static code analysis

Design and implement analyses and tools that examine program source code or binary artifacts without executing them to detect defects and security issues, compute code-quality and vulnerability metrics (for example cyclomatic complexity), and extract structural or documentation indicators. This work includes building control-flow and data-flow analyses, static application security testing (SAST) pipelines, oracle analyses, and other program-analysis techniques for reporting vulnerabilities, style violations, and abstraction properties.

staticcodeanalysis

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.05
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$196K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This study addresses the lack of systematic evaluation of the long-term effectiveness, actionability, and stability of Static Application Security Testing (SAST) tools in open-source ecosystems. The authors propose and implement the first longitudinal evaluation framework for SAST tools, conducting a large-scale temporal analysis across 114 CodeQL versions, 1,622 repositories, and 3,993 CVEs. Their findings reveal that CodeQL detected 171 CVEs, with 83 identifiable prior to patching; half of the generated alerts exhibited high file-level localization precision. However, 21 CVEs became undetectable due to tool updates, exposing detection blind spots introduced during version evolution. This work establishes both a methodological foundation and empirical evidence for the continuous reliability assessment of SAST tools.

CodeQLlongitudinal analysisopen-source software

This study addresses the lack of systematic evaluation of static code analysis tools, particularly regarding their effectiveness in detecting exploitable vulnerabilities. Through a comprehensive literature review, it presents the first holistic mapping of 246 tools across dimensions including vulnerability types, application domains, underlying analysis techniques, and evaluation methodologies. The findings reveal that most tools cover only a limited set of weaknesses, often identifying vulnerabilities that are not practically exploitable. Furthermore, evaluations commonly rely on small-scale, ad hoc benchmarks, which undermines the reliability of reported results. By exposing critical gaps in both the coverage of exploitable vulnerabilities and the rigor of empirical assessment, this work provides an evidence-based foundation and clear direction for future research and tool development in static analysis.

security vulnerabilitiessoftware securitystatic code analysis

Static Application Security Testing (SAST) tools exhibit low adoption and unverified effectiveness and usability in open-source embedded software (e.g., EMBOSS). Method: This work presents the first systematic evaluation of CodeQL’s practical utility in the embedded ecosystem, conducting large-scale CodeQL scanning across 258 mainstream embedded projects. The study integrates vulnerability pattern modeling, CI/CD pipeline integration, and developer surveys to assess barriers and enablers of SAST adoption. Contribution/Results: It reveals severe underutilization of SAST in embedded development and successfully deploys automated detection pipelines in 71% of target repositories. The analysis identifies 709 real defects (34% false-positive rate), of which 535 pose potential security risks; 376 were confirmed and fixed by developers, yielding two assigned CVEs. This work establishes a methodological framework and empirical benchmark for SAST adoption in embedded systems.

CodeQL identified 709 defects with 34% false positive rateLow adoption of SAST tools in EMBOSS due to perceived ineffectivenessUrging EMBOSS engineers to adopt modern SAST tools

Latest Papers

What's happening recently
View more

This work addresses the challenge of inaccurate taint analysis in JavaScript due to the language’s dynamic features and the vast npm ecosystem, which hinder precise identification of sources, sinks, and data flows, leading to high false-negative rates in existing static application security testing (SAST) tools. To overcome this, the authors propose SemTaint, the first approach that deeply integrates multi-agent large language models (LLMs) with static analysis. SemTaint leverages collaborative semantic reasoning to automatically extract CWE-specific taint specifications—including sources, sinks, call edges, and library summaries—and dynamically resolves unparseable calls while accurately modeling complex dependencies. Integrated into CodeQL, SemTaint successfully identifies 106 out of 162 previously missed vulnerabilities and discovers four new vulnerabilities in four widely used npm packages.

JavaScriptnpm ecosystemstatic program analysis

JavaScript code obfuscation can evade static application security testing (SAST) tools, leading to undetected vulnerabilities and a false sense of security in the software supply chain. This work constructs a realistic threat model for software supply chains and presents the first systematic evaluation of eight semantics-preserving obfuscation techniques—individually and in combination—against mainstream JavaScript SAST tools, namely Njsscan and Bearer. Through a two-phase empirical analysis using both OWASP Benchmark applications and real-world GitHub projects, the study introduces a quantitative metric termed Vulnerability Detection Loss (VDL). Results demonstrate that even a single obfuscation technique significantly suppresses the detection of high-severity vulnerabilities, while multiple combined obfuscations drive VDL close to 100%, exposing fundamental fragility and a critical lack of robustness in current SAST tools when confronted with common obfuscation strategies.

code securityJavaScript obfuscationsoftware supply chain

Static Application Security Testing (SAST) tools often suffer from high false positive rates, which undermines developer trust. This work proposes a novel false positive filtering approach based on Graph Convolutional Networks (GCNs), uniquely integrating GCNs with Code Property Graphs (CPGs) to effectively model both structural and semantic aspects of source code for distinguishing genuine vulnerabilities from false alarms. Evaluated on the CamBenchCAP dataset, the method achieves 100% test accuracy, and attains 96.6% accuracy on CryptoAPI-Bench. Notably, some instances labeled as misclassifications are in fact justified security warnings, reflecting the model’s strong discriminative capability and its conservative, security-oriented design philosophy.

Code AnalysisFalse PositiveSAST

This work proposes a unified framework that integrates graph neural networks with large language models (LLMs) to jointly detect, explain, and repair software maintainability and security issues. Addressing the high false-positive rates and maintenance overhead of existing code smell and vulnerability detection tools—stemming from their lack of structured contextual awareness—the approach uniquely fuses multi-dimensional program graphs, including abstract syntax trees (ASTs), control flow graphs (CFGs), and program dependence graphs (PDGs), with deep code embeddings. The resulting model is cross-lingual, interpretable, and readily integrable into CI/CD pipelines. Empirical evaluation on multilingual datasets demonstrates significant improvements over conventional rule-based analyzers and single-model baselines, achieving higher detection accuracy and generating more practical repair suggestions.

AI-assisted code reviewcode smellsprogram analysis

Hot Scholars

ZZ

Zibin Zheng

IEEE Fellow, Highly Cited Researcher, Sun Yat-sen University, China
BlockchainSmart ContractServices ComputingSoftware Reliability
MR

Michael R. Lyu

Professor of Computer Science & Engineering, The Chinese University of Hong Kong
software engineeringsoftware reliabilityfault tolerancemachine learning
XP

Xin Peng

East China University of Science and Technology
Artificial IntelligenceMachine LearningComplex Process Modeling
ML

Mingwei Liu

Rutgers University
China laborhigh performance work systems
JM

Jie M. Zhang

Lecturer (Assistant Professor), King's College London
LLMsSE4MLmachine learning testingmutation testing