Code quality management method and system
By integrating Jenkins cluster, SonarQube tools and code quality management platform, the problem of inefficient code quality management in large-scale applications is solved, and efficient code quality detection and management is achieved.
Patent Information
- Application Number
- CN202510034695.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-05-06
AI Technical Summary
The existing technology has problems such as performance bottlenecks, insufficient data integration, information silos and insufficient visualization when dealing with large-scale applications, resulting in inefficient and comprehensive code quality management.
By integrating Jenkins cluster, SonarQube tool and code quality management platform, concurrent task processing, centralized management and analysis of code defects, and real-time data display and problem management are carried out through the visualization platform.
It significantly improves the code quality detection efficiency and management effect of large-scale applications, solves the problems of performance bottlenecks, insufficient data integration, information silos and insufficient visualization, and realizes closed-loop management of code quality.
Smart Images

Figure CN119938490A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of software engineering, and in particular to a code quality management method and system. Background Art
[0002] Currently, code quality management in software development usually relies on multiple independent tools and systems, such as continuous integration (CI) tools such as Jenkins for automated building and testing, code static analysis tools such as SonarQube for detecting code defects and security vulnerabilities, and quality management platforms such as Jira for defect tracking and management. However, existing technologies often have the following problems when dealing with large-scale applications:
[0003] 1. Performance bottlenecks and task delays: When the existing continuous integration (CI) system handles a large number of concurrent build and scan tasks, the performance of a single node is insufficient, which easily leads to task delays and system overload. This makes the build and test efficiency inefficient during the development of large-scale applications.
[0004] 2. Insufficient centralized management of analysis results: Existing code quality analysis tools, such as SonarQube, can detect code defects, but often lack centralized management and real-time update functions for analysis results. This makes it difficult to integrate quality data and cannot provide dynamic and comprehensive quality feedback.
[0005] 3. Information silos and insufficient data visualization: Quality management platforms are usually not tightly integrated with continuous integration and code analysis tools, resulting in serious information silos. Existing systems lack effective data visualization and problem management functions, and are unable to display and track code quality status and problem handling progress in real time.
[0006] 4. Lack of efficient quality data integration and push: Existing technologies are insufficient in integrating quality data into decision support systems and pushing them regularly. This makes it difficult for departments or teams to obtain code quality reports and problem handling status in a timely manner, thus affecting the overall quality management efficiency.
[0007] These problems lead to inefficient and incomplete code quality management. Summary of the invention
[0008] In view of this, the present invention provides a code quality management method and system to solve the problems of performance bottlenecks, insufficient data integration, information islands and insufficient visualization in the prior art. By integrating Jenkins cluster, SonarQube tool and code quality management platform, it can realize concurrent task processing, centralized management and analysis of code defects, and perform real-time data display and problem management through a visualization platform, thereby significantly improving the code quality detection efficiency and management effect of large-scale applications.
[0009] A code quality management method comprises the following steps:
[0010] S1, the Jenkins cluster pulls the latest source code of multiple applications and transfers the latest source code of each application to the SonarQube tool;
[0011] S2, the SonarQube tool scans and analyzes the latest source code of each application according to the set security rules to detect the code quality of each application and obtain the latest code quality data of each application;
[0012] S3, the code quality management platform regularly obtains the latest source code and the latest code quality data of all applications from the SonarQube tool, synchronizes the applications with updated codes to its application list, and locates the application managers corresponding to all applications in the application list according to the application information stored in the platform database;
[0013] At the same time, the code quality management platform cleans and processes the data it receives, produces visual quality analysis reports for each application, and pushes them to the corresponding application managers;
[0014] S4: The application manager logs in to the code quality management platform. The code quality management platform displays all applications within the user's authority in the application list according to the user's authority. The application manager selects the application in the application list and marks the problem handling status. Then, he modifies the code of the selected application offline. After the code modification is completed, it is uploaded to the Jenkins cluster in time.
[0015] Preferably, the security rules include: any one or several of the following security rules: Bug category, vulnerability category, odor category, and security hotspot category.
[0016] Preferably, the latest code quality data output by the SonarQube tool includes code coverage, number of defects, duplication rate, number of defective code lines, code smell, technical debt, and code vulnerabilities.
[0017] Preferably, in step S3, the code quality management platform obtains the latest scan results of all applications from the SonarQube tool every 15-20 minutes.
[0018] Preferably, in step S3, the application information stored in the platform database includes the application name, the application code, the application manager corresponding to the application, and the department to which the application manager belongs.
[0019] Preferably, in step S3, the code quality management platform cleans and processes the received data, and produces a visual quality analysis report of the application program in the following specific steps:
[0020] The code quality management platform calculates the defect rate per thousand lines of code based on the latest code quality data of the application;
[0021] The code quality management platform calculates the cumulative number of discovered problems, the cumulative number of resolved problems, and the number of problem handling reopenings based on the latest code quality data and historical code quality data of the application, and obtains a quality analysis view report;
[0022] The code quality management platform generates an overall report of the application based on the defect rate per thousand lines of code and the quality analysis view report, and generates a visual quality analysis report of the application based on the overall report of the application, the incremental code of the application, and the entire code.
[0023] Preferably, the code quality management platform can also count the resolution efficiency and the number of problems solved by each application manager for each application manager, and rank the application managers according to their resolution efficiency and the number of problems solved by them, so as to urge the application managers with lower rankings to solve code quality problems.
[0024] Preferably, the resolution efficiency includes the amount of quality issues processed, the time required to resolve code quality issues, and the number of reopening issues.
[0025] Preferably, the code quality management platform can also generate a department code quality report based on the department code quality.
[0026] A system for code quality management using the method includes a Jenkins cluster, a SonarQube tool and a code quality management platform.
[0027] The Jenkins cluster is used to pull the latest source code of multiple applications and transfer the latest source code of each application to the SonarQube tool;
[0028] The SonarQube tool is used to scan and analyze the latest source code of each application according to the set security rules to detect the quality of their respective codes and obtain the latest code quality data of each application;
[0029] The code quality management platform is used to obtain the latest source code and the latest code quality data of all applications from the SonarQube tool, synchronize the applications with updated codes to their application lists, and locate the application managers corresponding to all applications in the application list based on the application information stored in the platform database; at the same time, it cleans and processes the received data, and produces visual quality analysis reports for each application and pushes them to the corresponding application managers.
[0030] The beneficial effects of the present invention are:
[0031] 1. By integrating Jenkins cluster, SonarQube tool and code quality management platform, the present invention can realize concurrent task processing, centralized management and analysis of code defects, and perform real-time data display and problem management through a visualization platform, thereby significantly improving the code quality detection efficiency and management effect of large-scale applications, and effectively solving the problems of performance bottlenecks, insufficient data integration, information islands and insufficient visualization existing in the prior art.
[0032] 2. The present invention realizes closed-loop management of code quality by integrating Jenkins cluster, SonarQube tool and code quality management platform, covering the entire life cycle from code construction, scanning, analysis to data visualization and problem management, ensuring the comprehensiveness and systematicness of code quality management.
[0033] 3. The code quality management platform of the present invention can display the code quality scanning results of the SonarQube tool in real time and provide a dynamically updated code quality analysis report, making the code quality status and problem handling progress more intuitive and real-time, thereby improving the efficiency of management and decision-making; and can push the code quality analysis report and problem handling status to the relevant departments or application managers in a timely manner, so that the departments can obtain quality data and decision-making support in a timely manner, thereby improving the overall communication and management efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0035] Figure 1 It is a schematic flow diagram of the method of the present invention.
[0036] Figure 2 It is the operation flow chart of the code quality management platform. DETAILED DESCRIPTION
[0037] In order to make the purpose, technical scheme and advantages of the present invention clearer, the present invention is described below by the specific embodiments shown in the accompanying drawings. However, it should be understood that these descriptions are only exemplary and are not intended to limit the scope of the present invention. In addition, in the following description, the description of well-known structures and technologies is omitted to avoid unnecessary confusion of the concept of the present invention.
[0038] The terms used in this disclosure are for the purpose of describing specific embodiments only and are not intended to limit the disclosure. The singular forms of "a", "said" and "the" used in this disclosure and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.
[0039] In order to better understand the technical solution of the present invention, the present invention is described in detail below with reference to the accompanying drawings.
[0040] The present invention provides a code quality management method, which specifically comprises the following steps:
[0041] S1, the Jenkins cluster pulls the latest source code of multiple applications and transfers the latest source code of each application to the SonarQube tool.
[0042] Jenkins cluster usually refers to the collaboration of multiple Jenkins instances to improve the efficiency and reliability of building, testing and deploying software applications. These instances can be configured as a master node (Master) and multiple worker nodes (Agents or Slaves) to achieve a distributed build environment. The master node is responsible for task scheduling and management, and the slave nodes are used to concurrently execute build and scan tasks.
[0043] By configuring the corresponding git address and token in the Jenkins page config settings, pull the latest source code of multiple applications from version control systems such as GitLab, and transfer the latest source code of each application to the SonarQube tool.
[0044] According to different needs, you can pull the latest source code of multiple applications from version control systems such as GitLab on a daily basis, or you can pull the latest source code of multiple applications based on strategies such as branch change / merge scanning.
[0045] S2, the SonarQube tool scans and analyzes the latest source code of each application according to the set security rules to detect the quality of their respective codes, identify and report potential security risks and security vulnerabilities, and obtain the latest code quality data of each application.
[0046] The latest code quality data output by the SonarQube tool includes code coverage, number of defects, duplication rate, number of defective code lines, code smell, technical debt, and code vulnerabilities.
[0047] The security rules are divided into the following categories: Bug category (1k+), Vulnerability category (299), Taste category (2.1K), Security hotspot (305). The rule sources are: Sonar native rules, Alibaba Cloud rules. Special security rules can also be added according to needs.
[0048] S3: The code quality management platform periodically obtains the latest source code and the latest code quality data of all applications from the SonarQube tool. For example, the latest scan results of all applications can be obtained from the SonarQube tool every 15-20 minutes.
[0049] After the code quality management platform obtains the latest source code and the latest code quality data of the application, it stores all the data it obtains in its database, and synchronizes the applications with updated codes to its application list (the application list lists all applications with code quality problems), and locates the application managers corresponding to all applications in the application list based on the application information stored in the database. The application information stored in the database includes the application name, application code, the application manager corresponding to the application, and the department to which the application manager belongs.
[0050] At the same time, the code quality management platform cleans and processes the data it receives, creates a visual quality analysis report for each application, and pushes it to the corresponding application manager.
[0051] Specifically, the code quality management platform cleans and processes the data it receives and produces a visual quality analysis report of the application program in the following specific steps:
[0052] The code quality management platform calculates the defect rate per thousand lines of code based on the latest code quality data of the application, that is, the defect rate per thousand lines of code is calculated based on the number of defects and the number of defective code lines;
[0053] The code quality management platform calculates the cumulative number of problems found, the cumulative number of problems solved, the number of problem handling restarts and other quality indicators based on the scanned version data of an application (including the latest code quality data and historical code quality data), and obtains the quality analysis view report of the application. The quality analysis view report can visually display the defect results, defect handling status and trend charts after the code is scanned, and can track and classify the historical version codes of a code defect so that the application manager can perform unified code quality control;
[0054] The code quality management platform generates an overall report of the application based on code coverage, number of defects, duplication rate, number of defective code lines, code smell, technical debt, code vulnerabilities, defect rate per thousand lines of code, and quality analysis view reports. Based on the overall report of the application, the incremental code of the application, and all the code, it generates a visual quality analysis report of the application, and pushes the quality analysis report to the corresponding application manager.
[0055] The quality analysis report is divided into three levels: incremental code, total code and overall report.
[0056] Based on the above method, a visual quality analysis report can be generated for each application in turn, and the application manager can be located according to the program code of the application, and the quality analysis report can be pushed to the corresponding application manager. The application manager can repair the code for defects, odors or vulnerabilities recorded in the quality analysis report.
[0057] S4, the application manager logs in to the code quality management platform. The code quality management platform displays all applications within the user's authority in the application list according to the user's authority. The application manager selects the application in the application list and marks the problem handling status (such as "handled" or "unhandled"), and then modifies the code of the selected application offline. After the code modification is completed, it is uploaded to the Jenkins cluster in time.
[0058] Preferably, the code quality management platform can also count the resolution efficiency and the number of problems solved by each application manager for each application manager, and rank the application managers according to their resolution efficiency and the number of problems solved by the managers, so as to urge the application managers with lower rankings to solve the code quality problems. The resolution efficiency includes the number of quality problems handled, the time required to solve the code quality, and the number of problem handling restarts.
[0059] The problem handling reopening number refers to the number of times the application manager modifies the code for the same quality problem.
[0060] Preferably, the code quality management platform can also obtain the department to which the person in charge of each application belongs based on the application information stored in its database, and then collect statistics on the latest code quality data and historical code quality data of all applications belonging to the same department, and generate a department code quality report based on the department code quality. The department code quality report can record the code coverage, number of defects, repetition rate, number of defective code lines, code smell, technical debt, code vulnerabilities, defect rate per thousand lines of code, and the department's efficiency in solving quality problems.
[0061] The above code quality management method is described in detail below through specific examples.
[0062] S1, the Jenkins cluster pulls the initial source code of three applications A, B, and C from version control systems such as GitLab, and transfers the obtained initial source code to the SonarQube tool;
[0063] S2, the SonarQube tool scans and analyzes the initial source code of applications A, B, and C according to the set security rules to detect their respective code quality, identify and report potential security risks and security vulnerabilities, and obtain the latest code quality data of each application, including code coverage, number of defects, duplication rate, number of defective code lines, code smell, technical debt, code vulnerabilities, and defects;
[0064] Assume that the SonarQube tool scans and finds that applications A, B, and C all have defects, vulnerabilities, and odors. The SonarQube tool transmits data such as the problems, code coverage, number of defects, duplication rate, and number of defective code lines of these three programs to the code quality management platform;
[0065] S3: The code quality management platform stores the received data in its database, displays applications A, B, and C in the application list, and locates the application owner of each application based on the program code of each application. The code quality management platform generates a quality analysis report based on data such as code coverage, number of defects, duplication rate, number of defective code lines, code smell, technical debt, code vulnerabilities, and defect rate per thousand lines of code, and sends it to the application owner.
[0066] The application manager logs in to the code quality management platform, selects the application in the application list, marks the problem handling status of the application as "handled", modifies the quality issues of the application, and after the modification is completed, uploads the latest source code to the Jenkins cluster.
[0067] Assume that application A and application B are both managed by application manager a, and application C is managed by application manager b. After application managers a and b modify the problems of the applications they are responsible for, they upload the modified latest source code to the Jenkins cluster.
[0068] Then, the Jenkins cluster transfers the latest source code of the three applications to the SonarQube tool (the latest source code of the three applications is not necessarily sent to the Jenkins cluster at the same time). The SonarQube tool rescans the latest source code of the three applications to identify and report potential security risks and security vulnerabilities. Assuming that during this scan, applications A and B still have defects and vulnerabilities, and application C still has smells, the code quality management platform calculates the cumulative number of problems found, the cumulative number of problems solved, the number of problem handling reopenings and other quality indicators based on the code quality data of application A scanned twice, generates a quality analysis view report, and generates an overall report of the application based on code coverage, number of defects, repetition rate, number of defective code lines, code smell, technical debt, code vulnerabilities, thousand-line code defect rate and quality analysis view report, and generates a visual quality analysis report of the application based on the overall report of the application, the incremental code of the application and all the code, and pushes the quality analysis report to the application manager a; similarly, the quality analysis reports of applications B and C are pushed to the corresponding application managers.
[0069] Application managers A and B log in to the code quality management platform, select an application in the application list, mark the application's problem handling status as "handled", and modify the quality issues of the application. After the modification is completed, upload the latest source code to the Jenkins cluster and repeat the above steps until there are no quality issues with applications A, B, and C.
[0070] The above-mentioned Jenkins cluster is used as a continuous integration system. In other embodiments, other CI tools such as GitLab CI, Travis CI or CircleCI can be used to replace the Jenkins cluster, but corresponding configuration adjustments are required; the SonarQube tool is used for code quality analysis. In other embodiments, Checkmarx, Fortify or Coverity can be used to replace the SonarQube tool; and the code quality management platform can select Tableau, Grafana or PowerBI and other platforms.
[0071] Preferably, the code quality management platform of the present application can migrate all its stored data to a cloud service environment, such as AWS, Azure, or Google Cloud, to take advantage of the automatic expansion and high availability of cloud services to enhance the flexibility and stability of the system.
[0072] The present invention also provides a code quality management system, including a Jenkins cluster, a SonarQube tool and a code quality management platform.
[0073] The Jenkins cluster is used to pull the latest source code of multiple applications and transfer the latest source code of each application to the SonarQube tool;
[0074] The SonarQube tool is used to scan and analyze the latest source code of each application according to the set security rules to detect the quality of their respective codes and obtain the latest code quality data of each application;
[0075] The code quality management platform is used to obtain the latest source code and the latest code quality data of all applications from the SonarQube tool, synchronize the applications with updated codes to their application lists, and locate the application managers corresponding to all applications in the application list based on the application information stored in the platform database; at the same time, it cleans and processes the received data, and produces visual quality analysis reports for each application and pushes them to the corresponding application managers.
[0076] Preferably, the code quality management platform can also count the resolution efficiency and the number of problems solved by each application manager for each application manager, and rank the application managers according to their resolution efficiency and the number of problems solved by the managers, so as to urge the application managers with lower rankings to solve the code quality problems. The resolution efficiency includes the number of quality problems handled, the time required to solve the code quality, and the number of problem handling restarts.
[0077] The problem handling reopening number refers to the number of times the application manager modifies the code for the same quality problem.
[0078] Preferably, the code quality management platform can also obtain the department to which the person in charge of each application belongs based on the application information stored in its database, and then collect statistics on the latest code quality data and historical code quality data of all applications belonging to the same department, and generate a department code quality report based on the department code quality. The department code quality report can record the code coverage, number of defects, repetition rate, number of defective code lines, code smell, technical debt, code vulnerabilities, defect rate per thousand lines of code, and the department's efficiency in solving quality problems.
[0079] The present invention also provides a computer device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method when executing the computer program.
[0080] In addition, the logic instructions in the above-mentioned memory can be implemented in the form of software functional units and sold or used as independent products, and can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including several instructions for a computer device to perform all or part of the steps of the method described in the embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0081] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0082] It should be clear that the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
Claims
1. A code quality management method, characterized in that: The specific steps include: S1, the Jenkins cluster pulls the latest source code of multiple applications and transfers the latest source code of each application to the SonarQube tool; S2, the SonarQube tool scans and analyzes the latest source code of each application according to the set security rules to detect the code quality of each application and obtain the latest code quality data of each application; S3, the code quality management platform regularly obtains the latest source code and the latest code quality data of all applications from the SonarQube tool, synchronizes the applications with updated codes to its application list, and locates the application managers corresponding to all applications in the application list according to the application information stored in the platform database; At the same time, the code quality management platform cleans and processes the data it receives, produces visual quality analysis reports for each application, and pushes them to the corresponding application managers; S4: The application manager logs in to the code quality management platform. The code quality management platform displays all applications within the user's authority in the application list according to the user's authority. The application manager selects the application in the application list and marks the problem handling status. Then, he modifies the code of the selected application offline. After the code modification is completed, it is uploaded to the Jenkins cluster in time.
2. The code quality management method according to claim 1, characterized in that: The security rules include: any one or several of the following security rules: Bug category, vulnerability category, odor category, and security hotspot category.
3. The code quality management method according to claim 1, characterized in that: The latest code quality data output by the SonarQube tool includes code coverage, number of defects, duplication rate, number of defective code lines, code smell, technical debt, and code vulnerabilities.
4. The code quality management method according to claim 1, characterized in that: In step S3, the code quality management platform obtains the latest scan results of all applications from the SonarQube tool every 15-20 minutes.
5. The code quality management method according to claim 1, characterized in that: In step S3, the application information stored in the platform database includes the application name, application code, the application manager corresponding to the application, and the department to which the application manager belongs.
6. The code quality management method according to claim 1, characterized in that: In step S3, the code quality management platform cleans and processes the received data and produces a visual quality analysis report of the application program. The specific steps are as follows: The code quality management platform calculates the defect rate per thousand lines of code based on the latest code quality data of the application; The code quality management platform calculates the cumulative number of discovered problems, the cumulative number of solved problems, and the number of problem handling reopenings based on the latest code quality data and historical code quality data of the application, and obtains a quality analysis view report; The code quality management platform generates an overall report of the application based on the defect rate per thousand lines of code and the quality analysis view report, and generates a visual quality analysis report of the application based on the overall report of the application, the incremental code of the application, and the entire code.
7. The code quality management method according to claim 6, characterized in that: The code quality management platform can also count the resolution efficiency and the number of problems solved by each application manager for each application manager, and rank the application managers according to their resolution efficiency and the number of problems solved by them, so as to urge the application managers with lower rankings to solve code quality problems.
8. The code quality management method according to claim 7, characterized in that: The resolution efficiency includes the number of quality issues handled, the time required to resolve code quality issues, and the number of problem handling reopenings.
9. The code quality management method according to claim 6, characterized in that: The code quality management platform can also generate a department code quality report based on the department code quality.
10. A system for code quality management using the method according to any one of claims 1 to 9, characterized in that: Including Jenkins cluster, SonarQube tool and code quality management platform, The Jenkins cluster is used to pull the latest source code of multiple applications and transfer the latest source code of each application to the SonarQube tool; The SonarQube tool is used to scan and analyze the latest source code of each application according to the set security rules to detect the quality of their respective codes and obtain the latest code quality data of each application; The code quality management platform is used to obtain the latest source code and the latest code quality data of all applications from the SonarQube tool, synchronize the applications with updated codes to their application lists, and locate the application managers corresponding to all applications in the application list based on the application information stored in the platform database; at the same time, it cleans and processes the received data, and produces visual quality analysis reports for each application and pushes them to the corresponding application managers.