Code scanning method, electronic equipment and computer program product
By determining the code selection range on the client, obtaining and processing the change types of the target code file, efficient code scanning is achieved, and resource consumption and false positive problems in traditional full scanning methods are solved, improving the efficiency and accuracy of code scanning.
Patent Information
- Application Number
- CN202510191404.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-27
AI Technical Summary
Traditional code scanning methods adopt full-scale scanning, which causes a large amount of computing resources and time to consume in large-scale code bases, and may generate false positives for unchanged code, increasing the workload of developers to troubleshoot problems.
A code scanning method is provided, by receiving a code selection instruction input by a user, determining a code selection range in the client, obtaining at least one object code file from a plurality of code files within the code selection range, determining its file change type, and processing the object code file based on the file change type to obtain the change code content for scanning.
This method can reduce the number of code files that determine the type of file change, improve the efficiency of code scanning, avoid scanning of unchanged codes, reduce the risk of false alarms, and thus reduce the workload of developers to troubleshoot problems.
Smart Images

Figure CN120045439A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a code scanning method, electronic equipment, and computer program product. Background Art
[0002] Frequent code updates and changes are inevitable during software development. As the codebase continues to grow, development teams need to continuously perform quality checks, security scans, and performance optimizations to ensure code reliability and security. Traditional code scanning methods typically employ a full scan approach, which involves comprehensive analysis and testing of the entire codebase.
[0003] Full scans consume a lot of computing resources and time, especially when the code base is large or the number of code files is large. Scanning efficiency is significantly reduced, and full scans may produce false positives for unchanged code, increasing the workload of developers in troubleshooting. Summary of the Invention
[0004] In view of the problems existing in the prior art, the present invention provides a code scanning method, an electronic device, and a computer program product.
[0005] The present invention provides a code scanning method, applied to a client, comprising: receiving a code selection instruction input by a user, and determining a code selection range in the client based on the code selection instruction; Acquire at least one target code file from a plurality of code files within the code selection range, wherein the target code file is a code file including a changed code; determining a file change type of at least one of the target code files; At least one of the target code files is processed based on the file change type to obtain changed code content, and the changed code content is scanned.
[0006] According to a code scanning method provided by the present invention, the file change type includes a newly added code file; Processing at least one of the target code files based on the file change type to obtain the changed code content specifically includes: When it is determined that the file change type of the target code file is a newly added code file, the changed code content is obtained based on the complete target code file.
[0007] According to a code scanning method provided by the present invention, the file change type includes changing a code file; Processing at least one of the target code files based on the file change type to obtain the changed code content specifically includes: When determining that the file change type of the target code file is a changed code file, obtaining the code file before the change; Comparing the pre-modified code file with the target code file to obtain a modified code; A change code content is obtained based on the change code.
[0008] According to a code scanning method provided by the present invention, comparing the pre-modified code file with the target code file to obtain the modified code specifically includes: Parsing the pre-modified code file and the target code file according to the first naming keyword to obtain a first subroutine name of the pre-modified code file and a second subroutine name of the target code file; The first subprogram name and the second subprogram name are processed respectively by a preset content acquisition method to obtain a first subprogram content corresponding to the first subprogram name and a second subprogram content corresponding to the second subprogram name. Determine the first subroutine name corresponding to the second subroutine name, compare the first subroutine content corresponding to the first subroutine name with the second subroutine content corresponding to the second subroutine name, and obtain a change code.
[0009] According to a code scanning method provided by the present invention, obtaining the changed code content based on the changed code specifically includes: At least one subprogram to which the change code belongs is determined, and content of the change code is obtained based on the complete subprogram.
[0010] According to a code scanning method provided by the present invention, scanning the changed code content specifically includes: A code scanning request is created based on the changed code content, and the changed code content and the code scanning request are sent to a server to receive a large model code scanning result returned by the server.
[0011] According to a code scanning method provided by the present invention, after sending the changed code content and the code scanning request to the server, the method further includes: Receive the task identifier and local code scanning instruction returned by the server; Polling the server for a large model code scanning result based on the task identifier, and performing a static code scan on the changed code content based on the local code scanning instruction; After determining that the large model code scanning result and the static code scanning result are obtained, the code scanning is stopped.
[0012] According to a code scanning method provided by the present invention, determining a file change type of at least one target code file specifically includes: A file change identifier of at least one of the target code files is obtained, and a file change type of the target code file is determined based on the file change identifier.
[0013] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements any of the above-described code scanning methods when executing the computer program.
[0014] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements any of the above code scanning methods.
[0015] Compared with full scanning, the code scanning method, electronic device, and computer program product provided by the present invention determine the code selection range in the client by receiving the code selection instruction input by the user, obtain at least one target code file from multiple code files within the code selection range, and determine the file change type of at least one target code file, which can reduce the number of code files for determining the file change type, thereby improving the efficiency of code scanning; based on the file change type, at least one target code file is processed to obtain the changed code content, and the changed code content is scanned, which can avoid scanning the unchanged code, reduce the risk of false alarms for the unchanged code, and thus reduce the workload of developers in troubleshooting problems. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0017] Figure 1 This is one of the flow charts of the code scanning method provided by the present invention.
[0018] Figure 2 This is one of the partial code schematic diagrams of the code scanning method provided by the present invention.
[0019] Figure 3 This is the second partial code schematic diagram of the code scanning method provided by the present invention.
[0020] Figure 4 This is the second flow chart of the code scanning method provided by the present invention.
[0021] Figure 5 It is a structural diagram of the code scanning device provided by the present invention.
[0022] Figure 6 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION
[0023] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0024] The following combination Figures 1-6 The code scanning method, electronic device and computer program product of the present invention are described.
[0025] Figure 1 This is one of the flow charts of the code scanning method provided by the present invention, which is applied to the client, such as Figure 1 As shown, the method includes: Step 101: Receive a code selection instruction input by a user, and determine a code selection range in the client based on the code selection instruction.
[0026] The code scanning method provided by the present invention can be applied to a code scanning plug-in in an integrated development environment. A code selection instruction refers to an instruction by which a user specifies a code range in the client through an interactive method provided by the client. For example, the client may have a built-in WebView for user interaction with the client, and the user can enter a code selection instruction in the WebView to specify a code range in the client.
[0027] WebView is a WebKit-based browser available in the Software Development Kit. It doesn't provide an address bar or navigation bar, displaying only a single web page. This prevents distractions from the address bar and navigation bar, allowing users to focus more on the web content and improve the user experience.
[0028] It should be noted that the range selection sub-command includes at least the current modification and the current file, wherein the code selection range corresponding to the current modification can be all code files in the current project that include changed code.
[0029] Step 102: Obtain at least one target code file from a plurality of code files within the code selection range, wherein the target code file is a code file including a changed code.
[0030] Changed code refers to the code that is added, deleted, or modified in the code file.
[0031] Exemplarily, the code scanning scope can be sent to a preset interface to obtain at least one target code file provided by the preset interface. For example, the client's integrated development environment may include multiple IDE instances, such as IDE 1, IDE 2, and IDE 3. If the code selection scope is the current modification in IDE 1, the relevant input parameters of the preset interface can be obtained based on IDE 1 to obtain the target code file in the IDE 1 project.
[0032] Step 103: Determine a file change type of at least one of the target code files.
[0033] The file change type refers to the specific type of modification operation on the target code file, which can describe the changes that occur to the code file during version control or development.
[0034] In one embodiment, determining the file change type of at least one of the target code files specifically includes: obtaining a file change identifier of at least one of the target code files, and determining the file change type of the target code file based on the file change identifier.
[0035] A file change identifier refers to an identifier used to indicate file change information. For example, a file change identifier can indicate metadata about the file change type. Exemplarily, the variable "changeType" can be set to the file change identifier, and the file change type can be set to the value of the file change identifier variable, such as ADDED, indicating that the target code file is a newly added code file, and MODIFIED, indicating that the target code file is a modified code file. This makes it easy to quickly and accurately determine the file change identifier variable and its value by traversing the name of the file change identifier variable in the target code file when determining the file change type of the target code file, so as to determine the file change type of the target code file.
[0036] Step 104: Process at least one of the target code files based on the file change type to obtain changed code content, and scan the changed code content.
[0037] The content of the change code may be the change code itself. In this embodiment, target code files of different file change types may be processed using different preset processing methods to obtain the file change type corresponding to each target code file. There is a corresponding relationship between the preset processing method and the file change type. For example, a mapping relationship may be established between the preset processing method and the file change type.
[0038] For example, after obtaining three target code files from multiple code files within the code selection range, the file change type of each target code file can be determined separately, and the target code files can be processed based on the preset processing method corresponding to the file change type to obtain the changed code content of each target code file.
[0039] Compared with full scanning, the code scanning method provided by the embodiment of the present invention determines the code selection range in the client by receiving the code selection instruction input by the user, obtains at least one target code file from multiple code files within the code selection range, and determines the file change type of at least one target code file, which can reduce the number of code files for determining the file change type, thereby improving the efficiency of code scanning; based on the file change type, at least one target code file is processed to obtain the changed code content, and the changed code content is scanned, which can avoid scanning the unchanged code, reduce the risk of false alarms for the unchanged code, and thus reduce the workload of developers in troubleshooting problems.
[0040] Based on the above embodiment, the file change type includes adding a new code file; Processing at least one of the target code files based on the file change type to obtain the changed code content specifically includes: When it is determined that the file change type of the target code file is a newly added code file, the changed code content is obtained based on the complete target code file.
[0041] Newly added code files are code files that did not exist in the previous version of the project but are present in the current version. You can use a distributed version control system to track changes in code files by adding a file change type. For example, using Git, you can add a git change status to a code file and use the file's git change status of ADDED to identify a newly added code file.
[0042] Based on any of the above embodiments, the file change type includes changing a code file; Processing at least one of the target code files based on the file change type to obtain the changed code content specifically includes: When determining that the file change type of the target code file is a changed code file, obtaining the code file before the change; Comparing the pre-modified code file with the target code file to obtain a modified code; A change code content is obtained based on the change code.
[0043] A modified code file refers to a code file whose code content differs from the previous version of the project code. For example, if you use Git to add a git change status to a code file, you can identify it as a modified code file by its git change status of MODIFIED. The pre-modified code file refers to the code file in the previous version of the project code that corresponds to the target code file.
[0044] For example, the changed code can be obtained by comparing the code file before the change and the target code file to determine the difference between the codes by checking whether the character strings are equal.
[0045] In this embodiment, for the newly added code file, the changed code content is directly generated based on the complete target code file, which can improve the processing efficiency and ensure the integrity and accuracy of the newly added code; for the changed code file, the specific changed code content is accurately extracted by comparing the files before and after the change, and the changed code is processed in a targeted manner. By differentially processing the newly added code file and the changed code file, the overall efficiency and accuracy of code scanning can be improved.
[0046] Based on any of the above embodiments, comparing the pre-modified code file with the target code file to obtain the modified code specifically includes: Parsing the pre-modified code file and the target code file according to the first naming keyword to obtain a first subroutine name of the pre-modified code file and a second subroutine name of the target code file; The first subprogram name and the second subprogram name are processed respectively by a preset content acquisition method to obtain a first subprogram content corresponding to the first subprogram name and a second subprogram content corresponding to the second subprogram name. Determine the first subroutine name corresponding to the second subroutine name, compare the first subroutine content corresponding to the first subroutine name with the second subroutine content corresponding to the second subroutine name, and obtain a change code.
[0047] A subroutine is an independent, reusable block of code that performs a specific task, such as a method body in Java, a function or method in Python, etc.
[0048] In one embodiment, obtaining the changed code content based on the changed code specifically includes: determining at least one subroutine to which the changed code belongs, and obtaining the changed code content based on the complete subroutine.
[0049] A complete subroutine includes the code content of the changed code and the changed code context information. The code content of the changed code context information is the code content of the complete subroutine excluding the changed code. For example, the changed code context information may include code logic surrounding the changed code, function call relationships, and variable definitions.
[0050] In this embodiment, the changed code content is obtained through a complete subroutine, which can provide changed code context information, helping to more comprehensively understand the actual impact of code changes, especially in large model code scanning, and can reduce problems such as false positives and missed negatives in large model code scanning.
[0051] Taking a Java code file as an example, a pre-modified code file can be read and parsed using a preset Java library to generate an abstract syntax tree for the pre-modified code file. The abstract syntax tree for the pre-modified code file can then be traversed using the first naming keyword to obtain the name of the first subroutine in the pre-modified code file. The method for obtaining the name of the second subroutine in the target code file is essentially the same as the method for obtaining the name of the first subroutine in the pre-modified code file and will not be further described here.
[0052] Afterwards, the first subprogram can be determined according to the first subprogram name by a preset method to obtain the first subprogram content. The second subprogram can be determined according to the second subprogram name by a preset method to obtain the second subprogram content.
[0053] Finally, by traversing the second subroutine name, it can be determined that the same subroutine name in the code file before the change is the corresponding first subroutine name, and the first subroutine content corresponding to the first subroutine name and the second subroutine content corresponding to the second subroutine name are compared. If the first subroutine content and the second subroutine content are inconsistent, the second subroutine is determined to be the changed code content.
[0054] In this embodiment, the first subroutine name of the code file before the change and the second subroutine name of the target code file are used to determine the correspondence between the second subroutine of the target code file and the first subroutine of the code file before the change. By comparing the content of the first subroutine and the content of the second subroutine with the corresponding relationship, it is determined whether the second subroutine of the target code file includes the change code, thereby reducing the risk of false positive of the change code.
[0055] To further reduce the risk of false positives of changed code, based on any of the above embodiments, comparing the pre-changed code file and the target code file to obtain the changed code further includes: parsing the pre-changed code file and the target code file according to the second naming keyword to obtain the first variable name of the pre-changed code file and the first variable name of the target code file; The first variable name and the second variable name are processed respectively by the preset content acquisition method to obtain the first variable content corresponding to the first variable name and the second variable content corresponding to the second variable name. Determine the first variable name corresponding to the second variable name, compare the first variable content corresponding to the first variable name with the second variable content corresponding to the second variable name, and obtain a change code.
[0056] The working principle and technical effect of obtaining the change code based on variable related information are basically the same as the working principle and technical effect of obtaining the change code based on subroutine related information, and will not be repeated here.
[0057] In a specific example, the code file before the change can be as follows Figure 2 As shown, it can be parsed into a syntax tree file1. The target code file can be Figure 3 As shown, it can be parsed into a syntax tree file2. File1 can be parsed according to the class to obtain the first method body name and the first variable name, and file2 can be parsed according to the class to obtain the second method body name and the second variable name.
[0058] For example, getValue() in file1 can be obtained through getMethods in the Application Programming Interface (API), and isCopilot in file1 can be obtained through getFields in the API. getValue() in file2 can be obtained through getMethods in the API, and isCopilot in file1 can be obtained through getFields in the API.
[0059] Traverse the getMehods in file2, obtain the getValue() method body in file1 according to its method name getValue(), and compare the getValue() method body in file1 and the getValue() method body in file2 based on whether the strings are equal. If they are not equal, the getValue() method body in file2 is determined as the changed code content.
[0060] In an example, the code implementation for obtaining the changed code is as follows: { "fileList": [{ "changeType": "ADDED", "content": [{ "code": "package com.ke.efficiency.gpt.service;\n\nimportorg.redisson.Redisson;\nimport org.redisson.api.RLock;\nimportorg.redisson.api.RedissonClient;\nimport org.redisson.config.Config;\n\npublic class RedissonExample {\n public static void main(String[] args) {\n / / Configure Redisson\n Config config = new Config();\nconfig.useSingleServer().setAddress(\"redis: / / 127.0.0.1:6379\");\n\n / / Create Redisson client\n RedissonClient redisson = Redisson.create(config);\n\n / / Obtain distributed lock\n RLock lock = redisson.getLock(\"myLock\");\n\n try {\n / / Try to acquire the lock\n lock.lock();\n / / Execute business logic\n System.out.println(\"Execute business logic\");\n} finally {\n / / Release the lock\n lock.unlock();\n}\n\n / / Close the Redisson client\n redisson.shutdown();\n}\n}\n", "startLine": 1 }], "path": " / gpt-api-service / src / main / java / com / ke / efficiency / gpt / service / RedissonExample.java" }, { "changeType": "MODIFIED", "content": [{ "code": "public int getValue() {\n\t\tInteger value = 2;\n\t\treturnvalue;\n\t}", "startLine": 30 }, { "code": "@PostMapping(value = \" / deleteUser\")\n\tpublic Message <copilottoolbo>deleteUser(CopilotUserOperateRequest copilotUserOperateRequest){\n\t\tThread thread = new Thread();\n\t\tthread.run();\n\t\treturnMessage.ok(gitHubService.batchDeleteInvitation(copilotUserOperateRequest));\n\t}", "startLine": 38 }, { "code": "public void example(String str1, String str2) {\n\t\tlongcurrentTimeMillis = System.currentTimeMillis();\n\t\tif (str2 == str1) {\n\t\t\tSystem.out.println(\"Strings are equal\");\n\t\t}\n\t}", "startLine": 44 }], "path": " / gpt-api-start / src / main / java / com / ke / efficiency / gpt / controller / ToolController.java" }], "type": "changedFile" } Among them, fileList represents the target code file, code represents the changed code, startLine represents the starting line number, and type is changedFile, which means that the code file includes the changed code.
[0061] In one embodiment, after obtaining at least one target code file, the method further comprises: adding a variable content variable; Get the changed code content, including: In the case where the file change type is a newly added code file, assigning the changed content variable based on the complete target code file to obtain the changed code content; In the case where the file change type is a changed code file, the changed content variable is assigned a value based on the subroutine to which the changed code belongs to obtain the changed code content.
[0062] In this embodiment, a variable of changed content is introduced, and the variable of changed content is dynamically assigned according to the file change type. In the case of a new code file, the assignment is based on the complete target code file, which can ensure the complete capture of the new content; in the case of a changed code file, the assignment of changes based on the subroutine level focuses on the actual modified part, provides contextual information, and reduces the interference of redundant information. It can efficiently extract and accurately manage the code change content, and reduce the consumption of computing resources.
[0063] In addition, compared to full scanning, obtaining the changed code content based on the change assignment at the subroutine level and performing large-model code scanning on the changed code content can save a lot of tokens and reduce the cost of using large-model code scanning.
[0064] With the rapid development of artificial intelligence tools, more and more intelligent coding plug-ins are appearing in integrated development environments. As the functionality of intelligent coding plug-ins continues to evolve, AI (Artificial Intelligence) code scanning, or large-scale code scanning, is gradually coming into the spotlight. AI code scanning refers to code scanning using large-scale models. Compared to traditional static rule-based code scanning, AI code scanning provides more comprehensive results and can provide recommendations for issues such as non-compliant coding standards and security risks. However, AI code scanning plug-ins currently available on the market can only query the large-scale model based on selected code to optimize that portion of the selected code. The question of how to perform AI code scanning on multiple files in a project that include modified code is a critical issue that the industry urgently needs to address.
[0065] To address this technical problem, based on any of the above embodiments, the changed code content is scanned, specifically including: creating a code scanning request based on the changed code content, sending the changed code content and the code scanning request to the server, to receive the large model code scanning result returned by the server.
[0066] A code scanning request is a request sent by the client to the server based on the changed code content, triggering the server to perform a big model code scan of the changed code content. For example, the code scanning request can be an HTTP request. The code scanning request can include a command to perform code analysis, information about the changed code in the changed code content, and the code path, so that the big model can determine the changed code and its context.
[0067] Static code scanning typically relies on predefined rules and patterns to detect issues in the code. These rules and patterns often fail to cover all possible security risks and code defects, leading to missed detections and false positives. Compared to static code scanning, this embodiment uses a large model to scan code by sending modified code content and code scanning requests to the server. This model can accumulate programming knowledge from massive amounts of code data, expanding the scope of security risks and code defects it covers. It also uses code execution simulation and other methods to discover dynamic security issues at runtime.
[0068] Moreover, in this embodiment, by providing contextual information of the changed code in the changed code content, the large model can understand the characteristics of the code semantics and contextual relationships, and can avoid risks such as missed detection and false alarms, and provide corresponding suggestions for scanned problems.
[0069] In one embodiment, a code selection command is used to determine a code selection scope. After identifying the code files to be scanned, a target macromodel can be selected from multiple macromodels to perform AI code scanning on the code files. The code selection command may include a model selection sub-command, a function selection sub-command, and a scope selection sub-command. For example, the code selection command may be "@super code scan current modification."
[0070] Specifically, when the user enters the model selection sub-command, a first selection list will pop up after entering @. This list displays the available large models. The user can select the corresponding large model by clicking the model name in the first selection list, or enter the model name to select the corresponding large model. The method for entering the function selection sub-command and range selection sub-command is basically the same as the method for entering the model selection sub-command, so it will not be repeated here.
[0071] In this embodiment, the code scanning range is directly selected through instructions, and the subsequent changes in code content are automatically determined and uploaded to the server for large model code scanning, which improves the convenience of code scanning and can enhance user experience.
[0072] Based on this, compared to performing large model code scanning locally, this embodiment performs large model code scanning on the server, which can reduce the computing resource requirements for large model code scanning on the local computing resources. At the same time, multiple large models can be deployed on the server. After changing the code content and code scanning request, the server can call the corresponding large model dialogue interface to perform large model code scanning.
[0073] Based on any of the above embodiments, after sending the changed code content and the code scanning request to the server, the method further includes: Receive the task identifier and local code scanning instruction returned by the server; Polling the server for a large model code scanning result based on the task identifier, and performing a static code scan on the changed code content based on the local code scanning instruction; After determining that the large model code scanning result and the static code scanning result are obtained, the code scanning is stopped.
[0074] The task identifier refers to a unique identifier assigned by the execution entity when creating a task, such as a task ID or taskId. The task identifier returned by the server can be the first task ID generated by the server when creating the large model code analysis task.
[0075] A local code scanning instruction is an instruction returned by the server to the client based on the changed code content, triggering the client to perform a static code scan on the changed code content. For example, the local code scanning instruction may include a second task ID generated by the server when notifying the client to perform a static code scan on the changed code content. This allows the server to poll for instructions returned by the server based on the second task ID and promptly obtain the latest local code scanning instruction returned by the server.
[0076] For example, at least part of the code scanning request may be the following code: { "command": ["@super", " / codeScanning"], / / indicates code analysis "data": { "fileList": [{ "content": { "code": "testContent", / / Changed code "startLine": 12 / / The starting line of code }, "path": " / gpt / controller / WelcomeController.java" / / Code path }], "type": "changedFile" / / indicates code push or commit } } At least part of the task identifier returned by the server may be: { "taskId": "123" } The server returns at least part of the local code scan instruction, which can be the following code: { "path":[" / gpt-api-start / src / main / java / com / ke / efficiency / gpt / controller / ToolController.java"], / / Path to scan "taskId": "1044689365789446144", / / Task ID "command": "acceptLocalScan" / / Command type } The static code scanning rules can be obtained locally or from the server. For example, the code scanning method can be applied to the AI code scanning plug-in in the IDE, and when the AI code scanning plug-in is started, the static code scanning rules can be automatically obtained from the cloud.
[0077] In this embodiment, a large-model code scan is performed on the changed code content on the server side, and a static code scan is performed on the changed code content locally. Potential security risks based on machine learning, new code improvement directions, and clear grammar and known security issues based on scanning rules can be displayed to the user at the same time, thereby improving the accuracy of problems discovered by code scanning in a complementary manner.
[0078] In one embodiment, after obtaining the static code scanning results on the client, the static code scanning results can be uploaded to the server so that the static scanning results and the large model code scanning results can be further analyzed and processed across platforms on the server, and the final code scanning results can be returned to the client, thereby reducing the false positive rate of problems found in the code scanning and improving the analysis efficiency of the code scanning results.
[0079] For example, the static code scanning result may be uploaded via an HTTP message, and at least part of the content of the HTTP message may be the following code: [{ "issues": [ { "message": "Replace this use of System.out or System.err by alogger.", / / bug title "ruleDesc": "rule", / / rule description "ruleKey": "java:S106", / / unique identifier of the rule "severity": "MAJOR", / / bug severity "startColumn": 3, / / Code problem column "startLine": 51, / / Code problem line "type": "CODE_SMELL", / / Question type "uid": 4, / / Display sort ID }], "path": " / gpt-api-start / src / main / java / com / ke / efficiency / gpt / controller / ToolController.java" }] Figure 4 This is the second flow chart of the code scanning method provided by the present invention. In order to specifically illustrate the function of the code scanning method provided by this embodiment, as shown in FIG. Figure 4 As shown, a specific example is provided below.
[0080] The client is set up with an IDE environment, and a code scanning plug-in is installed in the IDE environment. The code scanning plug-in includes a plug-in core, a side webview, and a bottom webview. The display area of the bottom webview is larger than the display area of the side webview. Among them, the plug-in core can be used to monitor the user's code submission action in the IDE, and communicate with the side webview and the bottom webview respectively. A code scanning method is applied to a client code scanning plug-in.
[0081] The user can input a code selection instruction through the side webview to create a scanning task, so that the plug-in core obtains at least one target code file from multiple code files within the code selection range, and the target code file is a code file including the changed code; Determine a file change type of at least one of the target code files; the file change type includes a newly added code file and a changed code file, When determining that the file change type of the target code file is a newly added code file, obtaining the changed code content based on the complete target code file; When determining that the file change type of the target code file is a changed code file, obtaining the code file before the change; parsing the pre-change code file and the target code file according to the first naming keyword to obtain a first subroutine name of the pre-change code file and a second subroutine name of the target code file; processing the first subroutine name and the second subroutine name respectively by a preset content acquisition method to obtain a first subroutine content corresponding to the first subroutine name and a second subroutine content corresponding to the second subroutine name, determining the first subroutine name corresponding to the second subroutine name, and comparing the first subroutine content corresponding to the first subroutine name with the second subroutine content corresponding to the second subroutine name; Parsing the pre-change code file and the target code file according to the second naming keyword to obtain a first variable name of the pre-change code file and a first variable name of the target code file; processing the first variable name and the second variable name by the preset content acquisition method to obtain a first variable content corresponding to the first variable name and a second variable content corresponding to the second variable name, determining the first variable name corresponding to the second variable name, comparing the first variable content corresponding to the first variable name and the second variable content corresponding to the second variable name to obtain a change code, determining at least one subroutine to which the change code belongs, and obtaining the change code content based on the complete subroutine; Create a code scanning request based on the changed code content, send the changed code content and the code scanning request to the server, create a scanning task, receive the task ID and local code scanning instruction returned by the server through the side webview; and transparently transmit the task ID to the plug-in kernel; The bottom webview polls the server for the large model code scanning result based on the task ID, and the plug-in kernel performs static code scanning on the changed code content based on the local code scanning instruction; after determining that the large model code scanning result and the static code scanning result are obtained, the code scanning is stopped, and after obtaining the static code scanning result on the client, the static code scanning result is sent to the server for upload.
[0082] It is understood that the large model code scanning results and the static code scanning results can be displayed in the bottom webview with a larger display area, enhancing the user experience by making it easier for users to view. For example, a list of questions can be displayed to the user on the left side of the bottom webview, and detailed information of the selected question in the question list can be displayed on the right side.
[0083] The side webview and bottom webview both request data from the server through polling, and the unique identifier of each poll is the task ID. Communication between the side webview and the plugin core can be achieved through jsbridge.
[0084] The code scanning device provided by the present invention is described below. The code scanning device described below and the code scanning method described above can be referenced to each other.
[0085] Figure 5 The following is a schematic diagram of the structure of a code scanning device, which is applied to the client, such as Figure 5 As shown, the device includes: A code selection module 501 is configured to receive a code selection instruction input by a user and determine a code selection range in the client based on the code selection instruction; A file acquisition module 502 is configured to acquire at least one target code file from a plurality of code files within the code selection range, wherein the target code file is a code file including a changed code; A type determination module 503 is configured to determine a file change type of at least one of the target code files; The code scanning module 504 is configured to process at least one of the target code files based on the file change type to obtain changed code content, and scan the changed code content.
[0086] Based on any of the above embodiments, the file change type includes adding a new code file; The type determination module 503 is specifically configured to: when determining that the file change type of the target code file is a newly added code file, obtain the changed code content based on the complete target code file.
[0087] Based on any of the above embodiments, the file change type includes changing a code file; The type determination module 503 further includes: a pre-change code file acquiring unit, configured to acquire the pre-change code file when determining that the file change type of the target code file is a changed code file; a changed code determining unit, configured to compare the pre-changed code file with the target code file to obtain a changed code; The change code content determining unit is configured to obtain the change code content based on the change code.
[0088] Based on any of the above embodiments, the change code determination unit is specifically configured to: Parsing the pre-modified code file and the target code file according to the first naming keyword to obtain a first subroutine name of the pre-modified code file and a second subroutine name of the target code file; The first subprogram name and the second subprogram name are processed respectively by a preset content acquisition method to obtain a first subprogram content corresponding to the first subprogram name and a second subprogram content corresponding to the second subprogram name. Determine the first subroutine name corresponding to the second subroutine name, compare the first subroutine content corresponding to the first subroutine name with the second subroutine content corresponding to the second subroutine name, and obtain a change code.
[0089] Based on any of the above embodiments, the change code content determining unit is specifically configured to: determine at least one subprogram to which the change code belongs, and obtain the change code content based on the complete subprogram.
[0090] Based on any of the above embodiments, the code scanning module 504 is specifically used to: create a code scanning request based on the changed code content, send the changed code content and the code scanning request to the server, and receive the large model code scanning result returned by the server.
[0091] Based on any of the above embodiments, the code scanning module 504 is further configured to: receive the task identifier and the local code scanning instruction returned by the server; Polling the server for a large model code scanning result based on the task identifier, and performing a static code scan on the changed code content based on the local code scanning instruction; After determining that the large model code scanning result and the static code scanning result are obtained, the code scanning is stopped.
[0092] Based on any of the above embodiments, the type determination module 503 is specifically configured to: obtain a file change identifier of at least one of the target code files, and determine a file change type of the target code file based on the file change identifier.
[0093] Figure 6 The following is a schematic diagram of the structure of an electronic device, such as Figure 6 As shown, the electronic device may include: a processor 610, a communications interface 620, a memory 630, and a communications bus 640, wherein the processor 610, the communications interface 620, and the memory 630 communicate with each other via the communications bus 640. The processor 610 may invoke logic instructions in the memory 630 to execute a code scanning method, which includes: receiving a code selection instruction input by a user, determining a code selection range in the client based on the code selection instruction; obtaining at least one target code file from multiple code files within the code selection range, the target code file being a code file including changed code; determining a file change type of at least one of the target code files; processing at least one of the target code files based on the file change type to obtain changed code content, and scanning the changed code content.
[0094] Furthermore, the logic instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0095] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the code scanning method provided by the above methods, which includes: receiving a code selection instruction input by a user, and determining a code selection range in the client based on the code selection instruction; obtaining at least one target code file from multiple code files within the code selection range, wherein the target code file is a code file including a changed code; determining a file change type of at least one of the target code files; processing at least one of the target code files based on the file change type to obtain a changed code content, and scanning the changed code content.
[0096] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the code scanning method provided by the above-mentioned methods, the method comprising: receiving a code selection instruction input by a user, and determining a code selection range in the client based on the code selection instruction; obtaining at least one target code file from multiple code files within the code selection range, the target code file being a code file including a changed code; determining a file change type of at least one of the target code files; processing at least one of the target code files based on the file change type to obtain a changed code content, and scanning the changed code content.
[0097] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0098] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.
[0099] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.< / copilottoolbo>
Claims
1. A code scanning method, characterized in that: Applied to the client, including: receiving a code selection instruction input by a user, and determining a code selection range in the client based on the code selection instruction; Acquire at least one target code file from a plurality of code files within the code selection range, wherein the target code file is a code file including a change code; Determining a file change type of at least one of the target code files; At least one of the target code files is processed based on the file change type to obtain changed code content, and the changed code content is scanned.
2. The code scanning method according to claim 1, characterized in that: The file change types include adding new code files; Processing at least one of the target code files based on the file change type to obtain the changed code content specifically includes: When it is determined that the file change type of the target code file is a newly added code file, the changed code content is obtained based on the complete target code file.
3. The code scanning method according to claim 1, characterized in that: The file change type includes changing code files; Processing at least one of the target code files based on the file change type to obtain the changed code content specifically includes: When it is determined that the file change type of the target code file is a changed code file, obtaining the code file before the change; Comparing the pre-change code file with the target code file to obtain a changed code; The change code content is obtained based on the change code.
4. The code scanning method according to claim 3, characterized in that: Comparing the pre-modified code file with the target code file to obtain the modified code specifically includes: Parse the pre-change code file and the target code file respectively according to the first naming keyword to obtain a first subroutine name of the pre-change code file and a second subroutine name of the target code file; The first subprogram name and the second subprogram name are processed respectively by a preset content acquisition method to obtain a first subprogram content corresponding to the first subprogram name and a second subprogram content corresponding to the second subprogram name, Determine the first subprogram name corresponding to the second subprogram name, compare the first subprogram content corresponding to the first subprogram name with the second subprogram content corresponding to the second subprogram name, and obtain a change code.
5. The code scanning method according to claim 3, characterized in that: Obtaining the change code content based on the change code specifically includes: At least one subprogram to which the change code belongs is determined, and the change code content is obtained based on the complete subprogram.
6. The code scanning method according to claim 1, characterized in that: Scanning the changed code content specifically includes: A code scanning request is created based on the changed code content, and the changed code content and the code scanning request are sent to a server to receive a large model code scanning result returned by the server.
7. The code scanning method according to claim 6, characterized in that: After sending the changed code content and the code scanning request to the server, the method further includes: Receive the task identifier and local code scanning instruction returned by the server; Based on the task identifier, the server is polled for a large model code scanning result, and based on the local code scanning instruction, a static code scanning is performed on the changed code content; After determining that the large model code scanning result and the static code scanning result are obtained, the code scanning is stopped.
8. The code scanning method according to claim 1, characterized in that: Determining a file change type of at least one of the target code files specifically includes: A file change identifier of at least one of the target code files is obtained, and a file change type of the target code file is determined based on the file change identifier.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the code scanning method according to any one of claims 1 to 8 is implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the code scanning method according to any one of claims 1 to 8 is implemented.