Information processing device, information processing method, and information processing system

The information processing device addresses the limitations of conventional source code evaluation systems by providing a comprehensive quality assessment of source code through partial and overall evaluation values, leading to improved source code quality and reduced rework.

JP2025078442AActive Publication Date: 2025-05-20SOFTBANK CORPORATION
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2023191013
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-08
Publication Date
2025-05-20
Estimated Expiration
2043-11-08

AI Technical Summary

Technical Problem

Conventional source code evaluation systems only assess code quality based on inspection results and diagnostic history, failing to effectively improve the quality of source code constituting a system under development.

Method used

An information processing device that acquires code information for multiple source codes, calculates partial evaluation values using various evaluation methods, and computes an overall evaluation value based on reference weights, enabling comprehensive quality assessment of source code during the system development process.

Benefits of technology

This approach allows for improved source code quality, reduced rework, and enhanced productivity by providing a comprehensive evaluation of source code quality early in the development process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025078442000001_ABST
    Figure 2025078442000001_ABST
Patent Text Reader

Abstract

To enable improvement in quality of source codes constituting a system of a development object.SOLUTION: An information processing device includes: an acquisition part for acquiring code information about each of a plurality of source codes constituting a system of a development object; and a calculation part for calculating a partial evaluation value being an evaluation value corresponding to each of a plurality of different evaluation methods for evaluating each of the plurality of source codes on the basis of the code information, calculating the total evaluation value being evaluation values each corresponding to the plurality of different evaluation methods for evaluating the system of a development object on the basis of the partial evaluation value, and calculating an overall evaluation value showing overall evaluation to the system of a development object on the basis of reference weight corresponding to each of the plurality of different evaluation methods for evaluating the system of a development object and the total evaluation value.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an information processing device, an information processing method, and an information processing system. [Background technology]

[0002] Conventionally, there are known techniques for evaluating the quality of source code. For example, a source code evaluation system is known that evaluates source code generated for each work process in a design and development project that includes multiple work processes and is developed in a distributed development environment consisting of multiple terminals, and evaluates the quality of the source code based on the inspection results output by a quality inspection means that inspects each source code generated and on diagnostic history information related to the results of inspections that the quality inspection means performed on the source code in the past. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2006-59276 A Summary of the Invention [Problem to be solved by the invention]

[0004] However, in the above-mentioned conventional technology, the quality of the source code is merely evaluated based on the inspection results output by a quality inspection means that performs inspection on each generated source code and diagnostic history information regarding the results of inspections that the quality inspection means performed on the source code in the past, and therefore it is not necessarily possible to improve the quality of the source code that constitutes the system being developed.

[0005] An object of the present application is to provide an information processing device, an information processing method, and an information processing system that can improve the quality of source code that constitutes a system under development. [Means for solving the problem]

[0006] The information processing device of the present application comprises an acquisition unit that acquires code information for each of a plurality of source codes that constitute a system to be developed, and a calculation unit that calculates partial evaluation values, which are evaluation values ​​corresponding to each of a plurality of different evaluation methods for evaluating each of the plurality of source codes based on the code information, calculates an overall evaluation value, which is an evaluation value corresponding to each of a plurality of different evaluation methods for evaluating the system to be developed based on the partial evaluation values, and calculates an overall evaluation value that indicates an overall evaluation of the system to be developed based on reference weights, which are weights corresponding to each of the plurality of different evaluation methods for evaluating the system to be developed, and the overall evaluation value. Effect of the Invention

[0007] According to one aspect of the embodiment, it is possible to improve the quality of source code that constitutes a system to be developed. [Brief description of the drawings]

[0008] [Figure 1] FIG. 1 is a diagram for explaining the system development process. [Diagram 2] FIG. 2 is a diagram illustrating an example of the configuration of an information processing system according to the embodiment. [Diagram 3] FIG. 3 is a diagram illustrating an example of the configuration of the information processing device according to the embodiment. [Figure 4] FIG. 4 is a diagram for explaining a method for calculating a comprehensive evaluation value according to the embodiment. [Diagram 5] FIG. 5 is a diagram illustrating an example of evaluation report information according to the embodiment. [Figure 6] FIG. 6 is a flowchart showing a processing procedure performed by the information processing device according to the embodiment. [Figure 7] FIG. 7 is a hardware configuration diagram illustrating an example of a computer that realizes the functions of the information processing device. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0009] Hereinafter, the information processing device, the information processing method, and the information processing system according to the present application will be described in detail with reference to the drawings. Note that the information processing device, the information processing method, and the information processing system according to the present application are not limited to the embodiments. In addition, the same components in the following embodiments are denoted by the same reference numerals, and duplicated descriptions are omitted.

[0010] (Embodiment) 1. Introduction FIG. 1 is a diagram for explaining the system development process. FIG. 1 shows an example of a system development process that is generally called the waterfall type. Waterfall type system development is divided into multiple processes, such as business requirements definition, system requirements definition, basic design, detailed design, system implementation (production), unit testing, integration testing, comprehensive testing, and user acceptance testing, and each process has a sequence. In this application, the process from business requirements definition to system implementation (production) is called the production process, and the process from unit testing to user acceptance testing is called the test process.

[0011] System development begins with the business requirements definition process. In this process, the system developer listens to the client's business processes that they want to realize through a system, and summarizes the business requirements in a business requirements definition document. Business requirements are summarized from the perspective of what business issues or problems are the background to the need for system development, and what kind of business flow is desired to be realized as the final goal. Business requirements are defined from the perspective of the client or user.

[0012] After the business requirements definition process, the next step is the system requirements definition process. In this process, the system developer puts together the system requirements, such as the functions and performance to be included in the system, in order to realize the contents summarized in the business requirements definition document. System requirements are classified into functional requirements, which define the functions to be implemented, and non-functional requirements, which define the contents that must be met other than functionality, such as performance, stability, and security level.

[0013] Following the system requirements definition process, the next step is the basic design process. In the basic design process, the system developer specifies the functions to be implemented in the system to realize the contents outlined in the system requirements specification document, and compiles them in a basic design document. Basic design is also called external design, and the system developer determines the appearance (external to the system) of the screens used by the client or user from the perspective of the client or user who will actually use the system.

[0014] After the basic design process, the system developer moves on to the detailed design process. In the detailed design process, the system developer creates a detailed design of how the functions to be implemented in the system will be implemented in order to realize the contents of the basic design document, and compiles the design in a detailed design document. Detailed design is also called internal design, and the system developer determines the internal specifications of the system from the developer's perspective.

[0015] After the detailed design process, the next step is system implementation (manufacturing). In the system implementation (manufacturing) process, the system developer programs based on the detailed design document and creates the source code that constitutes the system being developed. The system being developed is created by combining multiple source codes. For example, the source code corresponds to a module, which is a part of a program.

[0016] Furthermore, after the system implementation (manufacturing) process, the next step is the unit testing process. In this process, the system developer verifies whether the program works correctly as a single function. In this process, the modules that are components of the program are tested to see if they function without any problems. In other words, unit testing is a test that checks the quality of the source code. The contents verified in unit testing correspond to the contents of the detailed design document.

[0017] After unit testing, the next step is integration testing, where the system developer combines functions to verify that they work properly. In integration testing, tests are conducted to check the combination of modules together, as well as the integration with external modules. In other words, integration testing is a test that checks the quality of source code that combines source code together, or source code that combines source code corresponding to an external module with source code. The contents verified in integration testing correspond to the contents of the basic design document.

[0018] After integration testing, the next step is comprehensive testing. In this process, the system developer integrates all the functions and verifies that the system works properly. In other words, comprehensive testing is a test that checks the quality of all the integrated source code (i.e., the system being developed). The contents verified in comprehensive testing correspond to the contents of the system requirements specification document.

[0019] After the comprehensive testing process, the next step is the user acceptance testing process. In the user acceptance testing process, the system developer verifies whether the system works properly in the actual operating environment of the client or user. In other words, user acceptance testing is a test that checks the quality of the system being developed in the actual operating environment of the client or user. The contents verified in user acceptance testing correspond to the contents of the business requirements specification document.

[0020] As explained in Figure 1, in the manufacturing process of system development, deliverables such as a business requirements definition document, a system requirements definition document, a basic design document, a detailed design document, and source code are created. At this time, the quality check of the source code, which is the final deliverable in the manufacturing process, is left to each test process (unit test, integration test, comprehensive test, and user acceptance test) in the testing process that follows the system implementation (manufacturing) process. In this way, if a problem is found in the quality of the source code as a result of a quality check of the source code in the testing process that follows the system implementation (manufacturing) process, the system developer will have to go back to the system implementation (manufacturing) process and correct the source code. Furthermore, such rework work can have a significant impact on the progress of system development.

[0021] As explained above, in waterfall-type system development, the system development process is divided into multiple processes that are ordered relative to each other, and the system cannot proceed to the next process until the previous process is completed. This improves the quality of the system, and is therefore considered a development method suitable for systems where the quality of the system is important, such as systems that handle money-related transactions. In system development where the waterfall-type development method is adopted, the emphasis is generally on quality, so system developers improve the overall quality by repeating the process of implementing (manufacturing) the system and the process of testing, and addressing the issues that are discovered one by one. However, in the field of system development, it is often difficult to address all of the issues that are discovered due to the balance between various constraints such as personnel and development time, and in such cases, decisions that may affect the quality of the entire system are often made.

[0022] In response to this, the information processing device according to the embodiment acquires code information on each of a plurality of source codes constituting a system to be developed. The information processing device also calculates partial evaluation values, which are evaluation values ​​corresponding to a plurality of different evaluation methods for evaluating each of the plurality of source codes, based on the code information, calculates an overall evaluation value, which is an evaluation value corresponding to a plurality of different evaluation methods for evaluating the system to be developed, based on the partial evaluation values, and calculates an overall evaluation value indicating an overall evaluation of the system to be developed, based on the reference weights, which are weights corresponding to a plurality of different evaluation methods for evaluating the system to be developed, and the overall evaluation value.

[0023] This allows the information processing device to comprehensively check the quality of the system being developed using a plurality of different evaluation methods, for example, at the stage of the system implementation (manufacturing) process in the system development process. Therefore, the information processing device can improve the quality of the source code constituting the system being developed. Furthermore, since the information processing device can improve the quality of the source code constituting the system being developed at the stage of the system implementation (manufacturing) process, it is possible to prevent rework from the test process after the system implementation (manufacturing) process. Therefore, the information processing device can improve the productivity of the source code constituting the system being developed.

[0024] Furthermore, by preventing rework from the test process to the system implementation (manufacturing) process and improving productivity, developers can allocate the time they would have spent on administrative tasks such as approval processes and meetings to consider response policies at each process to improving the quality of the source code, thereby improving the quality of the entire system. Therefore, the information processing device can improve the quality of the entire system even when it is subject to various constraints such as personnel and development period.

[0025] 2. Configuration of the Information Processing System Fig. 2 is a diagram showing a configuration example of an information processing system according to an embodiment. As shown in Fig. 2, the information processing system 1 according to the embodiment includes a development server 10, a collection server 20, and an information processing device 100. The development server 10, the collection server 20, and the information processing device 100 are connected to each other via a predetermined communication network (network N) so as to be able to communicate with each other via wired or wireless communication.

[0026] The development server 10 is a server that provides a version control system. The development server 10 is used by a system developer. The development server 10 manages the versions (change history) of source code files created by the system developer. The development server 10 stores information about the versions (change history) of source code files and directories in a repository. As the version control system, various systems such as Git, Fossil, and Mercurial can be used.

[0027] The collection server 20 acquires repository list information from the development server 10. The collection server 20 also collects code information on each of a plurality of source codes constituting the system to be developed. Specifically, the collection server 20 collects code information on each of all systems included in the repository list information. For example, the collection server 20 collects, as code information, the latest source code file at a predetermined time from the development server 10 at predetermined time intervals.

[0028] The collection server 20 also collects, as code information, evaluation information of the source code detected by a dedicated tool used to evaluate the source code from the developer's terminal device. The collection server 20 may collect evaluation information of the source code by executing the dedicated tool used to evaluate the source code on the source code file collected from the development server 10.

[0029] For example, the collection server 20 collects, as an example of evaluation information, the number of vulnerabilities pointed out in the source code detected by a dedicated tool used to perform vulnerability diagnosis on the source code. The collection server 20 also collects, as an example of evaluation information, the number of static test findings of the source code detected by a dedicated tool used to perform static testing on the source code. The collection server 20 also collects, as an example of evaluation information, the number of coding rule violations pointed out in the source code detected by a dedicated tool used to perform coding rule violation testing on the source code. The collection server 20 also collects, as an example of evaluation information, the number of inappropriate comments pointed out in the source code detected by a dedicated tool used to perform inappropriate comment testing on the source code. The collection server 20 also collects, as an example of evaluation information, the number of review findings of the source code detected by a dedicated tool used to detect problem points in a code review.

[0030] The collection server 20 also collects, as an example of evaluation information, information that associates information that can identify a person who created source code with the number of lines of source code coded by that person from the development server 10. The collection server 20 also collects, as an example of evaluation information, information that associates information that can identify a person who performed a code review of the source code with the number of lines of source code code reviewed by that person from the development server 10.

[0031] The information processing device 100 acquires code information on each of a plurality of source codes constituting the system to be developed from the collection server 20. The information processing device 100 also calculates partial evaluation values, which are evaluation values ​​corresponding to each of a plurality of different evaluation methods for evaluating each of the plurality of source codes, based on the code information, calculates an overall evaluation value, which is an evaluation value corresponding to each of the plurality of different evaluation methods for evaluating the system to be developed, based on the partial evaluation values, and calculates an overall evaluation value indicating an overall evaluation of the system to be developed, based on the overall evaluation value and standard weights, which are weights corresponding to each of the plurality of different evaluation methods for evaluating the system to be developed.

[0032] 3. Configuration of Information Processing Device 3 is a diagram showing an example of the configuration of an information processing device according to an embodiment. The information processing device 100 according to the embodiment includes a communication unit 110, a storage unit 120, an input unit 130, a display unit 140, and a control unit 150.

[0033] (Communication unit 110) The communication unit 110 is connected to the network N by wire or wirelessly, and transmits and receives information to and from the collection server 20. For example, the communication unit 110 is realized by a NIC (Network Interface Card), an antenna, or the like.

[0034] (Storage unit 120) The storage unit 120 is realized by, for example, a semiconductor memory element such as a random access memory (RAM) or a flash memory, or a storage device such as a hard disk or an optical disk. Specifically, the storage unit 120 stores an information processing program according to the embodiment. The storage unit 120 also stores various pieces of information acquired by the acquisition unit 151. The storage unit 120 also stores various pieces of information calculated by the calculation unit 152. The storage unit 120 also stores various pieces of information generated by the generation unit 153.

[0035] (Input unit 130) The input unit 130 is an input device that accepts various inputs from the outside. The input unit 130 includes an operation device that accepts input operations by a user. The operation device is a device such as a keyboard, a mouse, or an operation key that allows a user to perform various operations. When a touch panel is adopted in the information processing device 100, the touch panel is also included in the operation device. In this case, a user performs various operations by touching the screen with a finger or a stylus.

[0036] (Display section 140) The display unit 140 is a display device that displays various information. The display unit 140 is, for example, a liquid crystal display, an organic EL (Electro Luminescence) display, or the like. Note that, when a touch panel is adopted in the information processing device 100, the display unit 140 may be a device integrated with the operation device of the input unit 130. The display unit 140 displays various information and provides it to the user. In the following description, the display unit 140 may be referred to as a screen. For example, the display unit 140 displays the evaluation report information generated by the generation unit 153 according to the control of the display control unit 154.

[0037] (Control unit 150) The control unit 150 is a controller, and is realized, for example, by a CPU (Central Processing Unit), MPU (Micro Processing Unit), etc., executing various programs stored in a storage device inside the information processing device 100 using a RAM as a working area. The control unit 150 is also a controller, and is realized, for example, by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array).

[0038] The control unit 150 has an acquisition unit 151, a calculation unit 152, a generation unit 153, and a display control unit 154 as functional units, and may realize or execute the information processing action described below. Note that the internal configuration of the control unit 150 is not limited to the configuration shown in FIG. 3, and may be other configurations as long as they perform the information processing described below. Also, each functional unit indicates a function of the control unit 150, and does not necessarily have to be physically distinct.

[0039] (Acquisition part 151) The acquisition unit 151 acquires various information. Specifically, the acquisition unit 151 acquires code information related to each of a plurality of source codes constituting the system to be developed. More specifically, the acquisition unit 151 acquires code information from the collection server 20. For example, the acquisition unit 151 acquires, as the code information, the total number of lines of source code (hereinafter, may be abbreviated as "number of lines of source code") for each source code.

[0040] Furthermore, the acquiring unit 151 acquires, as the code information, the number of points where vulnerabilities have been identified in the source code (hereinafter, may be referred to as the "number of identified vulnerabilities") for each source code as a result of vulnerability diagnosis (also called source code diagnosis) performed on the source code. For example, the acquiring unit 151 acquires the number of identified vulnerabilities detected by a dedicated tool (hereinafter, may be referred to as the "vulnerability diagnosis tool") used to perform vulnerability diagnosis on source code.

[0041] Vulnerability diagnosis may be a process of determining whether or not there is source code that corresponds to a vulnerability or defect published by an industry group such as the Open Worldwide Application Security Project (OWASP), MITRE Corporation, or the Payment Card Industry Data Security Standard (PCI-DSS). For vulnerability diagnosis, an analysis tool that detects the corresponding vulnerability or defect may be used. Specifically, for example, the analysis tool may be a well-known tool such as CppChck, Flawfinder, or Coverity, but is not limited to these, and a person skilled in the art may select an optimal analysis tool based on the purpose of diagnosis, the use of the system, the required quality requirements, etc.

[0042] Furthermore, the acquiring unit 151 acquires, as code information, for each source code, the number of points where problems have been identified in the source code as a result of performing a static test on the source code (hereinafter, may be referred to as the "number of static test findings"). For example, the acquiring unit 151 acquires the number of static test findings detected by a dedicated tool used to perform a static test on the source code.

[0043] Static testing may be a process of determining whether or not there is a syntax error in source code. A syntax check tool may be used for static testing. Specifically, for example, the syntax check tool may be a well-known tool such as Coverity, IntelliJ IDEA, or FindBugs, but is not limited to these. A person skilled in the art may select an optimal analysis tool based on the diagnostic purpose, the use of the system, the required quality requirements, and the like.

[0044] Furthermore, the acquiring unit 151 acquires, as code information, for each source code, the number of locations where coding rule violations have been identified in the source code (hereinafter, may be referred to as the "number of coding rule violations identified") as a result of a test for detecting locations that violate the coding rules on the source code (hereinafter, may be referred to as the "coding rule violation test"). For example, the acquiring unit 151 acquires the number of coding rule violations identified by a dedicated tool used for conducting a coding rule violation test on the source code.

[0045] The coding rule violation test may be a process of judging whether the source code complies with the source code description rules that are predefined for each project. The coding rule may be a rule that is individually formulated for each project. The coding rule may also be a rule that is determined and made public for each programming language by a specific company or organization. Specifically, for example, Google's Java (registered trademark) Style (https: / / checkstyle.sourceforge.io / google_style.html) may be adopted. A coding rule violation test may use a coding rule check tool. Specifically, for example, the coding rule check tool may be a well-known tool such as Checkstyle or PMD, but is not limited thereto. A person skilled in the art may select an optimal analysis tool based on the diagnostic purpose, the use of the system, the required quality requirements, and the like.

[0046] In addition, the acquisition unit 151 acquires, for each source code, the number of locations in the source code where inappropriate comments are pointed out (hereinafter, may be referred to as "inappropriate comment count") as a result of performing a test (hereinafter, may be described as "inappropriate comment test") for detecting locations in the source code where inappropriate comments are attached to the source code. For example, the acquisition unit 151 acquires the inappropriate comment count detected by a dedicated tool used to perform the inappropriate comment test on the source code. The inappropriate comment may be, for example, a comment indicating that the corresponding issue of the source code, such as a comment for marking a part that is an issue recognized by the developer himself / herself or a part to be corrected in the future, is included. Such a comment means that the corresponding issue of the source code is included, and the fact that the comment remains means that the corresponding issue remains without being addressed. Specifically, for example, the acquisition unit 151 acquires the inappropriate comment count detected by a dedicated tool that detects comments with "TODO" or comments with "FIX ME" as inappropriate comments. Note that the inappropriate comments acquired by the acquisition unit 151 are not limited to the above example and can be appropriately selected according to coding rules and the like applied to each development project.

[0047] Furthermore, the acquisition unit 151 acquires, as code information, the number of points where problems have been pointed out in the source code as a result of a code review performed on the source code (hereinafter, may be referred to as the "review number") for each source code. For example, the acquisition unit 151 acquires the review number detected by a dedicated tool used to detect problem points in a code review. For example, the review number may be the number of correction points included in a correction proposal for the review result. Specifically, for example, the review number may be the number of correction points included in a source code proposed in a merge request. Here, a merge request is an example of a function that requests another developer to reflect the addition or correction of code, etc., in the main body of a version control system when a specific developer adds or corrects code, etc. in the main body. In other words, a merge request is an example of a procedure in which a developer other than the specific developer reviews the correction proposed by the specific developer and then reflects it. Note that a merge request may also be called a pull request depending on the version control system.

[0048] Furthermore, the acquiring unit 151 acquires, as the code information, for each source code, the number of lines of source code coded by each person who created the source code. For example, the acquiring unit 151 acquires, for each source code, information that associates information that can identify the person who created the source code with the number of lines of source code coded by that person (hereinafter, this may be referred to as an "evaluation index of personal nature in coding"). Specifically, for example, a commit log made to a version control system may be referenced. Here, a commit is an example of a function that finalizes a change when a change is made to a specific part of source code under development. The commit log includes information about the developer who made the commit and the content changed in the commit, so that it is possible to know who made what amount of changes.

[0049] Furthermore, the acquiring unit 151 acquires, as the code information, the number of code reviews performed by each person who performed a code review on the source code. For example, the acquiring unit 151 may acquire, as the number of code reviews, the number of lines of the source code reviewed by each person. Specifically, for example, the acquiring unit 151 acquires, for each source code, information that associates information that can identify the person who performed the code review on the source code with the number of lines of the source code that were code reviewed by that person (hereinafter, this may be referred to as an "evaluation index of personal nature in code review").

[0050] Also, for example, the number of code reviews may be the number of merge requests made by each person. A merge request includes information for identifying the person who proposed the correction and the contents of the correction proposal made by each person. Generally, a merge request is made for each related correction, so other corrections that are necessary in conjunction with a certain correction can be counted as one correction proposal. Therefore, by aggregating merge requests, the number of substantive code reviews by each person can be identified. In this way, the number of substantive code reviews can be easily grasped.

[0051] The acquisition unit 151 also acquires code information on each of a plurality of source codes constituting a system to be developed corresponding to each of a plurality of systems. For example, the acquisition unit 151 acquires code information on each of all systems managed by the development server 10. For example, the acquisition unit 151 acquires the number of lines of source code for each of all systems managed by the development server 10. The acquisition unit 151 also acquires, for each of all systems managed by the development server 10, the number of vulnerabilities identified, the number of static tests identified, the number of coding rule violations identified, the number of inappropriate comments identified, the number of reviews identified, an evaluation index of personal nature in coding, and an evaluation index of personal nature in code review, for each of the source codes.

[0052] (Calculation unit 152) The calculation unit 152 calculates various information. Specifically, the calculation unit 152 calculates a partial evaluation value that is an evaluation value corresponding to each of a plurality of different evaluation methods for evaluating each of a plurality of source codes, based on the code information. In other words, the calculation unit 152 calculates a partial evaluation value that is an evaluation value corresponding to each of a plurality of different evaluation methods for evaluating a source code, for each source code, based on the code information. More specifically, the calculation unit 152 calculates a partial evaluation value that is an evaluation value corresponding to each of a plurality of different evaluation methods for evaluating the quality of the source code, for each source code. That is, the calculation unit 152 calculates a plurality of different partial evaluation values ​​for each source code. That is, the calculation unit 152 calculates a plurality of different partial evaluation values ​​for each of all source codes constituting the system to be developed.

[0053] For example, the multiple different evaluation methods for evaluating the quality of source code may be at least two of vulnerability diagnosis, static testing, coding rule violation testing, inappropriate comment testing, code review, evaluation of personalities in coding, and evaluation of personalities in code review. In the following, a case will be described in which the multiple different evaluation methods for evaluating the quality of source code are vulnerability diagnosis, static testing, coding rule violation testing, inappropriate comment testing, code review, evaluation of personalities in coding, and evaluation of personalities in code review.

[0054] For example, the calculation unit 152 calculates the vulnerability density in the source code as a partial evaluation value corresponding to the vulnerability diagnosis. For example, the calculation unit 152 calculates the vulnerability density in the source code by dividing the number of vulnerabilities acquired for each source code by the acquisition unit 151 by the number of lines of the source code.

[0055] In addition, the calculation unit 152 calculates the static test indication density in the source code as a partial evaluation value corresponding to the static test. For example, the calculation unit 152 calculates the static test indication density in the source code by dividing the number of static test indications acquired for each source code by the acquisition unit 151 by the number of lines of the source code.

[0056] Furthermore, the calculation unit 152 calculates the coding rule violation detection density in the source code as a partial evaluation value corresponding to the coding rule violation test. For example, the calculation unit 152 calculates the coding rule violation detection density in the source code by dividing the number of coding rule violation detections acquired for each source code by the acquisition unit 151 by the number of lines of the source code.

[0057] In addition, the calculation unit 152 calculates the density of inappropriate comments in the source code as a partial evaluation value corresponding to the inappropriate comment test. For example, the calculation unit 152 calculates the density of inappropriate comments in the source code by dividing the number of inappropriate comments acquired for each source code by the acquisition unit 151 by the number of lines of the source code.

[0058] Furthermore, the calculation unit 152 calculates a review indication rate in the source code as a partial evaluation value corresponding to the code review. For example, the calculation unit 152 calculates the review indication rate in the source code by dividing the number of review indications acquired for each source code by the acquisition unit 151 by the number of lines of the source code.

[0059] Furthermore, the calculation unit 152 calculates a ratio indicating how much coding each person did in the source code as a partial evaluation value corresponding to the evaluation of the personal nature of coding. For example, the calculation unit 152 calculates the ratio of the amount of coding for each person in the source code by dividing the evaluation index of the personal nature of coding for each person acquired for each source code by the acquisition unit 151 by the number of lines of the source code. Next, the calculation unit 152 determines that the largest ratio of the amount of coding for each person in the source code is to be the personal ratio of the amount of coding for the source code.

[0060] For example, suppose that three people, namely, persons A to C, have coded source code. Also, suppose that, of 100 lines of source code, the number of lines of source code coded by person A is 80 lines, the number of lines of source code coded by person B is 15 lines, and the number of lines of source code coded by person C is 5 lines. In this case, the calculation unit 152 calculates that the percentage of the amount of coding by person A is 80%, the percentage of the amount of coding by person B is 15%, and the percentage of the amount of coding by person C is 5%. Next, the calculation unit 152 determines that the largest percentage of the amount of coding by each person in the source code, 80%, is set as the personal percentage of the amount of coding in the source code. For example, since the personal percentage of the amount of coding in the source code is relatively large at 80%, it can be seen that the amount of coding is biased toward a specific person. In general, if the personal percentage of the amount of coding is large, for example, when a person with a large percentage of the amount of coding is no longer present, it may be difficult to correct the source code. Therefore, it is considered that a large proportion of the coding amount that depends on individuals is more likely to have a negative impact on the quality of the source code than a small proportion of the coding amount that depends on individuals.

[0061] Furthermore, the calculation unit 152 calculates a ratio indicating how much code review was performed by which person in the source code as a partial evaluation value corresponding to the evaluation of personal nature in the code review. For example, the calculation unit 152 calculates the ratio of the code review amount for each person in the source code by dividing the evaluation index of personal nature in the code review for each person acquired for each source code by the acquisition unit 151 by the number of lines of the source code. Next, the calculation unit 152 determines that the largest ratio of the code review amount among the ratios of the code review amount for each person in the source code is to be the personal ratio of the code review amount for the source code.

[0062] For example, assume that three persons D to F have performed code reviews on a source code. In addition, assume that, of 100 lines of source code, the number of lines of source code that have been code reviewed by person D is 80 lines, the number of lines of source code that have been code reviewed by person E is 15 lines, and the number of lines of source code that have been code reviewed by person F is 5 lines. In this case, the calculation unit 152 calculates the percentage of the amount of code review by person D to be 80%, the percentage of the amount of code review by person E to be 15%, and the percentage of the amount of code review by person F to be 5%. Next, the calculation unit 152 determines that the percentage of the amount of code review that is the largest among the percentages of the amount of code review for each person in the source code, 80%, is set as the personal percentage of the amount of code review for the source code. For example, since the personal percentage of the amount of code review for the source code is relatively large at 80%, it can be seen that the amount of code review is biased toward a specific person. In general, when the personal percentage of the amount of code review is high, for example, the source code may be evaluated in a biased manner toward the evaluation of a person with a high percentage of the amount of code review. Therefore, it is considered that a high degree of personal dependency in the amount of code review is more likely to have a negative impact on source code quality than a low degree of personal dependency in the amount of code review.

[0063] Furthermore, the calculation unit 152 calculates an overall evaluation value, which is an evaluation value corresponding to each of a plurality of different evaluation methods for evaluating the system to be developed, based on the partial evaluation values. Specifically, the calculation unit 152 calculates a first overall evaluation value based on the partial evaluation values. For example, the calculation unit 152 calculates an average value of the partial evaluation values ​​in the system to be developed as the first overall evaluation value. In other words, the calculation unit 152 calculates a value obtained by dividing the sum of the partial evaluation values ​​of all source codes constituting the system to be developed by the total number of source codes included in the system to be developed as the first overall evaluation value.

[0064] Here, the multiple different evaluation methods for evaluating the quality of the system to be developed are the same as the multiple different evaluation methods for evaluating the quality of the source code. For example, the multiple different evaluation methods for evaluating the quality of the system to be developed may be at least two or more evaluation methods among vulnerability diagnosis, static testing, coding rule violation testing, inappropriate comment testing, code review, evaluation of personalities in coding, or evaluation of personalities in code review.

[0065] In the following, a case will be described in which the multiple different evaluation methods for evaluating the quality of a system to be developed are vulnerability diagnosis, static testing, coding rule violation testing, inappropriate comment testing, code review, evaluation of personal characteristics in coding, and evaluation of personal characteristics in code review. That is, the calculation unit 152 calculates a first overall evaluation value corresponding to each of the vulnerability diagnosis, static testing, coding rule violation testing, inappropriate comment testing, code review, evaluation of personal characteristics in coding, and evaluation of personal characteristics in code review.

[0066] For example, the calculation unit 152 calculates an average value of the vulnerability detection density in the system under development as a first overall evaluation value corresponding to the vulnerability diagnosis. For example, the calculation unit 152 calculates the average value of the vulnerability detection density in the system under development by dividing the sum of the vulnerability detection densities in all source codes constituting the system under development by the total number of source codes included in the system under development.

[0067] Furthermore, the calculation unit 152 calculates an average value of the static test finding density in the system under development as a first overall evaluation value corresponding to the static tests. For example, the calculation unit 152 calculates the average value of the static test finding density in the system under development by dividing the sum of the static test finding densities in all source codes constituting the system under development by the total number of source codes included in the system under development.

[0068] Furthermore, the calculation unit 152 calculates an average value of the coding rule violation detection density in the system under development as a first overall evaluation value corresponding to the coding rule violation test. For example, the calculation unit 152 calculates the average value of the coding rule violation detection density in the system under development by dividing the sum of the coding rule violation detection densities in all source codes constituting the system under development by the total number of source codes included in the system under development.

[0069] Furthermore, the calculation unit 152 calculates an average value of the density of inappropriate comments in the system to be developed as a first overall evaluation value corresponding to the inappropriate comment test. For example, the calculation unit 152 calculates the average value of the density of inappropriate comments in the system to be developed by dividing the sum of the densities of inappropriate comments in all source codes constituting the system to be developed by the total number of source codes included in the system to be developed.

[0070] Furthermore, the calculation unit 152 calculates an average value of the review indication rates in the system under development as a first overall evaluation value corresponding to the code reviews. For example, the calculation unit 152 calculates the average value of the review indication rates in the system under development by dividing the sum of the review indication rates in all source codes constituting the system under development by the total number of source codes included in the system under development.

[0071] Furthermore, the calculation unit 152 calculates an average value of the personal ratio of the amount of coding in the system to be developed as a first overall evaluation value corresponding to the evaluation of the personal nature of the coding. For example, the calculation unit 152 calculates the average value of the personal ratio of the amount of coding in the system to be developed by dividing the sum of the personal ratios of the amount of coding in all source codes constituting the system to be developed by the total number of source codes included in the system to be developed.

[0072] Furthermore, the calculation unit 152 calculates an average value of the personal ratio of the amount of code review in the system under development as a first overall evaluation value corresponding to the evaluation of the personal nature of the code review. For example, the calculation unit 152 calculates the average value of the personal ratio of the amount of code review in the system under development by dividing the sum of the personal ratios of the amount of code review in all source codes constituting the system under development by the total number of source codes included in the system under development.

[0073] Furthermore, the acquiring unit 151 acquires repository list information from the collection server 20. Next, the acquiring unit 151 acquires code information for each of all systems (hereinafter, may be referred to as "all systems") included in the repository list information. Next, the calculation unit 152 calculates a partial evaluation value for each of all systems based on the code information for each of all systems, and calculates a first overall evaluation value for each of all systems based on the partial evaluation value for each of all systems. Next, the calculation unit 152 calculates a representative value of the first overall evaluation values ​​for all systems based on the first overall evaluation values ​​for each of all systems. For example, the calculation unit 152 calculates a median of the first overall evaluation values ​​for all systems as the representative value.

[0074] Moreover, the calculation unit 152 calculates a second overall evaluation value based on the first overall evaluation value. The calculation unit 152 calculates a second overall evaluation value corresponding to each of a plurality of different evaluation methods for evaluating the quality of the system to be developed based on the first overall evaluation value corresponding to each of a plurality of different evaluation methods for evaluating the quality of the system to be developed. For example, the calculation unit 152 calculates a second overall evaluation value corresponding to the vulnerability diagnosis based on the first overall evaluation value corresponding to the vulnerability diagnosis. The calculation unit 152 also calculates a second overall evaluation value corresponding to the static test based on the first overall evaluation value corresponding to the static test. The calculation unit 152 also calculates a second overall evaluation value corresponding to the coding rule violation test based on the first overall evaluation value corresponding to the coding rule violation test. The calculation unit 152 also calculates a second overall evaluation value corresponding to the inappropriate comment test based on the first overall evaluation value corresponding to the inappropriate comment test. The calculation unit 152 also calculates a second overall evaluation value corresponding to the code review based on the first overall evaluation value corresponding to the code review. Furthermore, the calculation unit 152 calculates a second overall evaluation value corresponding to the personal evaluation in coding based on the first overall evaluation value corresponding to the personal evaluation in coding. Furthermore, the calculation unit 152 calculates a second overall evaluation value corresponding to the personal evaluation in code review based on the first overall evaluation value corresponding to the personal evaluation in code review.

[0075] More specifically, the calculation unit 152 calculates a second overall evaluation value for the system based on a comparison between a representative value of the first overall evaluation values ​​for the multiple systems and the first overall evaluation value for the system. For example, the calculation unit 152 calculates a second overall evaluation value for the system based on a comparison between a median value of the first overall evaluation values ​​for the multiple systems and the first overall evaluation value for the system as a representative value. For example, the calculation unit 152 calculates the second overall evaluation value for the system based on a comparison between the median value of the first overall evaluation values ​​for all systems and the first overall evaluation value for the system.

[0076] For example, the calculation unit 152 calculates how many times the first overall evaluation value in the system is the median of the first overall evaluation values ​​in the multiple systems. In other words, the calculation unit 152 calculates a value obtained by dividing the first overall evaluation value in the system by the median of the first overall evaluation values ​​in the multiple systems (hereinafter, may be referred to as a "first relative evaluation value"). Next, the calculation unit 152 determines whether the first relative evaluation value is equal to or less than a first threshold value (e.g., 0.5, etc.). When the calculation unit 152 determines that the first relative evaluation value is equal to or less than the first threshold value, it determines the second overall evaluation value to be, for example, 100 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the first relative evaluation value. For example, the calculation unit 152 determines the second overall evaluation value to be a larger value as the first relative evaluation value becomes smaller. For example, the calculation section 152 determines the second overall evaluation value to be a larger value within the range of 71 to 100 points as the first relative evaluation value is smaller.

[0077] Furthermore, when the calculation unit 152 determines that the first relative evaluation value exceeds the first threshold, the calculation unit 152 determines whether the first relative evaluation value is equal to or less than a second threshold (for example, 1.0). When the calculation unit 152 determines that the first relative evaluation value is equal to or less than the second threshold, the calculation unit 152 determines the second overall evaluation value to be, for example, 70 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the first relative evaluation value. For example, the smaller the first relative evaluation value is, the larger the second overall evaluation value is determined to be. For example, the smaller the first relative evaluation value is, the larger the second overall evaluation value is determined to be within a range of 31 to 70 points.

[0078] Furthermore, when the calculation unit 152 determines that the first relative evaluation value exceeds the second threshold, the calculation unit 152 determines whether the first relative evaluation value is equal to or less than a third threshold (for example, 1.5). When the calculation unit 152 determines that the first relative evaluation value is equal to or less than the third threshold, the calculation unit 152 determines the second overall evaluation value to be, for example, 30 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the first relative evaluation value. For example, the smaller the first relative evaluation value is, the larger the second overall evaluation value is determined to be. For example, the smaller the first relative evaluation value is, the larger the second overall evaluation value is determined to be within the range of 11 to 30 points.

[0079] Furthermore, when the calculation unit 152 determines that the first relative evaluation value exceeds the third threshold, it determines the second overall evaluation value to be, for example, 10 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the first relative evaluation value. For example, the smaller the first relative evaluation value, the larger the second overall evaluation value that the calculation unit 152 determines to be. For example, the smaller the first relative evaluation value, the larger the second overall evaluation value that the calculation unit 152 determines to be within the range of 0 to 10 points.

[0080] Instead of the median of the first overall evaluation values ​​in the multiple systems, the calculation unit 152 may calculate the second overall evaluation value in the system based on a comparison between the mode of the first overall evaluation values ​​in the multiple systems and the first overall evaluation value in the system. For example, the calculation unit 152 calculates the mode of the first overall evaluation values ​​in all systems as a representative value. Furthermore, the calculation unit 152 calculates the second overall evaluation value in the system based on a comparison between the mode of the first overall evaluation values ​​in all systems and the first overall evaluation value in the system.

[0081] Furthermore, instead of the median of the first overall evaluation values ​​of a plurality of systems, the calculation unit 152 may calculate a second overall evaluation value of the system based on a comparison between a reference value determined based on the first overall evaluation values ​​of past development cases and the first overall evaluation value of the system. For example, the calculation unit 152 may refer to the first overall evaluation values ​​of past development cases and determine the reference value based on 25% of the highest evaluation values. Furthermore, the calculation unit 152 may show the reference value to the developer of the system to be developed and then accept a correction of the reference value. Furthermore, the calculation unit 152 may show the first overall evaluation value of past development cases to the developer of the system to be developed and then accept a correction of the reference value.

[0082] Here, the quality required may differ depending on the system to be developed. Specifically, for example, a system used for a task that handles money or personal information may require high quality, whereas a system used for a task that does not handle such information may require less high quality. When managing development cases with different required quality in this way, if a standard value is determined uniformly based on all past development cases, problems may arise in that the standard value is insufficient for cases requiring high quality and excessive for cases requiring less high quality.

[0083] In contrast, the calculation unit 152 may calculate a second overall evaluation value in the system based on a comparison between a reference value determined based on the first overall evaluation value of past development cases of the same type as the current development target and the first overall evaluation value in the system, instead of the median value of the first overall evaluation values ​​in the multiple systems. Specifically, for example, the storage unit 120 holds quality parameters indicating the required quality for each development case. The calculation unit 152 may obtain the first overall evaluation value for a development case having the same type of quality parameter as the current development target and determine the reference value. For example, the quality parameter may be a step-by-step evaluation method such as a numerical value or an alphabet. Also, for example, the quality parameter may be a tag method indicating the use of the target system, such as money processing or personal information processing. For example, the quality parameter may be determined by the development manager. The reference value may be a value previously determined for each quality parameter.

[0084] For example, the calculation unit 152 calculates how many times the first overall evaluation value in the system is the most frequent value of the first overall evaluation value in the multiple systems. In other words, the calculation unit 152 calculates a value obtained by dividing the first overall evaluation value in the system by the most frequent value of the first overall evaluation value in the multiple systems (hereinafter, may be referred to as a "second relative evaluation value"). Next, the calculation unit 152 determines whether the second relative evaluation value is equal to or less than a fourth threshold value (e.g., 0.5, etc.). When the calculation unit 152 determines that the second relative evaluation value is equal to or less than the fourth threshold value, it determines the second overall evaluation value to be, for example, 100 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the second relative evaluation value. For example, the calculation unit 152 determines the second overall evaluation value to be a larger value as the second relative evaluation value becomes smaller. For example, the calculation section 152 determines the second overall evaluation value to be a larger value within the range of 71 to 100 points as the second relative evaluation value is smaller.

[0085] Furthermore, when the calculation unit 152 determines that the second relative evaluation value exceeds the fourth threshold, the calculation unit 152 determines whether the second relative evaluation value is equal to or less than a fifth threshold (for example, 1.0). When the calculation unit 152 determines that the second relative evaluation value is equal to or less than the fifth threshold, the calculation unit 152 determines the second overall evaluation value to be, for example, 70 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the second relative evaluation value. For example, the smaller the second relative evaluation value is, the larger the second overall evaluation value is determined to be. For example, the smaller the second relative evaluation value is, the larger the second overall evaluation value is determined to be within the range of 31 to 70 points.

[0086] Furthermore, when the calculation unit 152 determines that the second relative evaluation value exceeds the fifth threshold, the calculation unit 152 determines whether the second relative evaluation value is equal to or less than a sixth threshold (for example, 1.5). When the calculation unit 152 determines that the second relative evaluation value is equal to or less than the sixth threshold, the calculation unit 152 determines the second overall evaluation value to be, for example, 30 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the second relative evaluation value. For example, the smaller the second relative evaluation value is, the larger the second overall evaluation value is determined to be. For example, the smaller the second relative evaluation value is, the larger the second overall evaluation value is determined to be within the range of 11 to 30 points.

[0087] Furthermore, when the calculation unit 152 determines that the second relative evaluation value exceeds the sixth threshold, it determines the second overall evaluation value to be, for example, 10 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the second relative evaluation value. For example, the smaller the second relative evaluation value is, the larger the second overall evaluation value is determined to be. For example, the smaller the second relative evaluation value is, the larger the second overall evaluation value is determined to be within the range of 0 to 10 points.

[0088] Furthermore, the calculation unit 152 may determine the second overall evaluation value for the system based on the first overall evaluation value for the system, instead of calculating the second overall evaluation value for the system based on a comparison between a representative value of the first overall evaluation values ​​for a plurality of systems and the first overall evaluation value for the system. For example, when the first overall evaluation value for the system is the first overall evaluation value corresponding to an evaluation of personal nature in coding or the first overall evaluation value corresponding to an evaluation of personal nature in a code review, the calculation unit 152 determines the second overall evaluation value for the system based on the first overall evaluation value for the system.

[0089] For example, the calculation unit 152 determines whether the first overall evaluation value is equal to or less than a seventh threshold (for example, 50%). When the calculation unit 152 determines that the first overall evaluation value is equal to the seventh threshold, the calculation unit 152 determines the second overall evaluation value to be, for example, 100 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the first overall evaluation value. For example, the smaller the first overall evaluation value is, the larger the second overall evaluation value is determined to be. For example, the smaller the first overall evaluation value is, the larger the second overall evaluation value is determined to be within the range of 71 to 100 points.

[0090] Furthermore, when the calculation unit 152 determines that the first overall evaluation value exceeds the seventh threshold, the calculation unit 152 determines whether the first overall evaluation value is equal to or less than an eighth threshold (for example, 75%). When the calculation unit 152 determines that the first overall evaluation value is equal to or less than the eighth threshold, the calculation unit 152 determines the second overall evaluation value to be, for example, 70 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the first overall evaluation value. For example, the smaller the first overall evaluation value is, the larger the second overall evaluation value is determined to be. For example, the smaller the first overall evaluation value is, the larger the second overall evaluation value is determined to be within the range of 31 to 70 points.

[0091] Furthermore, when the calculation unit 152 determines that the first overall evaluation value exceeds the eighth threshold, the calculation unit 152 determines whether the first overall evaluation value is equal to or less than a ninth threshold (for example, 90%). When the calculation unit 152 determines that the first overall evaluation value is equal to or less than the ninth threshold, the calculation unit 152 determines the second overall evaluation value to be, for example, 30 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the first overall evaluation value. For example, the smaller the first overall evaluation value is, the larger the second overall evaluation value is determined to be. For example, the smaller the first overall evaluation value is, the larger the second overall evaluation value is determined to be within the range of 11 to 30 points.

[0092] Furthermore, when the calculation unit 152 determines that the first overall evaluation value exceeds the ninth threshold, it determines the second overall evaluation value to be, for example, 10 points. Note that the calculation unit 152 may determine the second overall evaluation value according to the magnitude of the first overall evaluation value. For example, the smaller the first overall evaluation value is, the larger the second overall evaluation value is determined to be. For example, the smaller the first overall evaluation value is, the larger the second overall evaluation value is determined to be within the range of 0 to 10 points.

[0093] Furthermore, the calculation unit 152 determines a second overall evaluation corresponding to the second overall evaluation value based on the second overall evaluation value. For example, when the second overall evaluation value is 71 points or more, the calculation unit 152 determines the second overall evaluation to be "A". When the second overall evaluation value is 31 points or more, the calculation unit 152 determines the second overall evaluation to be "B". When the second overall evaluation value is 11 points or more, the calculation unit 152 determines the second overall evaluation to be "C". When the second overall evaluation value is 10 points or less, the calculation unit 152 determines the second overall evaluation to be "D".

[0094] Furthermore, the calculation unit 152 calculates an overall evaluation value indicating an overall evaluation of the system to be developed based on the standard weights, which are weights corresponding to each of the multiple different evaluation methods for evaluating the system to be developed, and the overall evaluation values ​​corresponding to each of the multiple different evaluation methods for evaluating the system to be developed. Specifically, the calculation unit 152 calculates the overall evaluation value based on the standard weights, which are weights corresponding to each of the multiple different evaluation methods for evaluating the system to be developed, and the second overall evaluation values ​​corresponding to each of the multiple different evaluation methods for evaluating the system to be developed. More specifically, the calculation unit 152 calculates the sum of the weighted evaluation values, which are values ​​obtained by multiplying the standard weights and the second overall evaluation value, as the overall evaluation value.

[0095] For example, the calculation unit 152 calculates a weighted evaluation value obtained by multiplying a standard weight corresponding to a vulnerability diagnosis by a second overall evaluation value corresponding to the vulnerability diagnosis (hereinafter, this may be referred to as a "weighted evaluation value corresponding to a vulnerability diagnosis"). The calculation unit 152 also calculates a weighted evaluation value obtained by multiplying a standard weight corresponding to a static test by a second overall evaluation value corresponding to the static test (hereinafter, this may be referred to as a "weighted evaluation value corresponding to a static test"). The calculation unit 152 also calculates a weighted evaluation value obtained by multiplying a standard weight corresponding to a coding rule violation test by a second overall evaluation value corresponding to the coding rule violation test (hereinafter, this may be referred to as a "weighted evaluation value corresponding to a coding rule violation test"). The calculation unit 152 also calculates a weighted evaluation value obtained by multiplying a standard weight corresponding to an inappropriate comment test by a second overall evaluation value corresponding to the inappropriate comment test (hereinafter, this may be referred to as a "weighted evaluation value corresponding to an inappropriate comment test").

[0096] The calculation unit 152 also calculates a weighted evaluation value (hereinafter, may be referred to as a "weighted evaluation value corresponding to the code review") obtained by multiplying a standard weight corresponding to the code review by a second overall evaluation value corresponding to the code review. The calculation unit 152 also calculates a weighted evaluation value (hereinafter, may be referred to as a "weighted evaluation value corresponding to the evaluation of the personal nature of coding") obtained by multiplying a standard weight corresponding to the evaluation of the personal nature of coding by a second overall evaluation value corresponding to the evaluation of the personal nature of coding. The calculation unit 152 also calculates a weighted evaluation value (hereinafter, may be referred to as a "weighted evaluation value corresponding to the evaluation of the personal nature of coding") obtained by multiplying a standard weight corresponding to the evaluation of the personal nature of coding by a second overall evaluation value corresponding to the evaluation of the personal nature of coding.

[0097] Fig. 4 is a diagram for explaining a method for calculating a comprehensive evaluation value according to an embodiment. Fig. 4 shows a case where a plurality of different evaluation methods for evaluating a system to be developed are vulnerability diagnosis, static testing, coding rule violation testing, inappropriate comment testing, code review, evaluation of personalities in coding, and evaluation of personalities in code review.

[0098] In Fig. 4, the calculation unit 152 calculates an overall evaluation value by making a standard weight corresponding to an evaluation method related to vulnerability among a plurality of different evaluation methods for evaluating a system to be developed larger than standard weights corresponding to other evaluation methods. In Fig. 4, as an example of an evaluation method related to vulnerability, a standard weight of "0.35" corresponding to vulnerability diagnosis is larger than standard weights corresponding to other evaluation methods. In this case, the calculation unit 152 calculates a weighted evaluation value corresponding to the vulnerability diagnosis by multiplying the standard weight "0.35" corresponding to the vulnerability diagnosis by the second overall evaluation value corresponding to the vulnerability diagnosis.

[0099] Furthermore, the calculation unit 152 calculates the overall evaluation value by making the standard weight corresponding to the evaluation method related to the static test the next largest after the standard weight corresponding to the evaluation method related to the vulnerability. In Fig. 4, as an example of the evaluation method related to the static test, the standard weight "0.25" corresponding to the static test is the next largest after the standard weight "0.35" corresponding to the vulnerability diagnosis. In this case, the calculation unit 152 calculates the weighted evaluation value corresponding to the static test by multiplying the standard weight "0.25" corresponding to the static test by the second overall evaluation value corresponding to the static test, as an example of the evaluation method related to the static test.

[0100] Furthermore, the calculation unit 152 calculates the overall evaluation value by making the standard weight corresponding to the evaluation method for inappropriate comments in the code review the second largest after the standard weight corresponding to the evaluation method for the static test. In Fig. 4, the standard weight "0.15" corresponding to the inappropriate comment test, which is an example of the evaluation method for inappropriate comments in the code review, is the second largest after the standard weight "0.25" corresponding to the static test. At this time, the calculation unit 152 calculates the weighted evaluation value corresponding to the inappropriate comment test by multiplying the standard weight "0.15" corresponding to the inappropriate comment test, which is an example of the evaluation method for inappropriate comments in the code review, by the second overall evaluation value corresponding to the inappropriate comment test.

[0101] Furthermore, the calculation unit 152 calculates the overall evaluation value by making the standard weight corresponding to the evaluation method related to the code review the second largest after the standard weight corresponding to the evaluation method related to the inappropriate comments. In Fig. 4, as an example of the evaluation method related to the code review, the standard weight "0.10" corresponding to the code review is the second largest after the standard weight "0.15" corresponding to the inappropriate comment test. At this time, the calculation unit 152 calculates the weighted evaluation value corresponding to the code review by multiplying the standard weight "0.10" corresponding to the code review by the second overall evaluation value corresponding to the code review as an example of the evaluation method related to the code review.

[0102] Furthermore, as an example of an evaluation method for coding convention violations, the calculation unit 152 calculates a weighted evaluation value corresponding to the coding convention violation test by multiplying the reference weight "0.05" corresponding to the coding convention violation test by the second overall evaluation value corresponding to the coding convention violation test.

[0103] Furthermore, as an example of a method for evaluating the personal nature of the coding, the calculation unit 152 calculates a weighted evaluation value corresponding to the evaluation of the personal nature of the coding by multiplying the standard weight "0.05" corresponding to the evaluation of the personal nature of the coding by the second overall evaluation value corresponding to the evaluation of the personal nature of the coding.

[0104] In addition, as an example of an evaluation method for personal nature in the code review, the calculation unit 152 calculates a weighted evaluation value corresponding to the evaluation of personal nature in the code review by multiplying “0.05”, which is a standard weight corresponding to the evaluation of personal nature in the code review, by a second overall evaluation value corresponding to the evaluation of personal nature in the code review.

[0105] In addition, the calculation unit 152 calculates an overall evaluation value as the sum of a weighted evaluation value corresponding to the vulnerability diagnosis, a weighted evaluation value corresponding to the static test, a weighted evaluation value corresponding to the coding convention violation test, a weighted evaluation value corresponding to the inappropriate comment test, a weighted evaluation value corresponding to the code review, a weighted evaluation value corresponding to the evaluation of personal characteristics in coding, and a weighted evaluation value corresponding to the evaluation of personal characteristics in the code review.

[0106] Furthermore, the calculation unit 152 determines an overall evaluation corresponding to the overall evaluation value based on the overall evaluation value. In Fig. 4, when the overall evaluation value is 90 points or more, the calculation unit 152 determines the overall evaluation to be "A". When the overall evaluation value is 50 points or more, the calculation unit 152 determines the overall evaluation to be "B". When the overall evaluation value is 30 points or more, the calculation unit 152 determines the overall evaluation to be "C". When the overall evaluation value is less than 30 points, the calculation unit 152 determines the overall evaluation to be "D".

[0107] As described above, the calculation unit 152 calculates the overall evaluation value based on a comparison between a representative value of the overall evaluation values ​​in a plurality of systems and the overall evaluation value in the system. Specifically, the calculation unit 152 calculates the overall evaluation value based on a comparison between a median or a mode of the overall evaluation values ​​in the plurality of systems as a representative value and the overall evaluation value in the system. For example, the calculation unit 152 determines a second overall evaluation value based on a comparison between a representative value of the first overall evaluation values ​​in the plurality of systems and the first overall evaluation value in the system. In addition, the calculation unit 152 calculates the overall evaluation value based on the second overall evaluation value. Specifically, the calculation unit 152 calculates a weighted evaluation value, which is a value obtained by multiplying the standard weight by the second overall evaluation value, and calculates the sum of the weighted evaluation values ​​as the overall evaluation value.

[0108] (Generation unit 153) The generating unit 153 generates various information. Specifically, the generating unit 153 generates evaluation report information that visualizes an evaluation of the system under development based on the overall evaluation value and the comprehensive evaluation value calculated by the calculating unit 152. For example, the generating unit 153 generates evaluation report information that visualizes an overall evaluation based on the comprehensive evaluation value calculated by the calculating unit 152. The generating unit 153 also generates evaluation report information that visualizes a second overall evaluation based on the second overall evaluation value calculated by the calculating unit 152.

[0109] FIG. 5 is a diagram illustrating an example of evaluation report information according to an embodiment. In FIG. 5, the generating unit 153 generates evaluation report information in which a comprehensive evaluation "B" based on the comprehensive evaluation value calculated by the calculating unit 152 is visualized. The generating unit 153 also generates evaluation report information in which a second overall evaluation "B" corresponding to the vulnerability diagnosis calculated by the calculating unit 152 is visualized. The generating unit 153 also generates evaluation report information in which a second overall evaluation "A" corresponding to the static test calculated by the calculating unit 152 is visualized. The generating unit 153 also generates evaluation report information in which a second overall evaluation "A" corresponding to the coding rule violation test calculated by the calculating unit 152 is visualized. The generating unit 153 also generates evaluation report information in which a second overall evaluation "A" corresponding to the inappropriate comment test calculated by the calculating unit 152 is visualized. Although not shown in the figure, the generation unit 153 generates evaluation report information that visualizes the second overall evaluation corresponding to the code review calculated by the calculation unit 152, the second overall evaluation corresponding to the evaluation of personal nature in coding, and the second overall evaluation corresponding to the evaluation of personal nature in code review.

[0110] Furthermore, the generating unit 153 generates evaluation report information that visualizes the evaluation included in the evaluation report information generated a predetermined period ago. For example, the generating unit 153 generates evaluation report information that visualizes the second overall evaluation included in the evaluation report information generated in "March 2023", three months before "June 2023", when the current evaluation report information was generated.

[0111] (Display control unit 154) The display control unit 154 causes the display unit 140 to display the evaluation report information generated by the generation unit 153. Specifically, the display control unit 154 refers to the storage unit 120 and acquires the evaluation report information generated by the generation unit 153. Then, the display control unit 154 causes the display unit 140 to display the acquired evaluation report information.

[0112] 4. Processing Procedure Fig. 6 is a flowchart showing a processing procedure by the information processing device according to the embodiment. In Fig. 6, the acquisition unit 151 of the information processing device 100 acquires code information on each of a plurality of source codes constituting a system to be developed (step S101).

[0113] Furthermore, the calculation unit 152 of the information processing device 100 calculates partial evaluation values, which are evaluation values ​​corresponding to the different evaluation methods for evaluating the different source codes, based on the code information (step S102). Next, the calculation unit 152 calculates an overall evaluation value, which is an evaluation value corresponding to the different evaluation methods for evaluating the system to be developed, based on the partial evaluation values ​​(step S103). Next, the calculation unit 152 calculates an overall evaluation value indicating an overall evaluation of the system to be developed, based on the reference weights, which are weights corresponding to the different evaluation methods for evaluating the system to be developed, and the overall evaluation value (step S104).

[0114] Furthermore, the generating unit 153 of the information processing device 100 generates evaluation report information that visualizes the evaluation of the system under development based on the overall evaluation value and the comprehensive evaluation value (Step S105).

[0115] 5. Modifications In the above-described embodiment, the calculation unit 152 calculates the sum of the partial evaluation values ​​of all source codes constituting the system under development divided by the total number of source codes included in the system under development as the first overall evaluation value. In the modified example, the calculation unit 152 calculates the first overall evaluation value based on the partial evaluation values ​​and code weights, which are weights corresponding to each of a plurality of source codes.

[0116] Specifically, the calculation unit 152 calculates an overall evaluation value based on code weights, which are weights corresponding to each of a plurality of source codes, and the partial evaluation values. For example, the calculation unit 152 calculates a code-weighted evaluation value #1, which is a value obtained by multiplying the code weight #1 corresponding to the source code #1 by the partial evaluation value #1 corresponding to the source code #1. The calculation unit 152 also calculates a code-weighted evaluation value #2, which is a value obtained by multiplying the code weight #2 corresponding to the source code #2 by the partial evaluation value #2 corresponding to the source code #2. Similarly, the calculation unit 152 calculates a code-weighted evaluation value #k, which is a value obtained by multiplying the code weight #k corresponding to the source code #k (k is a natural number, 1≦k≦N (N is the total number of source codes)) by the partial evaluation value #k corresponding to the source code #k. The calculation unit 2152 also calculates the sum of the code-weighted evaluation value #1, the code-weighted evaluation value #2, ..., the code-weighted evaluation value #N as the first overall evaluation value.

[0117] For example, the calculation unit 152 calculates the overall evaluation value by making the code weight corresponding to the source code corresponding to the library larger than the code weights corresponding to the other source codes. Also, the calculation unit 152 calculates the overall evaluation value by making the code weight corresponding to the source code corresponding to the module that cooperates with other systems larger than the code weights corresponding to the other source codes. Also, the calculation unit 152 calculates the overall evaluation value by making the code weight corresponding to the source code corresponding to the module that handles personal information of users larger than the code weights corresponding to the other source codes.

[0118] 6. Effects As described above, the information processing device 100 according to the embodiment includes the acquisition unit 151 and the calculation unit 152. The acquisition unit 151 acquires code information related to each of a plurality of source codes constituting a system to be developed. The calculation unit 152 calculates partial evaluation values, which are evaluation values ​​corresponding to each of a plurality of different evaluation methods for evaluating each of the plurality of source codes, based on the code information, calculates an overall evaluation value, which is an evaluation value corresponding to each of a plurality of different evaluation methods for evaluating the system to be developed, based on the partial evaluation values, and calculates an overall evaluation value indicating an overall evaluation of the system to be developed, based on the reference weights, which are weights corresponding to each of the plurality of different evaluation methods for evaluating the system to be developed, and the overall evaluation value.

[0119] Thereby, the information processing device 100 can comprehensively evaluate the quality of the system to be developed using a plurality of different evaluation methods, for example, at the stage of the system implementation (manufacturing) process in the system development process. Furthermore, the information processing device 100 can enable a specialist supporting the development of the system to provide health guidance based on a comprehensive evaluation of the system to be developed, for example, like a medical checkup. Therefore, the information processing device 100 can improve the quality of the source code constituting the system to be developed. Furthermore, the information processing device 100 can improve the quality of the source code constituting the system to be developed, and thus can contribute to the achievement of Goal 9 of the Sustainable Development Goals (SDGs), "Build resilience, innovate and innovate,". Furthermore, the information processing device 100 can improve the quality of the source code constituting the system to be developed at the stage of the system implementation (manufacturing) process, and thus can prevent rework from the test process after the system implementation (manufacturing) process. Therefore, the information processing device 100 can improve the productivity of the source code constituting the system to be developed. In addition, the information processing device 100 can improve the quality of the source code that constitutes the system being developed at the system implementation (manufacturing) process stage, thereby contributing to the achievement of Goal 12 of the Sustainable Development Goals (SDGs), "Responsible Consumption and Production."

[0120] Furthermore, the calculation unit 152 calculates a comprehensive evaluation value based on a comparison between a representative value of the overall evaluation values ​​in the multiple systems and the overall evaluation value in the system. This enables the information processing device 100 to objectively evaluate the quality of the source code constituting the system under development based on a comparison with the representative value of the overall evaluation values ​​in the other systems.

[0121] Furthermore, the calculation unit 152 calculates an overall evaluation value as a representative value based on a comparison between the median or mode of the overall evaluation values ​​in the multiple systems and the overall evaluation value in the system. This enables the information processing device 100 to objectively evaluate the quality of the source code constituting the system under development based on a comparison with the median or mode of the overall evaluation values ​​in the other systems.

[0122] Furthermore, the calculation unit 152 calculates the overall evaluation value by setting a standard weight corresponding to an evaluation method related to vulnerabilities among a plurality of different evaluation methods for evaluating the system to be developed greater than standard weights corresponding to other evaluation methods. This enables the information processing device 100 to evaluate the quality of the source code constituting the system to be developed by placing emphasis on evaluation of vulnerabilities that are expected to have the greatest impact on the system among a plurality of evaluation methods.

[0123] Furthermore, the calculation unit 152 calculates the overall evaluation value by setting the standard weight corresponding to the evaluation method related to the static test as the second largest standard weight after the evaluation method related to the vulnerability. This enables the information processing device 100 to evaluate the quality of the source code constituting the system to be developed by placing emphasis on the result of the static test, which is expected to have the second largest impact on the system after the evaluation related to the vulnerability, among the multiple evaluation methods.

[0124] Furthermore, the calculation unit 152 calculates the overall evaluation value by setting the reference weight corresponding to the evaluation method regarding inappropriate comments in the code review to be the second largest after the evaluation method regarding the static test. This enables the information processing device 100 to evaluate the quality of the source code constituting the system to be developed by placing emphasis on inappropriate comments in the code review, which is expected to have the second largest impact on the system after the results of the static test, among the multiple evaluation methods.

[0125] The calculation unit 152 calculates an overall evaluation value based on the code weights, which are weights corresponding to each of the multiple source codes, and the partial evaluation value. The calculation unit 152 calculates an overall evaluation value by making the code weight corresponding to the source code corresponding to the library larger than the code weights corresponding to the other source codes. The calculation unit 152 calculates an overall evaluation value by making the code weight corresponding to the source code corresponding to the module that cooperates with other systems larger than the code weights corresponding to the other source codes. The calculation unit 152 calculates an overall evaluation value by making the code weight corresponding to the source code corresponding to the module that handles personal information of users larger than the code weights corresponding to the other source codes. This enables the information processing device 100 to evaluate the quality of the source codes constituting the system to be developed by placing more importance on the quality of the source codes that are expected to have a greater impact on the system.

[0126] The information processing device 100 further includes a generating unit 153. The generating unit 153 generates evaluation report information that visualizes the evaluation of the system under development based on the overall evaluation value and the comprehensive evaluation value.

[0127] This allows the information processing device 100 to easily visually grasp the evaluation of the quality of the source code that constitutes the system under development.

[0128] [7. Hardware Configuration] Moreover, the information processing device 100 according to the embodiment described above is realized by, for example, a computer 1000 having a configuration as shown in Fig. 7. Fig. 7 is a hardware configuration diagram showing an example of a computer that realizes the functions of the information processing device 100. The computer 1000 includes a CPU 1100, a RAM 1200, a ROM 1300, a HDD 1400, a communication interface (I / F) 1500, an input / output interface (I / F) 1600, and a media interface (I / F) 1700.

[0129] The CPU 1100 operates and controls each unit based on a program stored in the ROM 1300 or the HDD 1400. The ROM 1300 stores a boot program executed by the CPU 1100 when the computer 1000 is started up, programs that depend on the hardware of the computer 1000, and the like.

[0130] The HDD 1400 stores programs executed by the CPU 1100, data used by such programs, etc. The communication interface 1500 receives data from other devices via a predetermined communication network and sends it to the CPU 1100, and transmits data generated by the CPU 1100 to other devices via the predetermined communication network.

[0131] The CPU 1100 controls output devices such as a display and a printer, and input devices such as a keyboard and a mouse, via the input / output interface 1600. The CPU 1100 acquires data from the input devices via the input / output interface 1600. The CPU 1100 also outputs generated data to the output devices via the input / output interface 1600.

[0132] The media interface 1700 reads a program or data stored in the recording medium 1800 and provides it to the CPU 1100 via the RAM 1200. The CPU 1100 loads the program from the recording medium 1800 onto the RAM 1200 via the media interface 1700 and executes the loaded program. The recording medium 1800 is, for example, an optical recording medium such as a DVD (Digital Versatile Disc) or a PD (Phase change rewritable Disc), a magneto-optical recording medium such as an MO (Magneto-Optical disk), a tape medium, a magnetic recording medium, or a semiconductor memory.

[0133] For example, when the computer 1000 functions as the information processing device 100 according to the embodiment, the CPU 1100 of the computer 1000 executes programs loaded onto the RAM 1200 to realize the functions of the control unit 150. The CPU 1100 of the computer 1000 reads and executes these programs from the recording medium 1800, but as another example, the CPU 1100 may obtain these programs from other devices via a predetermined communication network.

[0134] Although some of the embodiments of the present application have been described in detail above with reference to the drawings, these are merely examples, and the present invention can be embodied in other forms that incorporate various modifications and improvements based on the knowledge of those skilled in the art, including the forms described in the Disclosure of the Invention section.

[0135] [8. Other] Furthermore, among the processes described in the above embodiments and modifications, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically by a known method. In addition, the information including the processing procedures, specific names, various data and parameters shown in the above documents and drawings can be changed arbitrarily unless otherwise specified. For example, the various information shown in each drawing is not limited to the illustrated information.

[0136] In addition, each component of each device shown in the figure is a functional concept, and does not necessarily have to be physically configured as shown in the figure. In other words, the specific form of distribution and integration of each device is not limited to that shown in the figure, and all or part of them can be functionally or physically distributed and integrated in any unit according to various loads, usage conditions, etc.

[0137] Furthermore, the above-described embodiments and modifications can be appropriately combined as long as the processing contents are not contradictory. [Explanation of symbols]

[0138] 1. Information Processing Systems 10 Development Server 20 Collection Server 100 Information processing device 110 Communications Department 120 Storage section 130 Input section 140 Display section 150 Control section 151 Acquisition Department 152 Calculation section 153 Generation part 154 Display control section

Claims

1. an acquisition unit that acquires code information relating to each of a plurality of source codes constituting a system to be developed; a calculation unit that calculates partial evaluation values, which are evaluation values ​​corresponding to a plurality of different evaluation methods for evaluating each of the plurality of source codes based on the code information, calculates an overall evaluation value, which is an evaluation value corresponding to a plurality of different evaluation methods for evaluating the system to be developed based on the partial evaluation values, and calculates an overall evaluation value that indicates an overall evaluation of the system to be developed based on standard weights, which are weights corresponding to a plurality of different evaluation methods for evaluating the system to be developed, and the overall evaluation value; An information processing device comprising:

2. The calculation unit is Calculating the overall evaluation value based on a comparison between a representative value of the overall evaluation values ​​for a plurality of systems and the overall evaluation value for the system under development The information processing device according to claim 1 .

3. The calculation unit is Calculating the overall evaluation value as the representative value based on a comparison between a median or a mode of the overall evaluation values ​​of the plurality of systems and the overall evaluation value of the system under development. The information processing device according to claim 2 .

4. The calculation unit is Among the multiple different evaluation methods for evaluating the system under development, the standard weight corresponding to the evaluation method regarding vulnerability is made larger than the standard weight corresponding to the other evaluation methods to calculate the overall evaluation value. The information processing device according to claim 1 .

5. The calculation unit is The standard weight corresponding to the evaluation method related to the static test is made the next largest after the standard weight corresponding to the evaluation method related to the vulnerability, and the overall evaluation value is calculated. The information processing device according to claim 4.

6. The calculation unit is The criterion weight corresponding to the evaluation method regarding the inappropriate comments in the code review is set to be second largest after the evaluation method regarding the static test, and the overall evaluation value is calculated. The information processing device according to claim 5 .

7. The calculation unit is The overall evaluation value is calculated based on code weights, which are weights corresponding to the plurality of source codes, and the partial evaluation values. The information processing device according to claim 1 .

8. The calculation unit is The code weight corresponding to the source code corresponding to the library is made larger than the code weight corresponding to the other source code to calculate the overall evaluation value. The information processing device according to claim 7.

9. The calculation unit is The code weight corresponding to the source code corresponding to the module that cooperates with another system is made larger than the code weight corresponding to the other source code to calculate the overall evaluation value. The information processing device according to claim 7.

10. The calculation unit is The code weight corresponding to the source code corresponding to the module that handles the user's personal information is made larger than the code weight corresponding to the other source codes to calculate the overall evaluation value. The information processing device according to claim 7.

11. The system further includes a generating unit that generates evaluation report information that visualizes an evaluation of the system under development based on the overall evaluation value and the comprehensive evaluation value. The information processing device according to claim 1 .

12. An information processing method implemented by a program executed by an information processing device, comprising: An acquisition step of acquiring code information regarding each of a plurality of source codes constituting the system to be developed; a calculation step of calculating partial evaluation values, which are evaluation values ​​corresponding to a plurality of different evaluation methods for evaluating each of the plurality of source codes based on the code information, calculating an overall evaluation value, which is an evaluation value corresponding to a plurality of different evaluation methods for evaluating the system to be developed based on the partial evaluation values, and calculating an overall evaluation value indicating an overall evaluation of the system to be developed based on standard weights, which are weights corresponding to a plurality of different evaluation methods for evaluating the system to be developed, and the overall evaluation value; An information processing method comprising:

13. An information processing system including a server and an information processing device, The server, Collect code information about each of the multiple source codes that make up the system to be developed, The information processing device includes: an acquisition unit that acquires the code information collected by the server; a calculation unit that calculates partial evaluation values, which are evaluation values ​​corresponding to a plurality of different evaluation methods for evaluating each of the plurality of source codes, based on the code information, calculates an overall evaluation value, which is an evaluation value corresponding to a plurality of different evaluation methods for evaluating the system to be developed, based on the partial evaluation values, and calculates an overall evaluation value indicating an overall evaluation of the system to be developed, based on standard weights, which are weights corresponding to a plurality of different evaluation methods for evaluating the system to be developed, and the overall evaluation value. Information processing system.

Citation Information

Patent Citations

  • Software quality evaluation system

    JP1994187145A

  • Source code evaluation device

    JP1995160495A

  • Software delivery system

    JP2002063236A

  • Management server in system for evaluating serviceability of source code, management method and program

    JP2021163016A

  • Quality information output apparatus, quality information output method, and program

    JP2022179849A