Welcome!

Java Authors: Carmen Gonzalez, Elizabeth White, Sematext Blog, Kevin Benedict, Pat Romanski

Related Topics: Java, XML, AJAX & REA, Apache

Java: Blog Post

Exploit the Results of Pmd, Findbugs and CheckStyle

Go deep inside the reults of the known Java static analysis tools.

Many Java static analysis tools exist right here, each one focusing on a specific area and each one has its advantages, we can enumerate:

  • Pmd which is a static rule-set based Java source code analyzer that identifies potential problems like:
    • Possible bugs—Empty try/catch/finally/switch blocks.
    • Dead code—Unused local variables, parameters and private methods.
    • Empty if/while statements.
    • Overcomplicated expressions—Unnecessary if statements, for loops that could be while loops.
    • Suboptimal code—Wasteful String/StringBuffer usage.
  • FindBugs which looks for bugs in Java code. It uses static analysis to identify hundreds of different potential types of errors in Java programs.
  • Checkstyle defines a set of available modules, each of which provides rules checking with a configurable level of strictness (mandatory, optional...). Each rule can raise notifications, warnings, and errors.

Many ways exist to exploit the results of these tools:

  • XML format: XML files could be generated from each of these tools, and it can be used to create an HTML report or used by another tool to exploit the analysis result.
  • HTML format: HTML report is the prefered way to generate reports and share them between the team, and you can create your custom report by using an xsl stylesheet.
  • IDE Plugins: almost all known IDE provides plugins for these tools, which gives the possibility to discover all violations from the source code.

One of the problems with code quality tools is that they tend to overwhelm developers with problems that aren't really problems -- that is, false positives. When false positives occur, developers learn to ignore the output of the tool or abandon it altogether.

And to exploit better their result, it's better to have a way to focus only on what we want and gives to developers a useful view. In this post we will discover another interesting way to exploit better the result of all known java static analysis tools, and query them like a database.

JArchitect and CQLinq
JArchitect
is another static analysis tool which complements the other tools, it uses a code query langage based on Linq ( CQLinq) to query the code base like a database.

Until JArchitect 3 you can query only analysis data extracted from JArchitect, however the V4 gives the possibility to import the analysis result from many other static analysis tools and query them with CQLinq.
Let's take as example the source code of the PDT core (the Php plugin for eclipse). and discover how we can exploit the analysis result of these tools from JArchitect.

To begin here are the steps to follows before requesting the analysis result:

  • Step1: Analyse the project with PMD, CPD, FindBugs and CheckStyle. And generate the XML files containing the result.
  • Step2: Analyze the project with JArchitect.
  • Step3: Import all the xml files into JArchitect from the menu "Plugins->Import Plugins Result Files"

JArchitect provides by default many useful queries to request these tools, and all these queries could be customized easilly.

plugins2

Let's discover some CQLinq queries:

Get all issues:

The request to get all issues is very simple, however as you can see it's not very interesting, indeed it's a challenge to exploit a result with 232 725 issues.

plugins1

To exploit better the result of these tools we can filter it with CQLinq and focus only on what we want.

Request by tool
We can modify the first request and add a criteria about the tool concerned.
plugins3

Request by ruleset

We can also filter by issue ruleset :

plugins20

Request by priority
We can also filter by priority:

plugins8

Most recurrent issues

It's interesting to know which issues are the most reported by these tools.

plugins10

Classes having most issues

It's very interesting to know the classes which contains many violations

plugins16

As we can observe CheckStyle report thousand of issues and many of them could be ignored.

The previous query is interesting, but it's not give us exactly the classes with lack of quality, another useful metric to take into account is the NBLinesOfCode, it's normal that a class with many lines of code contains many issues, for that we can modify the previous request to calculate the ratio between the Issues count and the NBLinesofCode.

plugins17

What's very strange in this result is that the ratio of the 8 first classes is more than 200, in this case we have more than 200 issues by code line.

To explain this behavior let's take a look at some lines of the CompilerAstParser:

plugins18

The NbLinesOfCode is the number of statements and not the physical lines, and this Class declare many arrays , each one is declared by thousand of physical lines, however each array declaration is considered as one statement.

And as shown before for the most recurrent issues query, the following rule '+' should be on a new line. is violated thousand of times for each array. Maybe it's better to remove these kind of rules from the CheckStyle configuration file.

Most popular methods having issues

When the static analysis tools report the issues, it's useful to locate which the prioritary issues to resolve? specially if it concerns bugs.

It's true that a bug could exist in a specific method, but what interesting to know is how many methods are impacted by the bug, and the popular method are the most used ones and it's better to resolve them quickly.

plugins11

Using CQLinq we can combine the result of all these tools and also the result of JArchitect to create more elaborated queries, and add these checks to the build process.

Issues Trend

Having issues in a project is not bad, we can say that's normal, however we have to check the quality trend of the project. Indeed it's a bad indicator if the number of issues grows after changes and evolutions. /p>

JArchitect provides the Trend Monitoring feature to create trend charts. Trend charts are made of trend metrics values logged over time at analysis time. More than 50 trend metrics are available per default and it is easy to create your own trend metrics.

Let's create a trend metric for the Pmd issues:

plugins6

And after you can easily create the trend chart to monitor the previous trend metric and add it to the JArchitect dashboard.

plugins19

With this trend chart we can monitor the evolution of the Pmd issues, and try to understand the reasons when the metric grows over versions.

Customize the JArchitect report

JArchitect make possible to append extra report sections in the HTML report that lists some CQLinq queries. In the CQLinq Query Explorer panel, a particular CQLinq group reported is bordered with an orange rectangle.

plugins12

You can also add to the report the Pmd trend chart:

plugins15

And in the HTML report these added sections are accesible from the menu:

plugins13

And here's the page added in the report for the Pmd CQLinq queries:

plugins14

Conclusion
JArchitect 4 is now open to other static analysis tools, and you can also plug your customized tool easily as descibed here. This way you can use all the JArchitect features to exploit better the result from the known java static analysis tools.

More Stories By Lahlali Issam

Lahlali Issam Lead Developer at JavaDepend, a tool to manage and understand complex Java code. With JavaDepend, software quality can be measured using Code Metrics, visualized using Graphs and Treemaps, and queried using CQL language, a SQL like to query the code base.

@ThingsExpo Stories
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is now open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.
Technology is enabling a new approach to collecting and using data. This approach, commonly referred to as the "Internet of Things" (IoT), enables businesses to use real-time data from all sorts of things including machines, devices and sensors to make better decisions, improve customer service, and lower the risk in the creation of new revenue opportunities. In his General Session at Internet of @ThingsExpo, Dave Wagstaff, Vice President and Chief Architect at BSQUARE Corporation, discuss the real benefits to focus on, how to understand the requirements of a successful solution, the flow of ...
"People are a lot more knowledgeable about APIs now. There are two types of people who work with APIs - IT people who want to use APIs for something internal and the product managers who want to do something outside APIs for people to connect to them," explained Roberto Medrano, Executive Vice President at SOA Software, in this SYS-CON.tv interview at Cloud Expo, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
We’re no longer looking to the future for the IoT wave. It’s no longer a distant dream but a reality that has arrived. It’s now time to make sure the industry is in alignment to meet the IoT growing pains – cooperate and collaborate as well as innovate. In his session at @ThingsExpo, Jim Hunter, Chief Scientist & Technology Evangelist at Greenwave Systems, will examine the key ingredients to IoT success and identify solutions to challenges the industry is facing. The deep industry expertise behind this presentation will provide attendees with a leading edge view of rapidly emerging IoT oppor...
In this Women in Technology Power Panel at 15th Cloud Expo, moderated by Anne Plese, Senior Consultant, Cloud Product Marketing at Verizon Enterprise, Esmeralda Swartz, CMO at MetraTech; Evelyn de Souza, Data Privacy and Compliance Strategy Leader at Cisco Systems; Seema Jethani, Director of Product Management at Basho Technologies; Victoria Livschitz, CEO of Qubell Inc.; Anne Hungate, Senior Director of Software Quality at DIRECTV, discussed what path they took to find their spot within the technology industry and how do they see opportunities for other women in their area of expertise.
DevOps Summit 2015 New York, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that it is now accepting Keynote Proposals. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete at launch. DevOps may be disruptive, but it is essential.
The Industrial Internet revolution is now underway, enabled by connected machines and billions of devices that communicate and collaborate. The massive amounts of Big Data requiring real-time analysis is flooding legacy IT systems and giving way to cloud environments that can handle the unpredictable workloads. Yet many barriers remain until we can fully realize the opportunities and benefits from the convergence of machines and devices with Big Data and the cloud, including interoperability, data security and privacy.
Wearable devices have come of age. The primary applications of wearables so far have been "the Quantified Self" or the tracking of one's fitness and health status. We propose the evolution of wearables into social and emotional communication devices. Our BE(tm) sensor uses light to visualize the skin conductance response. Our sensors are very inexpensive and can be massively distributed to audiences or groups of any size, in order to gauge reactions to performances, video, or any kind of presentation. In her session at @ThingsExpo, Jocelyn Scheirer, CEO & Founder of Bionolux, will discuss ho...
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is now open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.
Connected devices and the Internet of Things are getting significant momentum in 2014. In his session at Internet of @ThingsExpo, Jim Hunter, Chief Scientist & Technology Evangelist at Greenwave Systems, examined three key elements that together will drive mass adoption of the IoT before the end of 2015. The first element is the recent advent of robust open source protocols (like AllJoyn and WebRTC) that facilitate M2M communication. The second is broad availability of flexible, cost-effective storage designed to handle the massive surge in back-end data in a world where timely analytics is e...

ARMONK, N.Y., Nov. 20, 2014 /PRNewswire/ --  IBM (NYSE: IBM) today announced that it is bringing a greater level of control, security and flexibility to cloud-based application development and delivery with a single-tenant version of Bluemix, IBM's platform-as-a-service. The new platform enables developers to build ap...

Building low-cost wearable devices can enhance the quality of our lives. In his session at Internet of @ThingsExpo, Sai Yamanoor, Embedded Software Engineer at Altschool, provided an example of putting together a small keychain within a $50 budget that educates the user about the air quality in their surroundings. He also provided examples such as building a wearable device that provides transit or recreational information. He then reviewed the resources available to build wearable devices at home including open source hardware, the raw materials required and the options available to power s...
The Internet of Things promises to transform businesses (and lives), but navigating the business and technical path to success can be difficult to understand. In his session at @ThingsExpo, Sean Lorenz, Technical Product Manager for Xively at LogMeIn, demonstrated how to approach creating broadly successful connected customer solutions using real world business transformation studies including New England BioLabs and more.
Since 2008 and for the first time in history, more than half of humans live in urban areas, urging cities to become “smart.” Today, cities can leverage the wide availability of smartphones combined with new technologies such as Beacons or NFC to connect their urban furniture and environment to create citizen-first services that improve transportation, way-finding and information delivery. In her session at @ThingsExpo, Laetitia Gazel-Anthoine, CEO of Connecthings, will focus on successful use cases.
The Internet of Things is a misnomer. That implies that everything is on the Internet, and that simply should not be - especially for things that are blurring the line between medical devices that stimulate like a pacemaker and quantified self-sensors like a pedometer or pulse tracker. The mesh of things that we manage must be segmented into zones of trust for sensing data, transmitting data, receiving command and control administrative changes, and peer-to-peer mesh messaging. In his session at @ThingsExpo, Ryan Bagnulo, Solution Architect / Software Engineer at SOA Software, focused on desi...
Enthusiasm for the Internet of Things has reached an all-time high. In 2013 alone, venture capitalists spent more than $1 billion dollars investing in the IoT space. With "smart" appliances and devices, IoT covers wearable smart devices, cloud services to hardware companies. Nest, a Google company, detects temperatures inside homes and automatically adjusts it by tracking its user's habit. These technologies are quickly developing and with it come challenges such as bridging infrastructure gaps, abiding by privacy concerns and making the concept a reality. These challenges can't be addressed w...
The Domain Name Service (DNS) is one of the most important components in networking infrastructure, enabling users and services to access applications by translating URLs (names) into IP addresses (numbers). Because every icon and URL and all embedded content on a website requires a DNS lookup loading complex sites necessitates hundreds of DNS queries. In addition, as more internet-enabled ‘Things' get connected, people will rely on DNS to name and find their fridges, toasters and toilets. According to a recent IDG Research Services Survey this rate of traffic will only grow. What's driving t...
"For over 25 years we have been working with a lot of enterprise customers and we have seen how companies create applications. And now that we have moved to cloud computing, mobile, social and the Internet of Things, we see that the market needs a new way of creating applications," stated Jesse Shiah, CEO, President and Co-Founder of AgilePoint Inc., in this SYS-CON.tv interview at 15th Cloud Expo, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
The Internet of Things is tied together with a thin strand that is known as time. Coincidentally, at the core of nearly all data analytics is a timestamp. When working with time series data there are a few core principles that everyone should consider, especially across datasets where time is the common boundary. In his session at Internet of @ThingsExpo, Jim Scott, Director of Enterprise Strategy & Architecture at MapR Technologies, discussed single-value, geo-spatial, and log time series data. By focusing on enterprise applications and the data center, he will use OpenTSDB as an example t...
The industrial software market has treated data with the mentality of “collect everything now, worry about how to use it later.” We now find ourselves buried in data, with the pervasive connectivity of the (Industrial) Internet of Things only piling on more numbers. There’s too much data and not enough information. In his session at @ThingsExpo, Bob Gates, Global Marketing Director, GE’s Intelligent Platforms business, to discuss how realizing the power of IoT, software developers are now focused on understanding how industrial data can create intelligence for industrial operations. Imagine ...