An Empirical Study of Suppressed Static Analysis Warnings
Huimin Hu, Yingying Wang, Julia Rubin, Michael Pradel
摘要
Scalable static analyzers are popular tools for finding incorrect, inefficient, insecure, and hard-to-maintain code early during the development process. Because not all warnings reported by a static analyzer are immediately useful to developers, many static analyzers provide a way to suppress warnings, e.g., in the form of special comments added into the code. Such suppressions are an important mechanism at the interface between static analyzers and software developers, but little is currently known about them. This paper presents the first in-depth empirical study of suppressions of static analysis warnings, addressing questions about the prevalence of suppressions, their evolution over time, the relationship between suppressions and warnings, and the reasons for using suppressions. We answer these questions by studying projects written in three popular languages and suppressions for warnings by four popular static analyzers. Our findings show that (i) suppressions are relatively common, e.g., with a total of 7,357 suppressions in 46 Python projects, (ii) the number of suppressions in a project tends to continuously increase over time, (iii) surprisingly, 50.8% of all suppressions do not affect any warning and hence are practically useless, (iv) some suppressions, including useless ones, may unintentionally hide future warnings, and (v) common reasons for introducing suppressions include false positives, suboptimal configurations of the static analyzer, and misleading warning messages. These results have actionable implications, e.g., that developers should be made aware of useless suppressions and the potential risk of unintentional suppressing, that static analyzers should provide better warning messages, and that static analyzers should separately categorize warnings from third-party libraries.
CCS Concepts: • Software and its engineering → Software verification and validation; Software post-development issues.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- CodeMapper: A Language-Agnostic Approach to Mapping Code Regions Across CommitsHuimin Hu, Michael PradelICSE 2026
- CodeCureAgent: Automatic Classification and Repair of Static Analysis WarningsPascal Joos, Islem Bouzenia, Michael PradelFSE 2026
- LLM-Based Repair of Static Nullability ErrorsNima Karimipour, Pascal Joos, Michael Pradel, Martin Kellogg 等ISSTA 2026
- Sifting the Noise: A Comparative Study of LLM Agents in Vulnerability False Positive FilteringYunpeng Xiong, Ting ZhangISSTA 2026
它引用的顶会 Paper10
- PYEVOLVE: Automating Frequent Code Changes in Python ML SystemsMalinda Dilhara, Danny Dig, Ameya KetkarICSE 2023 · 被引用 46 次
- Detecting False Alarms from Automatic Static Analysis Tools: How Far are We?Hong Jin Kang, Khai Loong Aw, David LoICSE 2022 · 被引用 42 次
- Learning to Reduce False Positives in Analytic Bug DetectorsAnant Kharkar, Roshanak Zilouchian Moghaddam, Matthew Jin, Xiaoyu Liu 等ICSE 2022 · 被引用 33 次
- CodeShovel: Constructing Method-Level Source Code HistoriesFelix Grund, Shaiful Alam Chowdhury, Nick C. Bradley, Braxton Hall 等ICSE 2021 · 被引用 33 次
- The evolution of type annotations in python: an empirical studyLuca Di Grazia, Michael PradelFSE 2022 · 被引用 29 次
相关 Paper
- Tailoring programs for static analysis via program transformationRijnard van Tonder, Claire Le GouesICSE 2020 · 被引用 6 次
- A large-scale study of usability criteria addressed by static analysis toolsMarcus Nachtigall, Michael Schlichtig, Eric BoddenISSTA 2022 · 被引用 38 次
- An empirical study on the effectiveness of static C code analyzers for vulnerability detectionStephan Lipp, Sebastian Banescu, Alexander PretschnerISSTA 2022 · 被引用 99 次
- Understanding and Characterizing Mock Assertions in Unit TestsHengcheng Zhu, Valerio Terragni, Lili Wei, Shing-Chi Cheung 等FSE 2025 · 被引用 1 次
- "False negative - that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security TestingAmit Seal Ami, Kevin Moran, Denys Poshyvanyk, Adwait NadkarniS&P 2024 · 被引用 40 次
