IDE Support for Cloud-Based Static Analyses
Zusammenfassung
We present a user study with developers at Amazon Web Services on their expectations of IDE support for cloud-based static analyses. The paper was originally presented at ESEC/FSE 2021. Many companies are providing Static Application Security Testing (SAST) tools as a service. These tools fit well into CI/CD, because CI/CD allows time for deep static analyses on large code bases and prevents vulnerabilities in the early stages of the development lifecycle. In CI/CD, the SAST tools usually run in the cloud and provide findings via a web interface. Recent studies show that developers prefer seeing the findings of these tools directly in their IDEs. Most tools with IDE integration run lightweight static analyses and can give feedback at coding time, but SAST tools take longer to run and usually are not able to do so. Can developers interact directly with a cloud-based SAST tool that is typically used in CI/CD through their IDE? We conducted a user study to explore how such IDE support should be designed. Through this study we identified the key design elements expected by developers and investigated whether an IDE solution fits better into developers’ workflow in comparison to a web-based solution.
- Vollständige Referenz
- BibTeX
Luo, L. & Bodden, E.,
(2022).
IDE Support for Cloud-Based Static Analyses.
In:
Grunske, L., Siegmund, J. & Vogelsang, A.
(Hrsg.),
Software Engineering 2022.
Bonn:
Gesellschaft für Informatik e.V..
(S. 61-63).
DOI: 10.18420/se2022-ws-019
@inproceedings{mci/Luo2022,
author = {Luo, Linghui AND Bodden, Eric},
title = {IDE Support for Cloud-Based Static Analyses},
booktitle = {Software Engineering 2022},
year = {2022},
editor = {Grunske, Lars AND Siegmund, Janet AND Vogelsang, Andreas} ,
pages = { 61-63 } ,
doi = { 10.18420/se2022-ws-019 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
author = {Luo, Linghui AND Bodden, Eric},
title = {IDE Support for Cloud-Based Static Analyses},
booktitle = {Software Engineering 2022},
year = {2022},
editor = {Grunske, Lars AND Siegmund, Janet AND Vogelsang, Andreas} ,
pages = { 61-63 } ,
doi = { 10.18420/se2022-ws-019 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
Sollte hier kein Volltext (PDF) verlinkt sein, dann kann es sein, dass dieser aus verschiedenen Gruenden (z.B. Lizenzen oder Copyright) nur in einer anderen Digital Library verfuegbar ist. Versuchen Sie in diesem Fall einen Zugriff ueber die verlinkte DOI: 10.18420/se2022-ws-019
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
ISBN: 978-3-88579-714-2
ISSN: 1617-5468
Datum: 2022
Sprache:
(en)
(en)
Typ: Text/Conference Paper

