Code detection method and device, electronic equipment and readable storage medium

By building a directed relationship graph between code files and using pre-trained models for detection, the problem of lack of cross-file code detection capabilities in the prior art is solved, and a higher code detection accuracy is achieved.

CN120104470APending Publication Date: 2025-06-06NETEASE (HANGZHOU) NETWORK CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510032952.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-08
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The existing technology lacks cross-file code detection capabilities during software development, resulting in low code detection accuracy.

Method used

By obtaining the reference relationship between multiple files to be detected, a directed relationship graph is constructed, the graph is traversed to identify independent sets of connected components, and the files are code-detected using pre-trained code detection models, and finally the detection results are merged to improve detection accuracy.

Benefits of technology

Cross-file code detection is realized, significantly improving the accuracy of code detection, and able to more comprehensively discover and repair problems in the code.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120104470A_ABST
    Figure CN120104470A_ABST
Patent Text Reader

Abstract

The invention discloses a code detection method and device, electronic equipment and a readable storage medium. The method comprises the steps that multiple to-be-detected files including codes are acquired; determining a reference relationship of classes and / or functions in the to-be-detected file; constructing a directed relation graph of a plurality of to-be-detected files on the basis of the to-be-detected files; traversing the directed relation graph to obtain at least one connected component set comprising to-be-detected files, the to-be-detected files included in different connected component sets being mutually independent; performing code detection on the to-be-detected file in the connected component set through a plurality of pre-trained code detection models to obtain a plurality of detection results corresponding to the connected component set; and combining the plurality of detection results to obtain a target detection result of the connected component set. According to the code detection method and device, cross-file code detection is achieved through the pre-trained code detection model by obtaining the reference relation among the multiple to-be-detected files, and the code detection accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computers, and in particular to a code detection method, device, electronic device and readable storage medium. Background Art

[0002] In the software development process, code detection is a key step to ensure that the software product meets the expected standards. At present, static detection tools such as SonarLint (code detection extension plug-in) are usually used to detect quality problems in single-file code, helping to discover and fix problems in the code, so as to expose and fix problems before the code is submitted. However, static detection tools such as SonarLint usually only perform syntax and semantic detection on the code in a single file, and lack cross-file detection capabilities. Summary of the invention

[0003] In view of this, the present application provides a code detection method, an apparatus, an electronic device and a readable storage medium, which can realize cross-file code detection, thereby improving the accuracy of code detection.

[0004] In a first aspect, an embodiment of the present application provides a code detection method, the method comprising:

[0005] Acquire multiple files to be detected, wherein the files to be detected include codes;

[0006] Determine a first reference relationship to a target code element in the file to be detected, wherein the target code element includes a class and / or a function;

[0007] Constructing a directed relationship graph of the plurality of files to be detected according to the first reference relationship;

[0008] Traversing the directed relationship graph to obtain at least one connected component set, wherein the connected component set includes at least one of the to-be-detected files, and the to-be-detected files included in different connected component sets are independent of each other;

[0009] Performing code detection on the files to be detected in the connected component set by using a plurality of pre-trained code detection models respectively, to obtain a plurality of detection results corresponding to the connected component set;

[0010] The multiple detection results are merged to obtain a target detection result of the connected component set.

[0011] In a second aspect, an embodiment of the present application provides a code detection device, the device comprising:

[0012] An acquisition module, used for acquiring a plurality of files to be detected, wherein the files to be detected include codes;

[0013] A determination module, used to determine a first reference relationship to a target code element in the file to be detected, wherein the target code element includes a class and / or a function;

[0014] A construction module, used to construct a directed relationship graph of the plurality of files to be detected according to the first reference relationship;

[0015] A traversal module, used for traversing the directed relationship graph to obtain at least one connected component set, wherein the connected component set includes at least one file to be detected, and the files to be detected included in different connected component sets are independent of each other;

[0016] A code detection module, used to perform code detection on the files to be detected in the connected component set by using a plurality of pre-trained code detection models respectively, to obtain a plurality of detection results corresponding to the connected component set;

[0017] A merging module is used to merge the multiple detection results to obtain a target detection result of the connected component set.

[0018] In a third aspect, an embodiment of the present application provides an electronic device, including:

[0019] Processor; and

[0020] The memory is used to store a data processing program. After the electronic device is powered on and the program is run by the processor, the method of the first aspect is executed.

[0021] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium storing a data processing program, which is executed by a processor to perform the method of the first aspect.

[0022] The code detection method provided by the present application obtains multiple files to be detected including codes; determines the reference relationship between classes and / or functions in the files to be detected; and based on this, constructs a directed relationship graph of multiple files to be detected; traverses the directed relationship graph to obtain at least one connected component set including the files to be detected, and the files to be detected included in different connected component sets are independent of each other; performs code detection on the files to be detected in the connected component set through multiple pre-trained code detection models respectively, and obtains multiple detection results corresponding to the connected component set; and merges the multiple detection results to obtain the target detection result of the connected component set. By obtaining the reference relationship between multiple files to be detected and realizing cross-file code detection through the pre-trained code detection model, the accuracy of code detection is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the description of the embodiments of the present application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0024] Figure 1 A flowchart of a code detection method provided in an embodiment of the present application;

[0025] Figure 2 A first schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0026] Figure 3 A second schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0027] Figure 4 A first schematic diagram of a directed relationship graph provided in an embodiment of the present application;

[0028] Figure 5 A second schematic diagram of a directed relationship graph provided in an embodiment of the present application;

[0029] Figure 6 A third schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0030] Figure 7 A fourth schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0031] Figure 8 A schematic diagram of using a code detection model to perform code detection on a file to be detected provided in an embodiment of the present application;

[0032] Fig. 9 A fifth schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0033] Fig.10 A sixth schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0034] Fig.11 A seventh schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0035] Fig.12 An eighth schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0036] Fig.13 A ninth schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0037] Fig.14A tenth schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0038] Fig.15 An eleventh schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0039] Fig.16 A twelfth schematic diagram of a graphical user interface provided in an embodiment of the present application;

[0040] Fig.17 A schematic diagram of a structure of a code detection device provided in an embodiment of the present application;

[0041] Fig.18 A structural block diagram of an electronic device used for a code detection method is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0042] Many specific details are described in the following description to facilitate a full understanding of the present application. However, the present application can be implemented in many other ways than those described herein, and those skilled in the art can make similar generalizations without violating the connotation of the present application, so the present application is not limited by the specific implementation disclosed below.

[0043] It should be noted that the terms "first", "second", "third", etc. in the claims, description and drawings of the present application are used to distinguish similar objects and are not used to describe a specific order or sequence. The data used in this way are interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including", "having" and their variants are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0044] It should be understood that in the embodiments of the present application, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" is merely a way to describe the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the previous and subsequent associated objects are in an "or" relationship. "Including A, B and / or C" means including any one, any two, or any three of A, B, and C.

[0045] It should be understood that in the embodiments of the present application, "B corresponding to A", "B corresponding to A", "A corresponds to B", or "B corresponds to A" means that B is associated with A, and B can be determined according to A. Determining B according to A does not mean determining B only according to A, and B can also be determined according to A and / or other information.

[0046] Based on the problems existing in the above-mentioned related technologies, the embodiments of the present application provide a code detection method, device, electronic device and readable storage medium.

[0047] The code detection method provided in the embodiment of the present application can be executed by an electronic device, which can be a terminal or a server. The terminal can be a terminal device such as a smart phone, a tablet computer, or a laptop computer. The server can be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. It is understandable that the present application does not specifically limit the execution subject of the code detection method.

[0048] In an optional embodiment, when the code detection method is run on a terminal device, the terminal device stores an application for code detection. The terminal device interacts with the user through a graphical user interface. The terminal device may provide the graphical user interface to the user in a variety of ways, for example, it may be rendered and displayed on a display screen of the terminal device, or the graphical user interface may be presented through holographic projection.

[0049] In an optional embodiment, when the code detection method is run on a server, the method can be implemented and executed based on a cloud service system. A cloud service system refers to a service method based on cloud computing. A cloud service system includes a server and a client device. The operating body of the application for code detection and the display screen presentation body are separated, and the storage and operation of the code detection method are completed on the server. The display screen presentation of code detection is completed on the client, and the client is mainly used for receiving, sending and presenting code detection data. For example, the client can be a display device with a data transmission function close to the user side, such as a mobile terminal, a television, a computer, a handheld computer, a personal digital assistant, a head-mounted display device (head display device), etc., but the electronic device for code detection is a server in the cloud. When performing code detection, the user operates the client to send instructions to the server, and the server controls the operation of the code detection method according to the instructions, encodes and compresses the code detection data, and returns it to the client through the network. Finally, the client decodes and outputs the code detection data.

[0050] It should be noted that in the embodiments of the present application, the execution subject of the code detection method can be a terminal device or a server, wherein the terminal device can be a local terminal device or a client device in the aforementioned cloud service system. The embodiments of the present application do not limit the type of the execution subject.

[0051] The technical solution of the present application is described in detail below through specific embodiments. It should be noted that the following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments described below are used to explain the technical solution of the present application and are not intended to be used as a limitation for actual use.

[0052] In the related art, in the software development process, code detection is a key step to ensure that the software product meets the expected standards. At present, static detection tools such as SonarLint (code detection extension plug-in) are usually used to detect quality problems in single-file code, helping to discover and fix problems in the code, so as to expose and fix problems before the code is submitted. However, static detection tools such as SonarLint usually only perform syntax and semantic detection on the code in a single file, and lack cross-file detection capabilities.

[0053] In the embodiment of the present application, multiple files to be detected including codes are obtained; the reference relationship of classes and / or functions in the files to be detected is determined; and a directed relationship graph of multiple files to be detected is constructed based on this; the directed relationship graph is traversed to obtain at least one connected component set including the files to be detected, and the files to be detected included in different connected component sets are independent of each other; the files to be detected in the connected component set are respectively subjected to code detection by multiple pre-trained code detection models to obtain multiple detection results corresponding to the connected component set; the multiple detection results are merged to obtain the target detection result of the connected component set. Therefore, the code detection method provided in the embodiment of the present application improves the accuracy of code detection by obtaining the reference relationship between the files to be detected and realizing cross-file code detection through a pre-trained code detection model.

[0054] In order to solve the technical problems existing in the related art, the embodiment of the present application provides a code detection method, such as Figure 1 As shown, Figure 1 This is a flowchart of an example of a code detection method provided in an embodiment of the present application. It should be noted that the steps shown can be performed in a logical order different from that shown in the flowchart of the method. The method may include the following steps S101 to S106.

[0055] Step S101: Acquire multiple files to be detected, wherein the files to be detected include codes.

[0056] In an optional embodiment, the file to be detected may be a file to be detected stored in a code hosting platform.

[0057] It should be noted that the code hosting platform provides a powerful version control system that allows developers to track and manage the code change history. Each code modification will be recorded to facilitate historical review and error correction, ensuring the quality and stability of the code. The code hosting platform can be at least one of Gitlab, SVN (Subversion) and CVS (Concurrent Versions System).

[0058] In a possible embodiment, the file to be detected is obtained by calling an API (Application Programming Interface) of a code hosting platform.

[0059] In a possible embodiment, obtaining the file to be detected by calling an API of the code hosting platform includes the following steps:

[0060] Create an access token on the code hosting platform. The access token is used for identity authentication. The access token is created based on the account of the code hosting platform. This application does not limit the method of creating the access token. After that, copy the token and enter the token, warehouse path and warehouse name in the graphical user interface to obtain the file to be tested.

[0061] In an optional embodiment, a token is created based on an account, and then the file to be detected stored in the account can be obtained based on the token corresponding to the account.

[0062] In an optional embodiment, if Figure 2 As shown, in the graphical user interface, the warehouse management interface is triggered by clicking on the warehouse management control, and the token control, warehouse address control and warehouse name control are displayed in the warehouse management interface. The token is input based on the token control, the warehouse address is input based on the warehouse address control, the warehouse name is input based on the warehouse name control, and the add control is triggered to display the corresponding warehouse code in the warehouse list, so that code detection can be performed on the warehouse code.

[0063] In an optional embodiment, if Figure 2As shown, a warehouse list is also displayed in the warehouse management interface, and the warehouse list includes at least one of the following information: warehouse name, warehouse address, warehouse code acquisition time, warehouse code update time, detection strategy library used to detect warehouse code, and parsing progress of warehouse code detection. The warehouse list also displays a configuration detection strategy control and an execution control. The configuration detection strategy control is used to configure the detection strategy used for code detection of warehouse code, and the execution control is used to perform code detection on warehouse code.

[0064] In an optional embodiment, if Figure 2 As shown, warehouse A and warehouse B are displayed in the warehouse list. Both warehouse A and warehouse B are code warehouses that have completed code detection. Among them, the warehouse list can display the following warehouse information for warehouse A: the warehouse name is A, the warehouse address is http: / / code****.git, the acquisition time is 05:11:05 on October 19, 2024, and the update time is 21:11:55 on October 21, 2024. Custom java and custom js detection strategies are adopted; the warehouse list can display the following warehouse information for warehouse B: the warehouse name is B, the warehouse address is http: / / code###.git, the acquisition time is 18:46:22 on October 20, 2024, and the update time is 21:02:55 on October 20, 2024. Custom java and sonarlint-java detection strategies are adopted.

[0065] Among them, custom-java is a custom java detection strategy, and sonarlint-java is the standard java detection strategy in sonarlint.

[0066] In an optional embodiment, a folder including the warehouse code is obtained by triggering the warehouse address, and a file to be tested that needs to be code tested is selected from the folder. The file to be tested may be a file to be tested including the warehouse code, or a file to be tested including a code branch of the warehouse code, or a file to be tested including the code in a certain folder in the warehouse code. This application is not limited to this.

[0067] In an optional embodiment, by triggering the warehouse address of any warehouse code displayed in the graphical user interface, based on the warehouse address, the Figure 3 The graphical user interface shown, Figure 3 The code branch drop-down control is included, and the code branch list control is displayed by triggering the code branch drop-down control. The code branch list includes code branch 1, code branch 2, and code branch 3. Select any code branch from the code branch list control as the file to be detected.

[0068] In an optional embodiment, in a manner similar to the above, code files in any folder in the code branch may be used as files to be detected, which is not described in detail in this application.

[0069] Step S102: Determine a first reference relationship to a target code element in the file to be detected, wherein the target code element includes a class and / or a function.

[0070] In an optional embodiment, the file to be detected is input into a preset model, and the reference relationship of the class and / or function in the file to be detected can be obtained.

[0071] In an optional embodiment, the preset model may be an LLM (Large Language Model) or other models, which is not limited in the present application.

[0072] It should be noted that the reference relationship to the class and / or function in the file to be detected refers to which function and / or which class is called by the code included in the file to be detected.

[0073] In an optional embodiment, code detection tools such as sonarlint and Pylint can be used to determine the reference relationship between classes and / or functions in the file to be detected. Of course, the present application can also use other methods to determine the reference relationship between classes and functions in the file to be detected, and the present application does not limit this.

[0074] Step S103: construct a directed relationship graph of multiple files to be detected according to the first reference relationship.

[0075] In a possible embodiment, the directed relationship graph also includes a configuration file of the file to be detected.

[0076] It should be noted that the configuration file is a place in the code to store settings, parameters and options. It allows developers to adjust the behavior of the program without modifying the application source code. The configuration file usually includes database connection information, API keys, environment-specific settings, etc. Depending on the programming language, the configuration file includes different formats, such as INT files, XML files, and JSON files.

[0077] When constructing a directed relationship graph of multiple files to be detected based on the first reference relationship, the basic structure of the directed relationship graph can be defined first: the directed relationship graph consists of a set of fixed points and a set of directed edges, each edge connects ordered vertices, the vertices can be any objects, and the edges represent the directional relationship between the vertices; initialize vertices: in the directed relationship graph, define the number of vertices, where arrays, linked lists or other data structures can be used to store vertices; add edges: in the directed relationship graph, the edges are directed, pointing from one vertex to another. When adding an edge, the target vertex needs to be added to the adjacency list of the starting vertex.

[0078] like Figure 4 As shown, Figure 4 A schematic diagram of constructing a directed relationship graph of multiple files to be detected based on the first reference relationship, wherein the circle represents the files to be detected, the triangle represents the classes referenced by the files to be detected, the square represents the configuration files of the files to be detected, the diamond represents the functions referenced by the files to be detected, the solid arrow represents a reference relationship between the two, and the dotted arrow represents an inclusion relationship between the two.

[0079] In a possible embodiment, a directed relationship graph of multiple files to be detected is constructed based on a first reference relationship, including: replacing a target code element in the first reference relationship with the file to be detected where the target code element is located, to obtain a second reference relationship between the files to be detected; and constructing a directed relationship graph of multiple files to be detected based on the second reference relationship.

[0080] like Figure 5 As shown, Figure 5 A schematic diagram of constructing a directed relationship graph of multiple files to be detected based on the second reference relationship, wherein the circle represents the files to be detected, the square represents the configuration files of the files to be detected, the solid arrow represents the reference relationship between the two, and the dotted arrow represents the inclusion relationship between the two.

[0081] Step S104: traverse the directed relationship graph to obtain at least one connected component set, wherein the connected component set includes at least one file to be detected, and the files to be detected included in different connected component sets are independent of each other.

[0082] It should be noted that the files to be detected included in different connected component sets are independent of each other, which means that there is no pointing relationship between the files to be detected in each connected component set and the files to be detected in other connected component sets.

[0083] In an optional embodiment, the files to be detected with an in-degree of 0 and an out-degree of not 0 in the directed relationship graph are used as starting points to perform BFS (Breath First Search) or DFS (Depth First Search) to obtain at least one connected component set.

[0084] Step S105: code detection is performed on the files to be detected in the connected component set using a plurality of pre-trained code detection models respectively, to obtain a plurality of detection results corresponding to the connected component set.

[0085] In a possible embodiment, multiple code detection models may be used to perform code detection on the codes in the connected component set to obtain multiple detection results.

[0086] In an optional embodiment, the training method of the code detection model includes the following steps:

[0087] A plurality of connected component set samples and cross-file detection error labels corresponding to the connected component set samples are obtained, wherein the connected component set samples include a plurality of file samples containing codes; the file samples in the connected component set samples are input into a code detection model to obtain a predicted detection result for the connected component set samples; and the model parameters of the code detection model are adjusted according to the difference between the predicted detection result and the cross-file detection error label.

[0088] In an optional embodiment, the difference between the predicted detection result and the cross-file detection error label is determined by calculating the loss function value, the gradient is calculated by back propagation, and the model parameters are updated according to the optimization algorithm. The above process is repeated for multiple rounds until the training stop condition is met. The training stop condition may be reaching the maximum number of iterations, the loss is no longer significantly reduced, etc.

[0089] It should be noted that the embodiments of the present application integrate multiple code detection models. Figure 6 As shown, the execution control is displayed in the graphical user interface. When the warehouse code with the warehouse name C is obtained, the user can instruct multiple code detection models to perform code detection on the warehouse code by triggering the execution control in the warehouse list. The graphical user interface also displays the warehouse information of the warehouse code with the warehouse name C: the warehouse address is http: / / code&&&&.git, the acquisition time is 2024-10-23 18;23:20, and the detection strategy is custom java and sonarlint-java.

[0090] In an optional embodiment, a code detection model drop-down list control is displayed in a graphical user interface, and a code detection model list control is displayed after the code detection model drop-down list control is triggered, so that the user can select a corresponding code detection model from the code detection model list control according to actual needs. It should be noted that the user can select multiple code detection models from the code detection model list control for code detection according to actual needs. For example, a code detection model group is selected from the code detection model list control for code detection according to actual needs, such as a code detection model group that includes code detection model 1, code detection model 2, and code detection model 3.

[0091] In the embodiments of the present application, a variety of code detection models are provided for code detection, which can meet the preferences and needs of different users, provide users with a more flexible code detection solution, and improve the accuracy and coverage of code detection.

[0092] Step S106: Merge multiple detection results to obtain a target detection result of a connected component set.

[0093] In a possible embodiment, merging the multiple detection results includes: classifying the multiple detection results, unifying the formats, and removing duplicates.

[0094] In a possible embodiment, the detection results are classified by classifying the multiple detection results according to the problem type, wherein the problem type includes at least one of the following types: naming, function, exception handling that does not use conventions, asynchronous operation, null value check, event listener release, loop optimization, magic value, etc. This application does not limit the problem type.

[0095] In a possible embodiment, considering that the formats of detection results output by different code detection models are inconsistent, when the code detection model outputs the detection result, the format of the output detection result is unified into one format.

[0096] In an optional embodiment, when the language type of the code to be detected is Python, the detection results can be unified into the Pylint format; when the language type of the code to be detected is C language and C++ language, the detection results can be unified into the Cppcheck format; when the language type of the code to be detected is JavaScript and TypeScript, the detection results can be unified into the ESLint format. Of course, when the language type of the code to be detected is Java, Python, C#, JavaScript, PHP, VB.NET, TypeScript, etc., the detection results can be unified into the SonarLint format.

[0097] In an optional embodiment, the GPT model can be used to classify and unify the format of the detection results, and other models can also be used to classify and unify the format of the detection results, which is not limited in this application.

[0098] In an optional embodiment, if Figure 7 As shown, the detection result control is triggered in the graphical user interface, the warehouse file tree control is displayed, and the model drop-down list control (such as Figure 7 The user triggers the model drop-down list control to select the corresponding model to classify and unify the detection results, and triggers the generation control to obtain the target detection results that are classified and unified in format using the code in the selected model.

[0099] In the embodiments of the present application, a unified format is used to return the results, which can ensure the standardization and readability of the test results.

[0100] In an embodiment of the present application, multiple files to be detected including codes are obtained; the reference relationship between classes and / or functions in the files to be detected is determined; and a directed relationship graph of the multiple files to be detected is constructed based on this; the directed relationship graph is traversed to obtain at least one connected component set including the files to be detected, and the files to be detected included in different connected component sets are independent of each other; code detection is performed on the files to be detected in the connected component set through multiple pre-trained code detection models, and multiple detection results corresponding to the connected component set are obtained; the multiple detection results are merged to obtain a target detection result of the connected component set.

[0101] Since only static detection tools are used to detect single files in the prior art, the accuracy of code detection is low. The embodiment of the present application obtains the reference relationship between multiple files to be detected and implements cross-file code detection through a pre-trained code detection model, thereby improving the accuracy of code detection.

[0102] It should be noted that in the process of software development and code review, single-file code detection refers to independent static analysis of a single source code file. This analysis focuses on issues such as code quality, logical errors, potential vulnerabilities, and coding standards within the file. Cross-file detection refers to static or dynamic analysis of the relationships and interactions between multiple files in one or more projects. This analysis focuses more on detecting cross-file errors, inconsistencies, and dependency conflicts.

[0103] In a possible embodiment, Figure 7As shown, a prompt word control is displayed in the graphical user interface, and the corresponding code detection type is entered in the prompt word control to display only the target detection results of the corresponding code detection type in the graphical user interface. Among them, the code detection type can include only displaying single-file problem codes, only displaying cross-file problem codes, not displaying low-severity error problem codes, etc. This application does not limit the code detection type.

[0104] In an optional embodiment, if Figure 8 As shown, multiple files to be detected are respectively input into multiple code detection models, such as code detection model 1, code detection model 2 and code detection model 3, to obtain multiple detection results, and the multiple detection results are input into the GPT model, and the GPT model classifies, removes duplicates and unifies the format of the detection results to obtain the target detection results, and then stores the target detection results in the database. Among them, the code detection model can be a traditional machine learning model and a deep learning model.

[0105] It should be noted that when performing code detection on the file to be detected, it is often necessary to undergo multiple modifications to obtain code that can run correctly. Therefore, in the embodiment of the present application, the historical target detection results of the file to be detected and the time when the historical target detection results were obtained will be stored so that the user can modify the code in the file to be detected based on the historical target detection results when modifying the code in the file to be detected.

[0106] In a possible embodiment, the method also includes: displaying, in a graphical user interface, the problem code of the file to be detected included in the connected component set, the code block where the problem code is located, and a question control for the problem code based on the target detection result; in response to question information for the problem code received in the question control, generating reply information for the question information through a preset model, and displaying the reply information in the graphical user interface.

[0107] In an optional embodiment, if Figure 7 As shown, in the graphical user interface, a warehouse name drop-down list control (such as Figure 7 The box containing the repository name A+check mark), the drop-down list control of the code branch name to which the problem code belongs (such as Figure 7 The GUI includes the warehouse branch a1+check mark box), the address of the file to be detected, the location of the problem code in the file to be detected, the problem type of the problem code, the detection strategy type of the problem code, and the date of obtaining the target detection result of the file to be detected. Of course, other controls can also be displayed in the graphical user interface, and this application does not limit this.

[0108] In an optional embodiment, Figure 7In the , you can trigger the warehouse name drop-down list control to display the warehouse name drop-down list, select any warehouse in the warehouse name drop-down list, and trigger the code branch name drop-down list control to display the code branch name drop-down list control, select any code branch in the code branch name drop-down list control, and then display the detection results of only any code branch.

[0109] In an optional embodiment, the detection strategy types may include at least one of the following types: vulnerabilities, vulnerabilities and code smells, wherein vulnerabilities refer to phenomena such as malfunction, crashes, data loss or abnormal interruptions caused by errors in the program itself during software operation; code smells refer to some problems or poor designs in the code that make the code difficult to maintain, expand and understand; code vulnerability refers to the feature that new errors or failures are easily introduced in the code during modification or expansion.

[0110] In an embodiment of the present application, a question control for the problem code is displayed in a graphical user interface, so that the user can input question information for the problem code through the question control, and then quickly obtain a detailed explanation of the target detection result and its corresponding solution through a dialogue, thereby quickly optimizing the code.

[0111] In an optional embodiment, an interactive function is implemented based on a preset model, so that the user can implement a dialogue function through the preset model, and then quickly obtain a detailed explanation of the target detection result and its corresponding solution through dialogue, and quickly optimize the code.

[0112] In a possible embodiment, the method also includes: obtaining the directory where the files to be detected included in the connected component set are located; based on the target detection results, displaying the directory where the files to be detected included in the connected component set are located in a graphical user interface, and displaying the number of problem codes included in the corresponding files to be detected for the directory.

[0113] In an optional embodiment, if Figure 7 As shown, the directory where the files to be detected included in the connected component set are located is displayed in the graphical user interface, and the number of problem codes included in the corresponding files to be detected is displayed for the directory. For example, the warehouse branch named a1 in the warehouse code of the warehouse named A includes 517 files and 2091 problems, among which the first js. file includes 1 problem, the second js. file includes 2 problems and the third js. file includes 6 problems.

[0114] In a possible embodiment, according to the target detection result, the problem code of the file to be detected included in the connected component set, the code block where the problem code is located, and the question control for the problem code are displayed in a graphical user interface, including: in response to a selection operation on a directory, according to the target detection result, the problem code included in the file to be detected corresponding to the directory in the connected component set, the code block where the problem code is located, and the question control for the problem code are displayed in the graphical user interface.

[0115] In an optional example, the problem type of the problem code and the block where the problem code is located are: exception handling - lines 22-28;

[0116] The problem code is: 'Variable, property and parameter names should comply with anaming convention';

[0117] 1const splitName='book-tab;

[0118] answer:

[0119] 'splitName' is a constant, but it uses camelCase with a lowercase beginning, which does not conform to the naming convention that constants should be all uppercase and separated by underscores;

[0120] 'splitName' should be renamed to 'SPLIT_NAME' to follow the naming convention for constants.

[0121] In an optional embodiment, if Fig. 9 As shown, a warehouse name drop-down list control (such as Fig. 9 The box containing the repository name A+check mark), the drop-down list control of the code branch name to which the problem code belongs (such as Fig. 9 Including warehouse branch a1 + check mark box), prompt word control, model drop-down list control (such as Fig. 9 The control includes the GPT+check mark box shown in the figure) and the build control, the detection date of the code branch, the number of problem types of the code branch, the severity of each problem of the code branch (such as 5 stars for severity, 4 stars for severity), the question control for each problem of the code branch, and the send control. The warehouse name drop-down list control of the warehouse to which the problem code belongs (such as Fig. 9 The box containing the repository name A+check mark), the drop-down list control of the code branch name to which the problem code belongs (such as Fig. 9 Including warehouse branch a1 + check mark box), prompt word control, model drop-down list control (such as Fig. 9For a specific explanation of the box including GPT+check mark shown in (including GPT+check mark) and the generation control, please refer to the above content, and this application will not go into details. A question control for each question of the code branch is displayed in the graphical user interface, so that the user can input question information for the question through the question control, and send the question information by triggering the send control, and then quickly obtain a detailed explanation of the question and its corresponding solution through the dialogue, and quickly optimize the code. For example, the problem may be: the return value of the play function is not processed, resulting in uncaught promise rejection and the error of the fetch request is not processed, which may result in uncaught exceptions, etc. The problem code address may be C / folder A / file B.js: lines 28-32 and C / folder B / file A.js: lines 20-38, etc.

[0122] In an optional embodiment, if Fig.10 As shown, the detection tool control is displayed in the graphical user interface, and the detection tool control is triggered to display the single file to be detected parsing control, so that the single file to be detected upload control (such as Fig.10 Click or drag to this area to upload) and upload the single file to be detected through the single file upload control, and then analyze the problem of the single file to be detected.

[0123] In an optional embodiment, if Fig.11 As shown, after uploading a single file to be detected through the single file upload control, the number of files (for example, the number of files is 2), the number of questions (such as the number of questions is 5), the uploaded single file to be detected, and the delete control corresponding to the single file to be detected are displayed. By performing a selection operation on the displayed single file to be detected, the problem analysis interface of the single file to be detected can be directly obtained. And in response to receiving a trigger operation for the delete control corresponding to the single file to be detected in the graphical user interface, the single file to be detected corresponding to the control can be deleted.

[0124] In an optional embodiment, the user can also directly input question information for a single file to be detected in the question control displayed in the graphical user interface, quickly obtain a detailed explanation of the target detection result and its corresponding solution through dialogue, and quickly optimize the code.

[0125] In an optional embodiment, a single file to be detected is input into a static detection tool and a code detection model respectively to obtain multiple detection results, and the multiple detection results are input into a GPT model. The GPT model classifies, deduplicates and unifies the format of the detection results to obtain target detection results, which are then stored in a database.

[0126] In a possible embodiment, a custom detection strategy control is displayed in a graphical user interface, and in response to receiving a custom detection strategy in the custom detection strategy control, the custom detection strategy is added to a code detection tool, so that when performing code detection on a file to be detected, a corresponding detection strategy can be checked according to the code in the file to be detected, thereby improving the flexibility of code detection. Among them, a detection strategy or a detection strategy group can be customized, and the detection strategy group can be classified according to the language type of the code.

[0127] In an optional embodiment, when performing code detection on a single file to be detected, a pre-trained code detection model and a static detection tool can be used to perform code detection on the single file to be detected; when performing cross-file code detection on multiple files to be detected, only a pre-trained code detection model can be used to perform cross-file code detection on multiple files to be detected.

[0128] In an optional embodiment, adding a custom detection strategy to a code detection tool includes: adding the custom detection strategy to a detection strategy library of a static detection tool; and / or, adding the custom detection strategy as a prompt word of a code detection model.

[0129] In an optional embodiment, when the code detection tool is sonarlint, the custom detection strategy is added to the sonarlint detection strategy library; when the code detection tool is a code detection model, the custom detection strategy is added to the prompt word of the code detection model.

[0130] In an optional embodiment, if Fig.12 As shown, the detection strategy library control is displayed in the graphical user interface, and the new detection strategy control is displayed after the detection strategy library control is triggered, and the detection strategy addition control is displayed after the new detection strategy control is triggered. Fig.13 As shown, when a user triggers the detection policy adding control, a detection policy description control may be displayed, which is used to instruct the user to enter the detection policy description information. In addition, at least one of the following controls may be displayed in the graphical user interface: a control for entering the detection policy name, a control for entering the detection policy type, a control for entering the detection policy severity, and a control for entering the recommended code and the non-recommended code for the detection policy. Of course, controls for entering other detection policy information may also be displayed, which is not limited in this application.

[0131] It should be noted that the severity of the detection strategy can be set by the user based on experience, for example, the severity level can be 5 stars, the severity level can be 4 stars, and so on.

[0132] In an optional embodiment, if Fig.12As shown, the graphical user interface also displays a detection strategy group name control, a management detection strategy group control, and the detection strategy name, detection strategy type, severity of the detection strategy, detection strategy description, recommended code and non-recommended code for the detection strategy, and operations for the detection strategy. Of course, other content can also be displayed in addition to this, and this application does not limit this. Among them, the management detection strategy group control is used to edit the relevant information of the detection strategy to complete the modification of the detection strategy.

[0133] In an optional embodiment, if Figure 2 As shown in the figure, when checking the detection strategy or detection strategy group for the code in the file to be detected, the user can click the configuration detection strategy control in the warehouse management interface to trigger the display of the detection strategy configuration control. Fig.14 As shown, the user can directly select the detection policy library in the displayed detection policy library drop-down list control to complete the detection policy library configuration, and can also complete the detection policy library configuration by searching for the detection policy library in the detection policy library search box control. After completing the detection policy library configuration, the user can select the detection policy in the displayed detection policy drop-down list control to complete the detection policy configuration, and can also complete the detection policy configuration by searching for the detection policy in the detection policy search box control.

[0134] It should be noted that the recommended code and the non-recommended code of the detection strategy are used so that the subsequent user can modify the code to be detected according to the recommended code and avoid problems existing in the non-recommended code during the modification process.

[0135] The operation may include a deletion operation, etc. This application does not limit the specific contents of the detection strategy group name, detection strategy name, detection strategy type, detection strategy severity, detection strategy description, recommended codes and non-recommended codes for problem codes, and operations for detection strategies.

[0136] The code detection system in the embodiment of the present application supports user-defined detection strategies and detection strategy groups, so that the user can select a single or multiple detection strategy groups according to actual needs, as well as some detection strategies in the detection strategy group to perform code detection on the code to be detected.

[0137] In a possible embodiment, the method also includes: based on the target detection results, counting the number of problem codes with the same problem type in the files to be detected included in the connected component set to obtain detection result statistics based on the problem type; and displaying the detection result statistics based on the problem type in a graphical user interface.

[0138] In a possible embodiment, the method also includes: based on the target detection results, counting the number of problem codes obtained by detecting the same detection strategy in the files to be detected included in the connected component set, to obtain detection result statistics based on the detection strategy type; and displaying the detection result statistics based on the detection strategy type in a graphical user interface.

[0139] In a possible embodiment, Fig.15 As shown, a code quality detection report control is displayed in a graphical user interface, and an analysis dashboard and feedback control are displayed after the code quality detection report control is triggered. At least one of the following statistical information is displayed after the analysis dashboard and feedback control are triggered: the overall problem score of the file to be detected (such as the overall problem score is 70.89), the number of problems of the file to be detected (such as the number of problems is 358), the number of files of the file to be detected (such as the number of files is 123), the problem density of the file to be detected (such as the problem density is 2.91), the detection result statistics based on the detection strategy type and the detection result statistics based on the problem type, etc., to facilitate the user to intuitively view the code, and the multi-dimensional analysis helps the user to fully understand the code status, quickly locate and solve the problem. Among them, the overall problem score of the code to be detected can be to design different scores for different problem types, and then design a full score, and use the full score to deduct the score of the problem in the code to be detected to obtain the overall problem score. Of course, other methods can also be used to calculate the overall problem score and problem density of the code to be detected, and this application does not limit this.

[0140] In an optional example, the detection result statistics based on the detection strategy type and the detection result statistics based on the problem type can be represented in the form of a pie chart or a bar chart. Fig.15 As shown, the detection result statistics based on the detection strategy type and the detection result statistics based on the problem type are displayed in the form of a pie chart, and the detection result statistics based on the detection strategy type and the detection result statistics based on the problem type are displayed in the form of a bar chart. Among them, the detection result statistics based on the problem type in code branch 1 include the number of unused exception handling issues of 126, the number of null value checking issues of 115, the number of event listener release issues of 132, and the number of loop optimization issues of 129. The detection result statistics based on the detection strategy type in code branch 1 include the number of vulnerabilities of 152, the number of vulnerabilities of 130, and the number of code smells of 168.

[0141] In a possible embodiment, an OpenAPI interface is set so that the software to which the graphical user interface belongs can be connected to different software for code detection to meet the diverse needs of users.

[0142] In a possible embodiment, the method further includes:

[0143] A feedback control for a first detection sub-result of a problem code is displayed in a graphical user interface, wherein the target detection result includes the first detection sub-result; in response to feedback information for the first detection sub-result received in the feedback control, the problem code is determined to be an iterative training sample of a code detection model, and a sample type of the problem code is determined based on the feedback information, wherein the sample type is a positive sample type or a negative sample type.

[0144] It should be noted that the positive sample is the problem code corresponding to the first detection sub-result whose feedback information is positive feedback, and the negative sample is the problem code corresponding to the first detection sub-result whose feedback information is negative feedback. It should be noted that positive feedback is used to indicate that the first detection sub-result is accurate, and negative feedback is used to indicate that the first detection sub-result is inaccurate.

[0145] In an optional embodiment, if Figure 7 As shown, the feedback control displayed in the graphical user interface is used to score the target detection results of the problem code. For the target detection results with scores higher than the first preset value and lower than the second preset value and their corresponding codes to be detected, they are used as training data of the model to train the model and improve the detection accuracy of the model. This feedback mechanism helps to continuously improve the inspection accuracy of the model and form a virtuous circle. Among them, the first preset value is greater than the second preset value.

[0146] In an optional embodiment, for example, for problem code A, the model's detection result is that there are problems with grammar, semantics or spelling. Taking the full score of user rating as 100 points, for example, the user gives a score below 50 points, such as 20, etc., then the problem to be detected and its corresponding target detection result are used to train the model so that the subsequent model can reduce misjudgment. For user scores above 70 points, such as 89, etc., then the problem code and its corresponding target detection result are used to train the model to improve the detection accuracy of the model. The model is continuously optimized through user feedback to improve detection accuracy. Users can directly influence the improvement of the code detection system and enhance user participation and trust.

[0147] In an optional embodiment, a problem list is displayed in a graphical user interface, the problem list including the path of the file to which the problem code belongs, the problem type, the problem severity, the problem, and improvement suggestions.

[0148] In an alternative example, Fig.16As shown, a code quality report drop-down control is displayed in the graphical user interface, and an improvement list control is displayed by triggering the code quality report drop-down control, and a problem list is displayed by triggering the improvement list control. For example, the path of the file to which the problem code belongs is rn-podcast-book-tab / index.android.js, the problem type is naming convention, the problem severity is 5 stars, the problem is that the function name "InitConfig" should start with a lowercase letter and use camel case naming, and the improvement suggestion is "change InitConfig to "initConfig" to comply with the naming convention."

[0149] Corresponding to the code detection method provided in the embodiment of the present application, the embodiment of the present application also provides a code detection device 1700, such as Fig.17 As shown, the device 1700 includes:

[0150] The acquisition module 1701 is used to acquire a plurality of files to be detected, wherein the files to be detected include codes;

[0151] A determination module 1702 is used to determine a first reference relationship to a target code element in the file to be detected, wherein the target code element includes a class and / or a function;

[0152] A construction module 1703 is used to construct a directed relationship graph of the plurality of files to be detected according to the first reference relationship;

[0153] A traversal module 1704 is used to traverse the directed relationship graph to obtain at least one connected component set, wherein the connected component set includes at least one file to be detected, and the files to be detected included in different connected component sets are independent of each other;

[0154] The code detection module 1705 is used to perform code detection on the files to be detected in the connected component set by using a plurality of pre-trained code detection models respectively, and obtain a plurality of detection results corresponding to the connected component set;

[0155] The merging module 1706 is used to merge the multiple detection results to obtain the target detection result of the connected component set.

[0156] In a possible embodiment, the determination module 1702 is configured to:

[0157] The target code element in the first reference relationship is replaced by the file to be detected where the target code element is located, so as to obtain a second reference relationship between the files to be detected;

[0158] A directed relationship graph of the plurality of files to be detected is constructed according to the second reference relationship.

[0159] In a possible embodiment, the apparatus further includes a training module 1707, which is used to:

[0160] Acquire a plurality of connected component set samples and cross-file detection error labels corresponding to the connected component set samples, wherein the connected component set samples include a plurality of file samples containing codes;

[0161] Inputting the file sample in the connected component set sample into the code detection model to obtain a prediction detection result for the connected component set sample;

[0162] According to the difference between the predicted detection result and the cross-file detection error label, the model parameters of the code detection model are adjusted.

[0163] In a possible embodiment, the device further includes a first display module 1708, configured to:

[0164] According to the target detection result, displaying the problem code of the file to be detected included in the connected component set, the code block where the problem code is located, and a question control for the problem code in a graphical user interface;

[0165] In response to receiving question information for the question code in the question control, answer information for the question information is generated through a preset first model, and the answer information is displayed in the graphical user interface.

[0166] In a possible embodiment, the device further includes a second display module 1709, which is used to:

[0167] Displaying a feedback control for a first detection sub-result of the problem code in the graphical user interface, wherein the target detection result includes the first detection sub-result;

[0168] In response to receiving feedback information for the first detection sub-result in the feedback control, determining that the problem code is an iterative training sample of the code detection model, and determining the sample type of the problem code based on the feedback information, wherein the sample type is a positive sample type or a negative sample type.

[0169] In a possible embodiment, the device further includes a third display module 1710, configured to:

[0170] Obtaining the directory where the to-be-detected file included in the connected component set is located;

[0171] According to the target detection result, the directory where the files to be detected included in the connected component set are located is displayed in the graphical user interface, and the number of problem codes included in the corresponding files to be detected is displayed for the directory.

[0172] In a possible embodiment, the third display module 1710 is specifically used for:

[0173] In response to a selection operation on the directory, based on the target detection result, the problem code included in the file to be detected corresponding to the directory in the connected component set, the code block where the problem code is located, and a question control for the problem code are displayed in the graphical user interface.

[0174] In a possible embodiment, the device further includes a fourth display module 1711, configured to:

[0175] Display custom detection strategy controls in the graphical user interface;

[0176] In response to receiving a custom detection policy in the custom detection policy control, the custom detection policy is added to the code detection model.

[0177] In a possible embodiment, the fourth display module 1711 is used to:

[0178] The custom detection strategy is added as a prompt word of the code detection model.

[0179] In a possible embodiment, the device further includes a fifth display module 1712, configured to:

[0180] According to the target detection result, the number of problem codes with the same problem type in the to-be-detected file included in the connected component set is counted to obtain detection result statistics based on the problem type;

[0181] The detection result statistics based on the problem type are displayed in a graphical user interface.

[0182] In a possible embodiment, the device further includes a sixth display module 1713, configured to:

[0183] According to the target detection result, the number of problem codes detected by the same detection strategy in the to-be-detected file included in the connected component set is counted to obtain detection result statistics based on the detection strategy type;

[0184] The detection result statistics based on the detection strategy type are displayed in a graphical user interface.

[0185] Corresponding to a code detection method provided in an embodiment of the present application, an embodiment of the present application also provides an electronic device for executing the code detection method, such as Fig.18 As shown, the electronic device includes: a processor 1801; and a memory 1802, which is used to store a program of the code detection method. After the device is powered on and the program of the code detection method is run by the processor, the following steps are performed:

[0186] Acquire multiple files to be detected, wherein the files to be detected include codes;

[0187] Determine a first reference relationship to a target code element in the file to be detected, wherein the target code element includes a class and / or a function;

[0188] Constructing a directed relationship graph of the plurality of files to be detected according to the first reference relationship;

[0189] Traversing the directed relationship graph to obtain at least one connected component set, wherein the connected component set includes at least one of the to-be-detected files, and the to-be-detected files included in different connected component sets are independent of each other;

[0190] Performing code detection on the files to be detected in the connected component set by using a plurality of pre-trained code detection models respectively, to obtain a plurality of detection results corresponding to the connected component set;

[0191] The multiple detection results are merged to obtain the target detection result of the connected component set. Corresponding to the code detection method provided in the embodiment of the present application, the embodiment of the present application also provides a computer-readable storage medium storing a program of the code detection method, which is executed by a processor to perform the following steps:

[0192] Acquire multiple files to be detected, wherein the files to be detected include codes;

[0193] Determine a first reference relationship to a target code element in the file to be detected, wherein the target code element includes a class and / or a function;

[0194] Constructing a directed relationship graph of the plurality of files to be detected according to the first reference relationship;

[0195] Traversing the directed relationship graph to obtain at least one connected component set, wherein the connected component set includes at least one of the to-be-detected files, and the to-be-detected files included in different connected component sets are independent of each other;

[0196] Performing code detection on the files to be detected in the connected component set by using a plurality of pre-trained code detection models respectively, to obtain a plurality of detection results corresponding to the connected component set;

[0197] The multiple detection results are merged to obtain a target detection result of the connected component set.

[0198] It should be noted that for the detailed description of the device, electronic device and computer-readable storage medium provided in the embodiments of the present application, reference can be made to the relevant description of the code detection method embodiment provided in the embodiments of the present application, which will not be repeated here.

[0199] Although the present application is disclosed as above in the form of a preferred embodiment, it is not intended to limit the present application. Any technical personnel in this field may make possible changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be based on the scope defined by the claims of the present application.

[0200] In a typical configuration, an electronic device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0201] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0202] 1. Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. Information can be computer-readable operations, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined in this article, computer-readable media does not include non-transitory media such as modulated data signals and carrier waves.

[0203] 2. Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0204] Although the present application is disclosed as above in the form of a preferred embodiment, it is not intended to limit the present application. Any technical personnel in this field may make possible changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be based on the scope defined by the claims of the present application.

Claims

1. A code detection method, characterized in that: The method comprises: Acquire multiple files to be detected, wherein the files to be detected include codes; Determine a first reference relationship to a target code element in the file to be detected, wherein the target code element includes a class and / or a function; Constructing a directed relationship graph of the plurality of files to be detected according to the first reference relationship; Traversing the directed relationship graph to obtain at least one connected component set, wherein the connected component set includes at least one of the to-be-detected files, and the to-be-detected files included in different connected component sets are independent of each other; Performing code detection on the files to be detected in the connected component set by using a plurality of pre-trained code detection models respectively, to obtain a plurality of detection results corresponding to the connected component set; The multiple detection results are merged to obtain a target detection result of the connected component set.

2. The method according to claim 1, characterized in that The step of constructing a directed relationship graph of the plurality of files to be detected according to the first reference relationship includes: The target code element in the first reference relationship is replaced by the file to be detected where the target code element is located, so as to obtain a second reference relationship between the files to be detected; A directed relationship graph of the plurality of files to be detected is constructed according to the second reference relationship.

3. The method according to claim 1, characterized in that The training method of the code detection model includes: Acquire a plurality of connected component set samples and cross-file detection error labels corresponding to the connected component set samples, wherein the connected component set samples include a plurality of file samples containing codes; Inputting the file sample in the connected component set sample into the code detection model to obtain a prediction detection result for the connected component set sample; According to the difference between the predicted detection result and the cross-file detection error label, the model parameters of the code detection model are adjusted.

4. The method according to claim 1, characterized in that: The method further comprises: According to the target detection result, displaying the problem code of the file to be detected included in the connected component set, the code block where the problem code is located, and a question control for the problem code in a graphical user interface; In response to receiving question information for the question code in the question control, answer information for the question information is generated through a preset first model, and the answer information is displayed in the graphical user interface.

5. The method according to claim 4, characterized in that The method further comprises: Displaying a feedback control for a first detection sub-result of the problem code in the graphical user interface, wherein the target detection result includes the first detection sub-result; In response to receiving feedback information for the first detection sub-result in the feedback control, determining that the problem code is an iterative training sample of the code detection model, and determining the sample type of the problem code based on the feedback information, wherein the sample type is a positive sample type or a negative sample type.

6. The method according to claim 4, characterized in that The method further comprises: Obtaining the directory where the to-be-detected file included in the connected component set is located; According to the target detection result, the directory where the files to be detected included in the connected component set are located is displayed in the graphical user interface, and the number of problem codes included in the corresponding files to be detected is displayed for the directory.

7. The method according to claim 6, characterized in that The step of displaying, in a graphical user interface, the problem code of the file to be detected, the code block where the problem code is located, and a question control for the problem code included in the connected component set according to the target detection result comprises: In response to a selection operation on the directory, based on the target detection result, the problem code included in the file to be detected corresponding to the directory in the connected component set, the code block where the problem code is located, and a question control for the problem code are displayed in the graphical user interface.

8. The method according to claim 1, characterized in that The method further comprises: Display custom detection strategy controls in the graphical user interface; In response to receiving a custom detection policy in the custom detection policy control, the custom detection policy is added to the code detection model.

9. The method according to claim 8, characterized in that Adding the custom detection strategy to the code detection model includes: The custom detection strategy is added as a prompt word of the code detection model.

10. The method according to claim 1, characterized in that The method further comprises: According to the target detection result, the number of problem codes with the same problem type in the to-be-detected file included in the connected component set is counted to obtain detection result statistics based on the problem type; The detection result statistics based on the problem type are displayed in a graphical user interface.

11. The method according to claim 1, characterized in that: The method further comprises: According to the target detection result, the number of problem codes detected by the same detection strategy in the to-be-detected file included in the connected component set is counted to obtain detection result statistics based on the detection strategy type; The detection result statistics based on the detection strategy type are displayed in a graphical user interface.

12. A code detection device, characterized in that: The device comprises: An acquisition module, used for acquiring a plurality of files to be detected, wherein the files to be detected include codes; A determination module, used to determine a first reference relationship to a target code element in the file to be detected, wherein the target code element includes a class and / or a function; A construction module, used to construct a directed relationship graph of the plurality of files to be detected according to the first reference relationship; A traversal module, used for traversing the directed relationship graph to obtain at least one connected component set, wherein the connected component set includes at least one file to be detected, and the files to be detected included in different connected component sets are independent of each other; A code detection module, used to perform code detection on the files to be detected in the connected component set by using a plurality of pre-trained code detection models respectively, to obtain a plurality of detection results corresponding to the connected component set; A merging module is used to merge the multiple detection results to obtain a target detection result of the connected component set.

13. An electronic device, characterized in that: include: processor; as well as The memory is used to store a data processing program. After the electronic device is powered on and the program is run by the processor, the method according to any one of claims 1 to 11 is executed.

14. A computer-readable storage medium, characterized in that: A data processing program is stored, and the program is run by a processor to execute the method according to any one of claims 1 to 11.