":{"primary":{"URL":"https:\/\/reference-global.com\/article\/10.2478\/acss-2024-0013"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,1]]},"references-count":75,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2024,8,15]]},"published-print":{"date-parts":[[2024,6,1]]}},"alternative-id":["10.2478\/acss-2024-0013"],"URL":"https:\/\/doi.org\/10.2478\/acss-2024-0013","relation":{},"ISSN":["2255-8691"],"issn-type":[{"value":"2255-8691","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,6,1]]}}}