An Empirical Study of Suppressed Static Analysis Warnings
Huimin Hu, Yingying Wang, Julia Rubin, Michael Pradel
Abstract
Scalable static analyzers are popular tools for finding incorrect, inefficient, insecure, and hard-to-maintain code early during the development process. Because not all warnings reported by a static analyzer are immediately useful to developers, many static analyzers provide a way to suppress warnings, e.g., in the form of special comments added into the code. Such suppressions are an important mechanism at the interface between static analyzers and software developers, but little is currently known about them. This paper presents the first in-depth empirical study of suppressions of static analysis warnings, addressing questions about the prevalence of suppressions, their evolution over time, the relationship between suppressions and warnings, and the reasons for using suppressions. We answer these questions by studying projects written in three popular languages and suppressions for warnings by four popular static analyzers. Our findings show that (i) suppressions are relatively common, e.g., with a total of 7,357 suppressions in 46 Python projects, (ii) the number of suppressions in a project tends to continuously increase over time, (iii) surprisingly, 50.8% of all suppressions do not affect any warning and hence are practically useless, (iv) some suppressions, including useless ones, may unintentionally hide future warnings, and (v) common reasons for introducing suppressions include false positives, suboptimal configurations of the static analyzer, and misleading warning messages. These results have actionable implications, e.g., that developers should be made aware of useless suppressions and the potential risk of unintentional suppressing, that static analyzers should provide better warning messages, and that static analyzers should separately categorize warnings from third-party libraries.
CCS Concepts: • Software and its engineering → Software verification and validation; Software post-development issues.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext efc473b2-9385-4bbc-aa6c-0f704d9be172Cited by top-tier papers4
- CodeMapper: A Language-Agnostic Approach to Mapping Code Regions Across CommitsHuimin Hu, Michael PradelICSE 2026
- CodeCureAgent: Automatic Classification and Repair of Static Analysis WarningsPascal Joos, Islem Bouzenia, Michael PradelFSE 2026
- LLM-Based Repair of Static Nullability ErrorsNima Karimipour, Pascal Joos, Michael Pradel, Martin Kellogg et al.ISSTA 2026
- Sifting the Noise: A Comparative Study of LLM Agents in Vulnerability False Positive FilteringYunpeng Xiong, Ting ZhangISSTA 2026
Builds on10
- PYEVOLVE: Automating Frequent Code Changes in Python ML SystemsMalinda Dilhara, Danny Dig, Ameya KetkarICSE 2023 · 46 citations
- Detecting False Alarms from Automatic Static Analysis Tools: How Far are We?Hong Jin Kang, Khai Loong Aw, David LoICSE 2022 · 42 citations
- Learning to Reduce False Positives in Analytic Bug DetectorsAnant Kharkar, Roshanak Zilouchian Moghaddam, Matthew Jin, Xiaoyu Liu et al.ICSE 2022 · 33 citations
- CodeShovel: Constructing Method-Level Source Code HistoriesFelix Grund, Shaiful Alam Chowdhury, Nick C. Bradley, Braxton Hall et al.ICSE 2021 · 33 citations
- The evolution of type annotations in python: an empirical studyLuca Di Grazia, Michael PradelFSE 2022 · 29 citations
Related papers
- Tailoring programs for static analysis via program transformationRijnard van Tonder, Claire Le GouesICSE 2020 · 6 citations
- A large-scale study of usability criteria addressed by static analysis toolsMarcus Nachtigall, Michael Schlichtig, Eric BoddenISSTA 2022 · 38 citations
- An empirical study on the effectiveness of static C code analyzers for vulnerability detectionStephan Lipp, Sebastian Banescu, Alexander PretschnerISSTA 2022 · 99 citations
- Understanding and Characterizing Mock Assertions in Unit TestsHengcheng Zhu, Valerio Terragni, Lili Wei, Shing-Chi Cheung et al.FSE 2025 · 1 citation
- "False negative - that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security TestingAmit Seal Ami, Kevin Moran, Denys Poshyvanyk, Adwait NadkarniS&P 2024 · 40 citations
