Automatic quality management method based on static code analysis

Through an automated quality management method based on static code analysis, the exclusive rule engine and cloud real-time update mechanism are used to solve the problem of compatibility detection of databases in China by the Innovative Innovation Project, and an efficient and low-cost adaptation process is achieved.

CN120336157AInactive Publication Date: 2025-07-18QIMING INFORMATION TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510811512.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-07-18
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing code analysis tools cannot effectively detect the compatibility problems of the Chinese databases of the Xinchuang project, resulting in the adaptation process relying on manual analysis, which is costly and error-prone.

Method used

Provide an automated quality management method based on static code analysis, including establishing static code scanning tools, using a proprietary rule engine for database compatibility detection, supporting local and platform scanning modes, and updating the rule base in real time through the cloud.

Benefits of technology

It has achieved efficient compatibility detection of the Chinese database of information innovation projects, reduced manual intervention, reduced costs, and improved work efficiency in the adaptation preparation stage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120336157A_ABST
    Figure CN120336157A_ABST
Patent Text Reader

Abstract

The invention discloses an automatic quality management method based on static code analysis. The method comprises the following steps: S1, establishing a static code scanning tool; s2, a static code scanning mode is determined, and code scanning is carried out; and S3, generating a compatibility report and updating the rule engine. The invention provides an exclusive rule engine aiming at the compatibility of a domestic database, and the common database migration problem in a credential project can be effectively detected; a code scanning method capable of being started without service is provided, dependence and cost are reduced, and the working efficiency of the adaptation preparation stage is improved; a rule base updated in real time at the cloud end is realized, and the rule engine is ensured to cope with constantly changing technical requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software analysis and modification, and specifically to an automated quality management method based on static code analysis. Background Art

[0002] In the current process of information technology innovation adaptation, project codes usually need to be comprehensively reviewed to ensure compatibility with domestic databases. However, most existing code analysis tools are oriented towards general scenarios and cannot conduct in-depth database compatibility detection for the special requirements of the information technology innovation environment. Especially in the preparatory stage of information technology innovation adaptation, the project team faces huge pressures of code migration and compatibility evaluation, lacking effective tools to identify and solve potential database compatibility problems. Most current mainstream tools support international mainstream databases such as MySQL, Oracle, and SQL Server, but do not provide rules and detection capabilities for specific compatibility problems faced by domestic databases (such as DM and Kingbase). Due to the significant differences in syntax, structure, and behavior between domestic databases and foreign databases, the adaptation process often relies on manual analysis, which is costly and error-prone. Summary of the Invention

[0003] To solve the above problems, the present invention provides an automated quality management method based on static code analysis, including the following steps: S1. Establish a static code scanning tool; S2. Determine the static code scanning method and conduct code scanning; S3. Generate a compatibility report and update the rule engine. Among them, the static code scanning tool in the S1 step specifically includes: a code scanning engine, a rule engine, a persistence framework adapter, a problem location module, and a report generation module; the code scanning engine is used to scan static source codes; the rule engine is used to match potential database compatibility problems in static codes; the persistence framework adapter is used to identify and analyze database operation codes generated by common persistence frameworks; the problem location module is used to accurately mark database compatibility problems in codes; the report generation module is used to generate an analysis report and propose code repair suggestions.

[0004] Further, the static code scanning methods in the S2 step include: a local scanning mode and a platform-side scanning mode.

[0005] Further, the local scanning mode specifically includes the following sub-steps: A1. The user starts the static code scanning tool and selects the directory where the static code to be scanned is located; A2. The static code scanning tool loads the static code to be scanned and parses it; A3. Identify and analyze potential database compatibility issues in the static code to be scanned; A4. Identify and analyze the code related to database operations, extract SQL statements and perform compatibility detection; A5. Mark the detected compatibility issues in the static code, generate a compatibility analysis report and provide repair suggestions.

[0006] Further, the platform-side scanning mode specifically includes the following sub-steps: B1. Upload the static code file to be scanned to the cloud platform through the code scanning engine; B2. Synchronize the rule engine with the detection rules in the cloud rule library and perform database compatibility detection; B3. The cloud platform interacts with the persistence framework adapter to identify the code related to database operations in the code, extract SQL statements and perform compatibility detection; B4. Mark the detected compatibility issues in the static code, generate a compatibility analysis report and provide repair suggestions.

[0007] Further, the compatibility analysis report includes the following information: the location of the detected database compatibility issues, a description of the specific situation of the issues, code repair suggestions, the amount of code detected, and the number of potential issues detected.

[0008] Further, the operating environment of the static code scanning tool is the JVM environment.

[0009] The present invention provides an automated quality management method based on static code analysis, which has the following beneficial effects: The present invention provides a dedicated rule engine for domestic database compatibility, which can effectively detect common database migration issues in Xinchuang projects; provides a code scanning method with service-free startup, reduces dependencies and costs, and improves the work efficiency in the adaptation preparation stage; realizes a cloud-based rule library with real-time updates to ensure that the rule engine can meet the ever-changing technical requirements. Description of the Drawings

[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on the structures shown in these drawings.

[0011] Figure 1 It is the flowchart of the method provided by the present invention. Detailed Embodiments

[0012] It should be understood that the specific embodiments described herein are only for explaining the present invention and are not used to limit the present invention.

[0013] The following details the implementation method of the present invention in conjunction with the accompanying drawings. What is described is only a partial embodiment, not all embodiments. For the purpose of clarity, representations and descriptions unrelated to the present invention are omitted in the drawings and the description.

[0014] For a clearer understanding of the technical features, objectives, and beneficial effects of the present invention, the following provides a detailed description of the technical solution of the present invention. Obviously, the described embodiments are a part of the embodiments of the present invention, rather than all embodiments, and should not be construed as a limitation on the scope of implementation of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the protection scope of the present invention.

[0015] As Figure 1 shown, the present invention provides an automated quality management method based on static code analysis, including the following steps: S1. Establish a static code scanning tool; S2. Determine the static code scanning method and perform code scanning; S3. Generate a compatibility report and update the rule engine. The operating environment of the static code scanning tool is the JVM environment.

[0016] Among them, the static code scanning tool in step S1 specifically includes: a code scanning engine, a rule engine, a persistence framework adapter, a problem location module, and a report generation module; the code scanning engine is used to scan the static source code; the rule engine is used to match potential database compatibility problems in the static code; the persistence framework adapter is used to identify and analyze database operation codes generated by common persistence frameworks; the problem location module is used to accurately mark database compatibility problems in the code; the report generation module is used to generate an analysis report and provide code repair suggestions.

[0017] The static code scanning methods in step S2 include: a local scanning mode and a platform-side scanning mode.

[0018] The local scanning mode specifically includes the following sub-steps: A1. The user starts the static code scanning tool and selects the directory where the static code to be scanned is located; A2. The static code scanning tool loads the static code to be scanned and parses it; A3. Identify and analyze potential database compatibility problems in the static code to be scanned; A4. Identify and analyze the code related to database operations, extract SQL statements and perform compatibility detection; A5. Mark the detected compatibility problems in the static code and generate a compatibility analysis report and provide repair suggestions.

[0019] The platform-side scanning mode specifically includes the following sub-steps: B1. Upload the static code file to be scanned to the cloud platform through the code scanning engine; B2. Synchronize the rule engine with the detection rules in the cloud rule library and perform database compatibility detection; B3. The cloud platform interacts with the persistence framework adapter to identify the code related to database operations in the code, extract SQL statements and perform compatibility detection; B4. Mark the detected compatibility issues in the static code and generate a compatibility analysis report and provide repair suggestions.

[0020] The compatibility analysis report includes the following information: the location of the detected database compatibility issues, a detailed description of the problem situation, code repair suggestions, the amount of code detected, and the number of potential problems detected.

[0021] Embodiment: A code analysis tool based on the JVM environment is used to detect database compatibility issues in the code of Xinchuang projects. This tool can run on multiple operating systems and supports two modes: local scanning and platform-side scanning.

[0022] The core components of this tool include: Code scanning engine: Runs in the JVM environment and is responsible for statically scanning the source code. Rule engine: Used to match potential database compatibility issues in the code and supports real-time updates through the cloud. Persistence framework adapter: Responsible for identifying and analyzing database operation codes generated by common persistence frameworks (such as MyBatis, Hibernate, MyBatis Plus). Problem localization module: Used to accurately mark database compatibility issues in the code. Report generation module: Generates an analysis report and provides repair suggestions.

[0023] The local scanning mode runs on the developer's local device, and the steps are as follows: The user starts the code analysis tool installed locally, ensuring that the device has a JVM running environment. Select the code directory of the project, and the tool automatically loads and parses the project files. The tool scans all code files in the project one by one through static code analysis, and calls the rule engine to detect potential database compatibility issues. Using the persistence framework adapter, the tool identifies and analyzes the code related to database operations, extracts SQL statements and performs compatibility detection. The tool marks the detected compatibility issues in the code through the problem localization module. Finally, a compatibility analysis report is generated, listing all the issues and providing detailed repair suggestions to help developers modify the code.

[0024] The platform - side scanning mode is based on the cloud server, and the steps are as follows: The user uploads the project code file to be scanned to the cloud platform through the tool interface. The cloud platform calls a high - performance code scanning engine for code analysis and uses the latest cloud - based rule library for database compatibility detection. The rule engine will automatically synchronize with the cloud - based rule library to ensure that the latest detection rules are used. The platform interacts with the persistence framework adapter to identify database operations related to the persistence framework used in the project, parse and detect whether the generated SQL statements meet the compatibility standards of domestic databases. After the analysis is completed, the platform generates a detailed compatibility report and provides it for the user to download. The report includes all detected compatibility issues and corresponding repair suggestions.

[0025] The tool has a built - in rule engine with specific compatibility detection rules developed for domestic databases (such as DM and KingbaseES). This rule engine supports two update methods: Local update: Developers can manually update the local rule library through the tool. Cloud update: The rule engine is updated in real - time through the cloud to ensure that the latest compatibility rules are used for each scan.

[0026] Whether it is local scanning or platform - side scanning, the tool will generate a detailed compatibility analysis report, which includes the following information: The location of the detected database compatibility issues (accurate to the code line); A specific description of the problem, including why this problem causes incompatibility in domestic databases; Repair suggestions to help developers modify at the problem location to meet the domestic database compatibility requirements; Statistical information, such as the amount of code detected and the number of potential problems detected, so that developers can evaluate the workload.

[0027] The tool supports multiple persistence frameworks, and the specific adaptation process is as follows: The tool identifies the persistence framework used in the project (such as MyBatis, Hibernate, etc.) through the persistence framework adapter; Extracts the code part of the database operation from the persistence framework, including SQL statements and database interaction code.

[0028] In the static code scanning tool provided by the present invention, it is also necessary to add plugin configuration through maven, and its main code is: <plugin> <groupid>com.qm.xinchuang< / groupid> <artifactid>xscan< / artifactid> <version> 1.0.0< / version> <configuration> <!--Scan directory--> <scanpaths> <scanpath>src / main / java / com / xxx / xxx< / scanpath> <scanpath>src / main / resources / mapper< / scanpath> < / scanpaths> <!--token--> <token>xxx.xxx.xxx< / token> <!--Cloud service address--> <xcurl>http: / / xxx.com.cn / < / xcurl> <!--Source database version--> <sourcedb>xxx< / sourcedb> <!--Target database version--> <xcdb>xxx< / xcdb> <!--Whether to enable console output--> <enablelog>true< / enablelog> <!--Number of test methods per day--> <methodstestestimate> 50< / methodstestestimate> <!--Number of problems solved per day--> <problemsolvedestimate> 2< / problemsolvedestimate> < / configuration> < / plugin> 。

[0029] The present invention provides an exclusive rule engine for domestic database compatibility, which can effectively detect common database migration problems in Xinchuang projects; provides a code scanning method for serverless startup, reduces dependencies and costs, and improves the work efficiency in the adaptation preparation stage; realizes a cloud - based rule library with real - time updates to ensure that the rule engine can cope with changing technical requirements.

[0030] The above are only the preferred embodiments of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein, and should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications and environments, and can be changed within the scope of the concept described herein through the above teachings or the technology or knowledge in the relevant field. Any changes and modifications made by those skilled in the art without departing from the spirit and scope of the present invention shall fall within the protection scope of the appended claims of the present invention.

Claims

1. An automated quality management method based on static code analysis, characterized in that It includes the following steps: S1. Establish a static code scanning tool; S2. Determine the static code scanning method and perform code scanning; S3. Generate a compatibility report and update the rule engine; Among them, the static code scanning tool in the S1 step specifically includes: a code scanning engine, a rule engine, a persistence framework adapter, a problem location module, and a report generation module; The code scanning engine is used to scan the static source code; The rule engine is used to match potential database compatibility issues in the static code; The persistence framework adapter is used to identify and analyze database operation code generated by common persistence frameworks; The problem location module is used to accurately mark database compatibility issues in the code; The report generation module is used to generate an analysis report and provide code repair suggestions.

2. The automated quality management method based on static code analysis according to claim 1, characterized in that The static code scanning methods in the S2 step include: local scanning mode, platform-side scanning mode.

3. The automated quality management method based on static code analysis according to claim 2, characterized in that The local scanning mode specifically includes the following sub-steps: A1. The user starts the static code scanning tool and selects the directory where the static code to be scanned is located; A2. The static code scanning tool loads the static code to be scanned and parses it; A3. Identify and analyze potential database compatibility issues in the static code to be scanned; A4. Identify and analyze the code related to database operations, extract SQL statements and perform compatibility detection; A5. Mark the detected compatibility issues in the static code and generate a compatibility analysis report and provide repair suggestions.

4. The automated quality management method based on static code analysis according to claim 2, characterized in that The platform-side scanning mode specifically includes the following sub-steps: B1. Upload the static code file to be scanned to the cloud platform through the code scanning engine; B2. Synchronize the rule engine with the detection rules in the cloud rule library and perform database compatibility detection; B3. The cloud platform interacts with the persistence framework adapter to identify the code related to database operations in the code, extract SQL statements and perform compatibility detection; B4. Mark the detected compatibility issues in the static code and generate a compatibility analysis report and provide repair suggestions.

5. The automated quality management method based on static code analysis according to claim 3 or 4, characterized in that, The compatibility analysis report includes the following information: the location of the detected database compatibility issues; a description of the specific situation of the issues; code repair suggestions; The amount of code detected; the number of potential issues detected.

6. The automated quality management method based on static code analysis according to claim 1, characterized in that The operating environment of the static code scanning tool is the JVM environment.

Citation Information

Patent Citations

  • Static code scanning method and device, equipment and medium

    CN116776335A

  • Data processing method and device, equipment, medium and product

    CN117251374A

  • Database migration method and device for heterogeneous database and medium

    CN119396799A