Railway application software research and development process management method

Through a railway application software R&D process management method, the problems of irregular R&D process and non-standard technical control are solved, a complete closed loop from business needs to software release is achieved, the efficiency and quality of software R&D are improved, and the recognition of the business parties is obtained.

CN120045164AActive Publication Date: 2025-05-27CHINA ACADEMY OF RAILWAY SCI CORP LTD +2
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510189441.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-27
Estimated Expiration
2045-02-20

AI Technical Summary

Technical Problem

The research and development process of railway application software is not standardized and the technical control is not standard, resulting in low efficiency and poor quality of software research and development, and it cannot be recognized by the business parties.

Method used

Provides a railway application software R&D process management method, which can determine R&D demand information by obtaining business demand information, analyzing, dismantling and distributing, conducting architectural design and branch development, monitoring development progress in real time, performing automatic static code scanning and merging, building code, packaging and storage, conducting security information scanning and acceptance testing, and ultimately achieving a complete closed loop from business demand to software release.

Benefits of technology

It has realized the standardization and standardization of the railway application software R&D process, improved the efficiency and quality of software R&D, and ensured the idealness of software development results and the recognition of business parties.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120045164A_ABST
    Figure CN120045164A_ABST
Patent Text Reader

Abstract

The invention discloses a railway application software research and development process management method, and relates to the technical field of railway application software research and development management, and the method comprises the steps: obtaining the business demand information of a railway application software research and development project; research and development demand information is determined through analysis, disassembly and distribution; performing architecture design to determine a research and development task, and generating a software architecture diagram; performing branch development on the research and development task to form a plurality of development tasks; performing automatic static code scanning on branch codes corresponding to the developed development tasks; combining the branch codes which are subjected to automatic static code scanning; automatically constructing a code, and packaging and storing to obtain a product; performing safety information scanning on the product; and carrying out acceptance test and release on the product of which the safety information is scanned. The research and development process of the railway application software is normalized and standardized, and the software research and development efficiency and quality can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of railway application software R & D management, and particularly to a method for managing the R & D process of railway application software. Background Art

[0002] At present, there are problems in the R & D of railway application software, such as non-standard R & D processes and non-standard technical control. First, there are a large number of information systems in each railway business, and the requirements proposed by the business side are not responded to in a timely manner, and there is a lack of review of requirements, which often causes problems of duplicate development. Second, the entire R & D process lacks unified management of the architecture and has weak collaborative development capabilities. In addition, test management is lacking, there is a lack of necessary test case input in the test link, and the correspondence with requirements is weak during acceptance.

[0003] In summary, due to the reasons of non-standard R & D processes and non-standard technical control mentioned above, the efficiency of software R & D is ultimately low, the quality is poor, the software development results are not ideal, and they cannot be recognized by the business side.

[0004] Based on this, how to provide a method for managing the R & D process of railway application software with standardized R & D processes and technical control standards to improve the efficiency and quality of software R & D has become a technical problem to be solved urgently in this field. Summary of the Invention

[0005] The purpose of this application is to provide a method for managing the R & D process of railway application software, which standardizes and standardizes the R & D process of railway application software and is beneficial to improving the efficiency and quality of software R & D.

[0006] To achieve the above purpose, this application provides the following solutions:

[0007] A method for managing the R & D process of railway application software, the method for managing the R & D process of railway application software includes:

[0008] Obtain the business requirement information of the R & D project of railway application software;

[0009] Analyze, disassemble and distribute the business requirement information to determine the R & D requirement information;

[0010] Conduct architecture design according to the R & D requirement information to determine the R & D tasks and generate a software architecture diagram; the software architecture diagram includes source code security information;

[0011] Conduct branch development on the R & D tasks to form multiple development tasks, and at the same time, monitor the development progress of each development task in real time;

[0012] Automatically perform static code scanning on the branch code corresponding to the completed development tasks, and update the source code security information in the software architecture diagram according to the results of the automatic static code scanning; the branch code includes development branch code and main branch code;

[0013] Merge the branch code that has completed automatic static code scanning to obtain the merged code;

[0014] Automatically build, package, and store the merged code to obtain an artifact;

[0015] Perform security information scanning on the artifact to obtain the artifact with completed security information scanning;

[0016] Conduct acceptance testing and release on the artifact with completed security information scanning.

[0017] Optionally, the railway application software R & D process management method is applied to a railway application software R & D process management system, which includes a project management module, a continuous integration and delivery module, a testing module, and an environment management module. The project management module, the continuous integration and delivery module, and the testing module are connected in sequence, and the environment management module is connected to the project management module, the continuous integration and delivery module, and the testing module respectively;

[0018] The project management module is used to register the project information of the railway application software R & D project, and the project information includes project name, business party information, project investment information, and sub - project information;

[0019] The continuous integration and delivery module is used to register the system information corresponding to the railway application software R & D project, and the system information includes system name and system function brief introduction, and selects the corresponding project or sub - project for association through information synchronization with the project management module;

[0020] The testing module is used to provide test case management capabilities and testing capabilities for UI testing, interface testing, and performance testing to support functional testing and acceptance testing, and generate test results;

[0021] The environment management module is used to provide and manage the resources required for containerized application operation, and divide the resources into a test area, a pre - release area, and a production area, and the test area, the pre - release area, and the production area are isolated from each other.

[0022] Optionally, obtaining the business requirement information of the railway application software R & D project specifically includes:

[0023] Use the project management module to enter the project information of the railway application software R & D project;

[0024] Determine the business requirement information of the railway application software R & D project according to the said project information;

[0025] Conduct a preliminary review of the business requirement information. The preliminary review refers to reviewing and screening the business requirement information, returning the unreasonable requirements and the requirements that do not need to be satisfied in the business requirement information for modification, and taking the reasonable requirements and the requirements that need to be satisfied in the business requirement information as the business requirement information, and execute the step of "analyzing, disassembling and distributing the business requirement information to determine the R & D requirement information".

[0026] Optionally, analyze, disassemble and distribute the business requirement information to determine the R & D requirement information, specifically including:

[0027] Use the project management module to analyze and disassemble the business requirement information to generate the R & D requirement information;

[0028] Enter the R & D requirement information into the sub-project in the project management module, and at the same time enter the acceptance test cases in the test module.

[0029] Optionally, conduct branch development on the R & D tasks to form multiple development tasks, and at the same time monitor the development progress of each development task in real time, specifically including:

[0030] Create a development branch according to the R & D task by using the continuous integration and delivery module to form multiple development tasks;

[0031] Use the continuous integration and delivery module to synchronize the development task information of all the development tasks and display the development task information in the form of a list;

[0032] Associate the branch names of each development task and the development branch, and after association, perform code pulling and development, and monitor the development progress of each development task in real time.

[0033] Optionally, conduct automatic static code scanning on the branch code corresponding to the completed development task, and update the source code security information in the software architecture diagram according to the automatic static code scanning result, specifically including:

[0034] Use the continuous integration and delivery module to conduct automatic static code scanning on the branch code corresponding to the completed development task to obtain the automatic static code scanning result; the automatic static code scanning result includes passing the automatic static code scanning or failing the automatic static code scanning;

[0035] Based on the results of the automatic static code scanning, issue a warning for the branch code that fails the automatic static code scanning, and send the results of the automatic static code scanning to the project management module;

[0036] Based on the results of the automatic static code scanning, use the project management module to update the source code security information in the software architecture diagram.

[0037] Optionally, merge the branch code that has completed automatic static code scanning to obtain the merged code, which specifically includes:

[0038] For the branch code that has completed automatic static code scanning, use the continuous integration and delivery module to initiate a branch merge request, which refers to a request to merge the development branch code and the main branch code in the branch code that has completed automatic static code scanning;

[0039] When the branch merge request is approved, use the continuous integration and delivery module to merge the development branch code and the main branch code in the branch code that has completed automatic static code scanning to obtain the merged code;

[0040] When the branch merge request is not approved, return the branch code that has completed automatic static code scanning for modification.

[0041] Optionally, automatically build, package, and store the merged code to obtain an artifact, which specifically includes:

[0042] Use the continuous integration and delivery module to automatically build and package the merged code, and at the same time analyze the dependencies referenced by the source code, generate software composition analysis SPDX document data, and synchronize the software composition analysis SPDX document data to the project management module;

[0043] Based on the software composition analysis SPDX document data, use the project management module to update all the dependency information of the components in the software architecture diagram, and the dependency information includes the dependency package name, dependency package version number, dependency package source, and information on whether the dependency package is open source;

[0044] Use the continuous integration and delivery module to store the packaged artifact in the artifact repository and generate the name and version number of the artifact.

[0045] Optionally, scan the security information of the artifact to obtain the artifact with the security information scanned, which specifically includes:

[0046] Use the continuous integration and delivery module to perform a security information scan on the artifact, generate security risk information of the artifact, and send the security risk information of the artifact to the project management module;

[0047] According to the security risk information of the artifact, use the project management module to update the software architecture diagram and the security risk information of the artifact;

[0048] Use the continuous integration and delivery module to perform a tagging operation on the artifact that has passed the security information scan, and generate tag information of the artifact;

[0049] According to the tag information of the artifact, perform a tag check on the artifact, and use the continuous integration and delivery module to deploy the artifact that has passed the tag check.

[0050] Optionally, perform an acceptance test and release on the artifact that has completed the security information scan, specifically including:

[0051] Use the environment management module to deploy environment information, and at the same time use the continuous integration and delivery module to add and configure the environment information; the environment information includes a test environment, a pre-release environment, and a production environment;

[0052] Based on the environment information, use the test module to provide UI testing, interface testing, and function testing for the artifact that has completed the security information scan, and generate a test result; the test result includes passing the acceptance test or failing the acceptance test;

[0053] Synchronize the test result to the project management module, and form a new work task according to the artifact that has failed the acceptance test; the new work task is used to modify the defects of the software corresponding to the artifact that has failed the acceptance test;

[0054] According to the test result, use the continuous integration and delivery module to deploy the artifact that has passed the acceptance test in the production environment, and access the new version after the software update according to the URL published by the environment management module, so as to realize the closed-loop from business requirements to software release.

[0055] According to the specific embodiments provided by the present application, the present application discloses the following technical effects:

[0056] This application provides a method for managing the research and development process of railway application software. By obtaining the business requirement information of the railway application software research and development project, the research and development requirement information is determined through analysis, decomposition, and distribution; then, the architecture design is carried out to determine the research and development tasks, and a software architecture diagram is generated; then, through branch development, automatic static code scanning, branch code merging, and building, packaging, and storing the code, the artifacts are formed; finally, the artifacts are scanned for security information, and the artifacts that have completed the security information scanning are subjected to acceptance testing and release. Based on the business requirement information, through operations such as automatic static code scanning and security information scanning, the acceptance testing and release of the artifacts are completed, realizing a complete closed-loop from business requirements to software release, standardizing and standardizing the research and development process of railway application software, improving the efficiency and quality of software research and development, thus obtaining a more ideal software development result, and further facilitating the recognition by the business side. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0058] Figure 1 It is an application environment diagram of a method for managing the research and development process of railway application software provided by an embodiment of the present application.

[0059] Figure 2 It is a flowchart of a method for managing the research and development process of railway application software provided by an embodiment of the present application.

[0060] Figure 3 It is a structural diagram of a system for managing the research and development process of railway application software provided by an embodiment of the present application.

[0061] Figure 4 It is a flowchart of the working process of each functional module provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0062] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0063] To make the above objects, features, and advantages of the present application more apparent and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0064] The railway application software R & D process management method provided by the embodiments of the present application can be applied to an application environment as Figure 1 shown. Among them, the terminal 102 communicates with the server 104 through a network. The data storage system can store the data that the server 104 needs to process. The data storage system can be set up separately, integrated on the server 104, or placed on the cloud or other servers. The terminal 102 can send the business requirement information to the server 104. After receiving the business requirement information, for the business requirement information, the server 104 analyzes, disassembles, and distributes it to determine the R & D requirement information; then conducts an architecture design to determine the R & D tasks and generates a software architecture diagram; conducts branch development on the R & D tasks to form multiple development tasks; automatically performs static code scanning on the branch code corresponding to the completed development tasks; merges the branch code that has completed automatic static code scanning; automatically builds the code, packages it, and stores it to obtain an artifact; performs security information scanning on the artifact; conducts acceptance testing and release on the artifact that has completed security information scanning. The server 104 can feedback the released software artifact to the terminal 102. In addition, in some embodiments, the railway application software R & D process management method can also be implemented separately by the server 104 or the terminal 102. For example, the terminal 102 can directly perform software R & D processing on the business requirement information, or the server 104 can obtain the business requirement information from the data storage system and perform software R & D processing on the business requirement information.

[0065] Among them, the terminal 102 can be, but is not limited to, various desktop computers, laptop computers, tablet computers, etc. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers, and can also be a cloud server.

[0066] In an exemplary embodiment, as Figure 2 shown, a railway application software R & D process management method is provided. This method is executed by a computer device, and can be specifically executed alone by a computer device such as a terminal or a server, or jointly executed by a terminal and a server. In the embodiments of the present application, taking this method applied to Figure 1 the server 104 as an example for description, it includes the following steps S1 to step S9.

[0067] Step S1: Obtain the business requirement information of the railway application software R & D project.

[0068] Step S2: Analyze, disassemble, and distribute the business requirement information to determine the R & D requirement information.

[0069] Step S3: Based on the R & D requirement information, conduct an architecture design, determine the R & D tasks, and generate a software architecture diagram; the software architecture diagram includes source code security information.

[0070] Step S4: Conduct branch development on the R & D tasks to form multiple development tasks, and simultaneously monitor the development progress of each development task in real time.

[0071] Step S5: Automatically perform static code scanning on the branch code corresponding to the completed development tasks, and update the source code security information in the software architecture diagram according to the results of the automatic static code scanning; the branch code includes development branch code and trunk branch code.

[0072] Step S6: Merge the branch code that has completed automatic static code scanning to obtain the merged code.

[0073] Step S7: Automatically build, package, and store the merged code to obtain an artifact.

[0074] Step S8: Perform security information scanning on the artifact to obtain the artifact with completed security information scanning.

[0075] Step S9: Conduct acceptance testing and release on the artifact with completed security information scanning.

[0076] In an exemplary embodiment, a railway application software R & D process management system is provided. The above-mentioned railway application software R & D process management method is applied to this railway application software R & D process management system. As Figure 3 shown, this railway application software R & D process management system includes functional modules such as a project management module, a continuous integration and delivery module, a testing module, and an environment management module. Among them, the project management module, the continuous integration and delivery module, and the testing module are connected in sequence, and the environment management module is respectively connected to the project management module, the continuous integration and delivery module, and the testing module.

[0077] In this embodiment, the project management module is used to register the project information of the railway application software R & D project. The project information includes the project name, business party information, project investment information, and sub - project information.

[0078] In this embodiment, the continuous integration and delivery module is used to register the system information corresponding to the railway application software R & D project. The system information includes the system name and a brief introduction to the system function, and selects the corresponding project or sub - project for association through information synchronization with the project management module.

[0079] In this embodiment, the test module is used to provide test case management capabilities and test capabilities for UI testing, interface testing, and performance testing to support functional testing and acceptance testing, and generate test results. The test results will be synchronized to the project management module to form new work tasks for fixing defects in the software.

[0080] In this embodiment, the environment management module is used to provide and manage the resources required for the operation of containerized applications, and divide the resources into a test area, a pre-production area, and a production area, corresponding to the test environment, the pre-production environment, and the production environment respectively. The test area, the pre-production area, and the production area are isolated from each other. Among them, the test area refers to the environmental area where testers carry out functional testing; the pre-production area refers to the environmental area where acceptance testing is carried out by simulating the real production environment; the production area refers to the environmental area where the software is officially put into production and operation.

[0081] In the railway application software R & D process management system of this embodiment, the project management module mainly collects information from other functional modules such as the continuous integration and delivery module and the test module for the display of the project advancement development progress. The information system in the continuous integration and delivery module corresponds to the project in the project management module. The test results generated by the test module are registered in the project management module to urge R & D personnel to fix defects as soon as possible. The continuous integration and delivery module will deploy the software in the environment provided by the environment management module for testing, release, etc.

[0082] Based on the above railway application software R & D process management system, in step S1 of this embodiment, the business requirement information of the railway application software R & D project is obtained, which specifically includes the following steps.

[0083] Step S11: Use the project management module to enter the project information of the railway application software R & D project.

[0084] Step S12: According to the project information, determine the business requirement information of the railway application software R & D project.

[0085] Step S13: Conduct a preliminary review of the business requirement information. The preliminary review refers to reviewing and screening the business requirement information, returning the unreasonable requirements and the requirements that do not need to be satisfied in the business requirement information for modification, and taking the reasonable requirements and the requirements that need to be satisfied in the business requirement information as the business requirement information, and executing step S2 "Analyze, disassemble, and distribute the business requirement information to determine the R & D requirement information".

[0086] In this embodiment, step S2 analyzes, disassembles, and distributes the business requirement information to determine the R & D requirement information, which specifically includes the following steps.

[0087] Step S21: Analyze and break down the business requirement information using the project management module to generate the R & D requirement information.

[0088] Step S22: Enter the R & D requirement information into the sub - projects in the project management module, and at the same time enter the acceptance test cases in the test module.

[0089] In this embodiment, step S4 performs branch development on the R & D tasks to form multiple development tasks, and at the same time monitors the development progress of each development task in real - time, specifically including the following steps.

[0090] Step S41: According to the R & D tasks, use the continuous integration and delivery module to create development branches to form multiple development tasks.

[0091] Step S42: Use the continuous integration and delivery module to synchronize the development task information of all the development tasks and display the development task information in the form of a list.

[0092] Step S43: Associate the branch names of each development task and the development branches. After association, perform code pulling and development, and monitor the development progress of each development task in real - time.

[0093] In this embodiment, step S5 performs automatic static code scanning on the branch code corresponding to the development tasks that have been completed, and updates the source code security information in the software architecture diagram according to the automatic static code scanning results, specifically including the following steps.

[0094] Step S51: Use the continuous integration and delivery module to perform automatic static code scanning on the branch code corresponding to the development tasks that have been completed to obtain the automatic static code scanning results. The automatic static code scanning results include passing or failing the automatic static code scanning.

[0095] Step S52: According to the automatic static code scanning results, give an alarm for the branch code that fails the automatic static code scanning, and send the automatic static code scanning results to the project management module.

[0096] Step S53: According to the automatic static code scanning results, use the project management module to update the source code security information in the software architecture diagram.

[0097] In this embodiment, step S6 merges the branch code that has completed automatic static code scanning to obtain the merged code, specifically including the following steps.

[0098] Step S61: For the branch code that has completed automatic static code scanning, use the continuous integration and delivery module to initiate a branch merge request. The branch merge request refers to a request to merge the development branch code and the main branch code in the branch code that has completed automatic static code scanning.

[0099] Step S62: When the branch merge request is approved, use the continuous integration and delivery module to merge the development branch code and the main branch code in the branch code that has completed automatic static code scanning to obtain the merged code.

[0100] Step S63: When the branch merge request is not approved, reject the branch code that has completed automatic static code scanning for modification.

[0101] In this embodiment, step S7 automatically builds, packages, and stores the merged code to obtain an artifact, which specifically includes the following steps.

[0102] Step S71: Use the continuous integration and delivery module to automatically build and package the merged code, and at the same time analyze the dependencies referenced by the source code, generate software composition analysis SPDX document data, and synchronize the software composition analysis SPDX document data to the project management module.

[0103] Step S72: According to the software composition analysis SPDX document data, use the project management module to update all the dependency information of the components in the software architecture diagram. The dependency information includes the dependency package name, dependency package version number, dependency package source, and information on whether the dependency package is open source.

[0104] Step S73: Use the continuous integration and delivery module to store the packaged artifact in the artifact repository and generate the name and version number of the artifact.

[0105] In this embodiment, step S8 scans the security information of the artifact to obtain the artifact with the security information scanned, which specifically includes the following steps.

[0106] Step S81: Use the continuous integration and delivery module to scan the security information of the artifact, generate the security risk information of the artifact, and send the security risk information of the artifact to the project management module.

[0107] Step S82: According to the security risk information of the artifact, use the project management module to update the security risk information of the software architecture diagram and the artifact.

[0108] Step S83: Use the continuous integration and delivery module to perform a tagging operation on the artifacts that have passed the security information scan, generating tag information for the artifacts.

[0109] Step S84: Based on the tag information of the artifacts, perform a tag check on the artifacts, and use the continuous integration and delivery module to deploy the artifacts that pass the tag check.

[0110] In this embodiment, step S9 performs acceptance testing and release on the artifacts that have completed the security information scan, specifically including the following steps.

[0111] Step S91: Use the environment management module to deploy environment information, and at the same time use the continuous integration and delivery module to add and configure the environment information; the environment information includes a test environment, a pre-release environment, and a production environment.

[0112] Step S92: Based on the environment information, use the test module to provide UI testing, interface testing, and function testing for the artifacts that have completed the security information scan, generating test results; the test results include passing the acceptance test or failing the acceptance test.

[0113] Step S93: Synchronize the test results to the project management module, and form a new work task based on the artifacts that fail the acceptance test. The new work task is used to modify the defects of the software corresponding to the artifacts that fail the acceptance test.

[0114] Step S94: Based on the test results, use the continuous integration and delivery module to deploy the artifacts that pass the acceptance test in the production environment, and access the new version after the software update according to the URL published by the environment management module, realizing the closed-loop from business requirements to software release.

[0115] Based on the business requirement information, this embodiment completes the acceptance testing and release of the artifacts through operations such as automatic static code scanning and security information scanning, realizes the complete closed-loop from business requirements to software release, realizes the standardization and standardization of the R & D process of railway application software, can improve the efficiency and quality of software R & D, thereby obtaining a more ideal software development result, and further facilitating the recognition of the business side.

[0116] To make the technical solution of this embodiment clearer, the following takes the form of an example to detail the implementation steps and work processes of the railway application software R & D process management method based on the railway application software R & D process management system in this embodiment. As Figure 4 shown, it mainly includes the following content.

[0117] (1) Obtain the business requirement information of the railway application software R & D project.

[0118] Enter the project information of the railway application software R & D project in the project management module, determine the business requirement information, and conduct a preliminary review; according to the review results, system construction project establishment can be carried out. The review results are divided into two cases: 1) If the business requirements are unreasonable, return for modification; 2) If the business requirements are reasonable, distribute the business requirements.

[0119] In this embodiment, the preliminary review is carried out manually to preliminarily screen out unreasonable and unrequired business requirements. For example, some business requirements are too large and exceed the project boundary, so they are considered unreasonable; some business requirements already have corresponding functions in the software and can already meet the business requirements, so they are considered business requirements that do not need to be met again.

[0120] (2) Analyze, disassemble, and distribute the business requirement information to determine the R & D requirement information.

[0121] Analyze and disassemble the business requirement information in the project management module, generate the corresponding R & D requirement information and enter it into the sub-project in the project management module; at the same time, enter the acceptance test cases in the test module. Among them, the acceptance test cases are test cases written for user requirements to test whether the software has implemented the user's business requirement information.

[0122] (3) Conduct architecture design according to the R & D requirement information.

[0123] In this embodiment, the technical manager conducts architecture design according to the R & D requirement information, generates and updates the software architecture diagram in the project management module; registers the R & D tasks in the project management module and distributes the R & D tasks to the corresponding developers.

[0124] (4) Conduct branch development on the R & D tasks, and at the same time, monitor the development progress of each development task in real time. Create a development branch in the corresponding code repository in the continuous integration and delivery module to form multiple development tasks; the continuous integration and delivery module will synchronize the development task information of all development tasks and display it in a list; the branch name is associated with the development task, and then code pulling and development are carried out, and the development progress of each development task is monitored in real time.

[0125] (5) Automatically perform static code scanning and warning on the branch code corresponding to the completed development tasks.

[0126] Submit the branch code corresponding to the completed development tasks to the code repository, and conduct automatic static code scanning through the continuous integration and delivery module. The branch code with serious errors and those that fail the automatic static code scanning in the automatic static code scanning results will be warned through the page, and all automatic static code scanning results will be sent to the project management module to update the source code security information of the corresponding function modules in the system's software architecture diagram.

[0127] In this embodiment, in addition to warnings, threshold values can also be set in the pipeline. When the error level exceeds the range of the threshold values, the pipeline execution is stopped, that is, the continuous integration and delivery process ends. The user needs to fix the error first and then execute it again.

[0128] (6) Merge the branch code that has completed automatic static code scanning.

[0129] In the continuous integration and delivery module, a branch merge request is initiated. The branch code for which the branch merge request review fails will be returned to the developer for modification; after the branch code for which the branch merge request review passes is confirmed to be merged in the continuous integration and delivery module, the development branch code and the main branch code are merged to obtain the merged code.

[0130] (7) Automatically build, package the merged code, and store the artifacts.

[0131] The continuous integration and delivery module automatically builds and packages the merged code; while automatically building the code, the continuous integration and delivery module analyzes the dependencies referenced by the source code, generates a Software Composition Analysis (SPDX) document, and synchronizes the SPDX document to the project management module; after receiving the SPDX document, the project management module updates all the dependency information of the components in the software architecture diagram according to the software composition information in the SPDX document. The dependency information includes: dependency package name, dependency package version number, dependency package source, and whether the dependency package is open source, etc.; the packaged artifacts are stored by the continuous integration and delivery module in the internal artifact repository, and the name and version number of the artifacts are generated.

[0132] Among them, "dependency" refers to external libraries or components referenced in the source code, and these external libraries or components are necessary for building, packaging, and running the code. Specifically, dependencies can be third-party open source libraries, private libraries, or other modules, which are usually managed by package management tools. Among them, package management tools such as Maven, npm, pip, etc. This process involves analyzing all external dependencies referenced in the source code. The focus of the analysis is to determine the external libraries directly or indirectly depended on by the source code, and the metadata of each dependency, such as dependency package name, dependency package version number, dependency package source, and whether the dependency package is open source, etc.

[0133] (8) Scan the security information of the artifacts.

[0134] After receiving new artifacts through the continuous integration and delivery module, it automatically triggers the security information scanning of the artifacts and generates a scan result report, including the security risk information of the artifacts; this security risk information is sent to the project management module; after receiving this security risk information, the project management module updates the software architecture diagram and updates the security risk information of the artifacts corresponding to the components; the continuous integration and delivery module will perform a tagging operation on the artifacts that pass the security information scanning; during the tagging operation, the hash value of the artifacts is calculated through the internally managed private key, and this hash value is recorded in the continuous integration and delivery module; the continuous integration and delivery module deploys the artifacts in the artifact library, and before deployment, it will check the tag information of the artifacts, and only the artifacts that pass the tag check are allowed to be deployed.

[0135] (9) Conduct acceptance testing and release on the artifacts that have completed the security information scanning.

[0136] In the continuous integration and delivery module, the environment information deployed in the environment management module will be added and configured, including the test environment, pre-production environment, and production environment. After the environment information deployment is completed, the test module provides capabilities such as UI testing, interface testing, and functional testing, and generates test results; the test results will be synchronized to the project management module to form a new work task for modifying the defects in the software corresponding to the artifacts that fail the acceptance testing.

[0137] For the artifacts that pass the acceptance testing, the operation and maintenance personnel will deploy the artifacts that pass the acceptance testing in the production environment in the continuous integration and delivery module. At this time, the business personnel can access the new version of the software after the update through the URL published by the environment management module, realizing the closed-loop from business requirements to software release.

[0138] In actual application, the business party puts forward the business requirements corresponding to a certain railway application software R & D project. The project manager can enter the business requirement information of the railway application software R & D project in the project management module. At the same time, the project manager registers the project information of the railway application software R & D project in the project management module, including project name, business party information, project investment information, sub-project information, etc. If a large project consists of several sub-projects, the sub-project information needs to be registered under this project. The technical manager registers the system information corresponding to the project in the continuous integration and delivery module. The system information includes system name, brief introduction of system functions, etc., and associates the project or sub-project corresponding to the system through information synchronization in the project management module. The information management party conducts a preliminary review of the business requirement information in the project management module. Unreasonable business requirements are returned for modification, and reasonable business requirements are assigned to the project manager for processing. After receiving the business requirement information, the project manager conducts decomposition work, that is, the process of analysis and disassembly, to determine the subsystem requirements, enters the disassembled business requirements in the sub-project in the project management module, and assigns the business requirements to the technical person in charge of the corresponding system; the project manager also writes acceptance test cases and enters them into the test module. After receiving the R & D requirement information corresponding to the business requirements of this system, the technical manager conducts architecture design and manually updates the software architecture diagram of this system in the project management module to achieve architecture update. The technical manager registers R & D tasks in the project management module and assigns the R & D tasks to the corresponding developers, that is, assigns each sub-task of the R & D tasks to each developer. Each developer separately receives the sub-tasks assigned to themselves in the project management module and creates a development branch in the corresponding code repository in the continuous integration and delivery module; the continuous integration and delivery module synchronizes the development task information of all the development tasks of this developer and displays it in a list. When creating the development branch, the developer associates the branch name with the development task, and then performs code pulling and development.

[0139] When developers submit the branch code corresponding to the completed development tasks to the code repository, it will automatically trigger the automatic static code scanning of the continuous integration and delivery module. The branch code that fails the automatic static code scanning will be alerted via the page. All the automatic static code scanning results will be sent to the project management module to update the source code security information of the corresponding functional modules in the software architecture diagram. Developers will initiate a branch merge request in the continuous integration and delivery module, and the branch merge request will be sent to the technical leader. After receiving the branch merge request, the technical manager reviews the branch code; for the branch code that passes the review, the technical manager clicks "Allow Merge" in the continuous integration and delivery module, and then the development branch code and the main branch code are merged. The changes in the main branch code will automatically trigger the automatic code building and packaging process of the continuous integration and delivery module. While automatically building the code, the continuous integration and delivery module will analyze the dependencies referenced by the source code, generate a Software Composition Analysis SPDX document, and synchronize this Software Composition Analysis SPDX document to the project management module; after receiving the software composition information in the Software Composition Analysis SPDX document, the project management module updates all the dependency information of the components in the software architecture diagram, including: dependency package name, dependency package version number, dependency package source, and whether the dependency package is open source, etc.

[0140] The packaged products are stored in the internal product repository by the continuous integration and delivery module, and the name and version number of the products are generated. After receiving new products, the continuous integration and delivery module automatically triggers the security information scanning of the products and generates the security risk information of the products; this security risk information is sent to the project management module; after receiving this security risk information, the project management module updates the software architecture diagram and updates the security risk information of the products corresponding to the components. The continuous integration and delivery module will perform tagging operations on the products that pass the security information scanning. The tag refers to the license tag. The process of the tagging operation is to calculate the hash value of the product through the private key managed internally, and this hash value is recorded in the continuous integration and delivery module. The continuous integration and delivery module deploys the products in the product library. Before deployment, it will check the tag information of the products. Only the products that pass the tag check are allowed to be deployed, realizing the license tag for product deployment. The continuous integration and delivery module will synchronize the environment information deployed in the environment management module and deploy to the test environment, pre-production environment and production environment respectively according to user requirements. After the continuous integration and delivery module deploys the products in the test environment, the test module provides capabilities such as UI testing, interface testing and functional testing, and generates test results; this test result will be synchronized to the project management module to form a new work task for modifying the defects in the software. After the continuous integration and delivery module deploys the products in the pre-production environment, the test module provides capabilities such as acceptance testing and stress testing, and extracts test cases from the test cases to automatically carry out relevant tests. This test result will also be synchronized to the project management module and will also form a new work task for modifying the defects in the software. The continuous integration and delivery module will deploy the products that pass the acceptance testing in the production environment. At this time, business personnel can access the new version of the software after the update through the URL published by the environment management module, realizing the complete closed-loop from business requirements to software release.

[0141] This embodiment integrates the project management module, continuous integration and delivery module, test module and environment management module to form a complete R & D process management system, optimizing all aspects of railway software R & D, including project management, continuous integration and delivery, test management, environment management, etc., thus constituting a method for managing the R & D process of railway application software. This method has the following advantages.

[0142] (1) Standardize the development process: By uniformly managing information such as projects, business requirements, architecture design, and development tasks, strengthening security audits, standardizing the entire development process, reducing the phenomena of repeated development and inefficient collaboration, and effectively solving the current problems of lack of unified architecture management, weak collaborative development ability, lack of security audits, and the disconnection of development, testing, and release processes due to the lack of unified development and deployment management tools.

[0143] (2) Automated Build and Integration: Through the continuous integration and delivery module, the code is automatically built and packaged, improving the efficiency and quality of code delivery.

[0144] (3) Dependency Management and Security Compliance: Automatically analyze the dependencies in the code and generate a Software Composition Analysis (SCA) SPDX document to provide transparency of dependency information and ensure the legality, open-source nature, and version security of all dependent packages.

[0145] (4) Security Scanning and Risk Management: By automatically performing static code scanning and security information scanning on branch code and artifacts respectively, security risks are discovered and addressed in advance, improving security and solving the current problems of lack of review, security deficiencies in source code and artifacts, and lack of dependency compliance.

[0146] (5) Automated Testing and Defect Management: Through the integration of automated testing and acceptance testing, the correctness and stability of software functions are ensured, and defects can be discovered and fixed in a timely manner, effectively solving the current problems of lack of systematic test management, insufficient test cases, weak requirements during acceptance, and the development results not being recognized by the business.

[0147] (6) Complete Closed-loop from Business Requirements to Software Release: From the collection of business requirements to software release, the entire process is clearly recorded and managed to ensure that the tasks and deliverables at each stage can be tracked and verified, ultimately achieving a complete closed-loop, enabling each business requirement to be responded to in a timely manner and software artifacts to be released efficiently, effectively solving the current problems of non-standard business requirement management, untimely response to business requirements, and resulting in duplicate development.

[0148] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.

[0149] Specific examples are used in this article to elaborate on the principles and implementation methods of this application. The descriptions of the above embodiments are only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, based on the idea of this application, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A railway application software development process management method, characterized in that: The railway application software development process management method comprises: Obtain business demand information for railway application software R&D projects; Analyze, disassemble and distribute the business demand information to determine the R&D demand information; Performing architecture design according to the R&D demand information, determining R&D tasks, and generating a software architecture diagram; the software architecture diagram includes source code security information; Carry out branch development on the research and development task to form multiple development tasks, and monitor the development progress of each development task in real time; Automatically perform static code scanning on the branch code corresponding to the completed development task, and update the source code security information in the software architecture diagram according to the automatic static code scanning result; the branch code includes development branch code and trunk branch code; Merge the branch codes that have completed automatic static code scanning to obtain the merged code; Automatically construct, package and store the merged code to obtain a product; Scanning the product for security information to obtain a product that has completed the security information scanning; The products that have completed the security information scan are accepted and released.

2. The railway application software development process management method according to claim 1, characterized in that: The railway application software development process management method is applied to a railway application software development process management system, which includes a project management module, a continuous integration and delivery module, a test module and an environment management module, wherein the project management module, the continuous integration and delivery module and the test module are connected in sequence, and the environment management module is connected to the project management module, the continuous integration and delivery module and the test module respectively; The project management module is used to register the project information of the railway application software development project, wherein the project information includes the project name, business party information, project investment information and sub-project information; The continuous integration and delivery module is used to register the system information corresponding to the railway application software development project, the system information including the system name and system function introduction, and to associate the corresponding project or sub-project by synchronizing with the information of the project management module; The test module is used to provide test case management capabilities as well as UI testing, interface testing and performance testing capabilities to support functional testing and acceptance testing, and generate test results; The environment management module is used to provide and manage the resources required for the operation of the containerized application, and divide the resources into a test area, a pre-release area, and a production area. The test area, the pre-release area, and the production area are isolated from each other.

3. The railway application software development process management method according to claim 2 is characterized in that: Obtain business demand information for railway application software development projects, including: Entering the project information of the railway application software development project using the project management module; Determine the business requirement information of the railway application software development project based on the project information; Conduct a preliminary review of the business demand information. The preliminary review refers to reviewing and screening the business demand information, returning unreasonable demands and demands that do not need to be met in the business demand information for modification, and taking reasonable demands and demands that need to be met in the business demand information as the business demand information, and executing the step of "analyzing, disassembling and distributing the business demand information to determine the R&D demand information".

4. The railway application software development process management method according to claim 3 is characterized in that: Analyze, disassemble and distribute the business demand information to determine the R&D demand information, including: Analyze and decompose the business demand information using the project management module to generate the R&D demand information; The R&D requirement information is entered into the sub-project in the project management module, and acceptance test cases are entered into the test module.

5. The railway application software development process management method according to claim 4 is characterized in that: The R&D task is branched and developed to form multiple development tasks, and the development progress of each development task is monitored in real time, including: According to the R&D tasks, the continuous integration and delivery module is used to create development branches to form multiple development tasks; Synchronize the development task information of all the development tasks using the continuous integration and delivery module, and display the development task information in a list format; Each of the development tasks is associated with the branch name of the development branch, and after the association, code is pulled and developed, and the development progress of each development task is monitored in real time.

6. The railway application software development process management method according to claim 5 is characterized in that: Automatically performing static code scanning on the branch code corresponding to the completed development task, and updating the source code security information in the software architecture diagram according to the automatic static code scanning result, specifically including: Using the continuous integration and delivery module to perform automatic static code scanning on the branch code corresponding to the completed development task to obtain an automatic static code scanning result; the automatic static code scanning result includes passing the automatic static code scanning or failing the automatic static code scanning; According to the automatic static code scanning result, an alarm is issued for the branch code that fails the automatic static code scanning, and the automatic static code scanning result is sent to the project management module; According to the automatic static code scanning result, the project management module is used to update the source code security information in the software architecture diagram.

7. The railway application software development process management method according to claim 6 is characterized in that: Merge the branch codes that have completed automatic static code scanning to obtain the merged code, including: For the branch code that has completed the automatic static code scanning, using the continuous integration and delivery module to raise a branch merge request, wherein the branch merge request refers to a request to merge the development branch code and the trunk branch code in the branch code that has completed the automatic static code scanning; When the branch merge request is approved, the development branch code and the trunk branch code in the branch code that has completed the automatic static code scanning are merged by using the continuous integration and delivery module to obtain the merged code; When the branch merge request fails the review, the branch code that has completed the automatic static code scanning is rolled back and modified.

8. The railway application software development process management method according to claim 7 is characterized in that: Automatically construct, package and store the merged code to obtain a product, specifically including: Utilize the continuous integration and delivery module to automatically build and package the merged code, analyze the dependencies of the source code references, generate software composition analysis SPDX document data, and synchronize the software composition analysis SPDX document data to the project management module; Analyze the SPDX document data according to the software composition, and use the project management module to update all dependency information of the components in the software architecture diagram, wherein the dependency information includes the name of the dependency package, the version number of the dependency package, the source of the dependency package, and whether the dependency package is open source; The continuous integration and delivery module is used to store the packaged artifacts in the artifact warehouse, and to generate the name and version number of the artifacts.

9. The railway application software development process management method according to claim 8, characterized in that: Scanning the product for security information to obtain a product that has completed the security information scanning specifically includes: Using the continuous integration and delivery module to scan the product for security information, generate security risk information of the product, and send the security risk information of the product to the project management module; According to the security risk information of the product, using the project management module to update the software architecture diagram and the security risk information of the product; Using the continuous integration and delivery module to perform a labeling operation on the product that has passed the security information scan, to generate label information of the product; According to the label information of the artifact, the artifact is subjected to label check, and the artifact that passes the label check is deployed using the continuous integration and delivery module.

10. The railway application software development process management method according to claim 9, characterized in that: Acceptance testing and release of the products that have completed the security information scan include: Deploy environmental information using the environmental management module, and add and configure the environmental information using the continuous integration and delivery module; the environmental information includes a test environment, a pre-release environment, and a production environment; Based on the environmental information, using the test module to provide UI testing, interface testing and functional testing for the product that has completed the security information scan, and generate test results; the test results include passing the acceptance test or failing the acceptance test; The test results are synchronized to the project management module, and new work tasks are formed according to the products that have not passed the acceptance test; the new work tasks are used to modify the defects of the software corresponding to the products that have not passed the acceptance test; According to the test results, the continuous integration and delivery module is used to deploy the products that pass the acceptance test in the production environment, and the new version after the software update is accessed according to the URL published by the environment management module, thereby realizing a closed loop from business needs to software release.

Citation Information

Patent Citations

  • An automatic software system quality inspection and rapid iteration method

    CN109684215A

  • Code template management method and system

    CN114416117A

  • Code warehouse management method and device, electronic equipment and storage medium

    CN115904933A

  • Software research and development project management method, equipment and medium

    CN117193794A

  • Application development method and device

    CN119065637A