Haris Adzemovic

dblp:288/2547 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2023
0000-0002-8080-1355ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Program analysis · 67% Debugging and program repair · 33%

Topics — the 3 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Debugging and program repair
automated program repair
0.712023
Sorald: Automatic Patch Suggestions for SonarQube Static Analysis Violations · IEEE Trans. Dependable Secur. Comput. 2023
Program analysis
static analysis
0.712023
Sorald: Automatic Patch Suggestions for SonarQube Static Analysis Violations · IEEE Trans. Dependable Secur. Comput. 2023
Program analysis › static analysis
static analysis warnings
0.712023
Sorald: Automatic Patch Suggestions for SonarQube Static Analysis Violations · IEEE Trans. Dependable Secur. Comput. 2023

Methods — techniques the papers use, named apart from their topics

metaprogramming templates · 0.7abstract syntax tree transformation · 0.7
YearPublicationVenuePosition
2023 Sorald: Automatic Patch Suggestions for SonarQube Static Analysis Violations
abstract
Previous work has shown that early resolution of issues detected by static code analyzers can prevent major costs later on. However, developers often ignore such issues for two main reasons. First, many issues should be interpreted to determine if they correspond to actual flaws in the program. Second, static analyzers often do not present the issues in a way that is actionable. To address these problems, we present Sorald: a novel system that uses metaprogramming templates to transform the abstract syntax trees of programs and suggests fixes for static analysis warnings. Thus, the burden on the developer is reduced from interpreting and fixing static issues, to inspecting and approving full fledged solutions. Sorald fixes violations of 10 rules from SonarJava, one of the most widely used static analyzers for Java. We evaluate Sorald on a dataset of 161 popular repositories on Github. Our analysis shows the effectiveness of Sorald as it fixes 65% (852/1,307) of the violations that meets the repair preconditions. Overall, our experiments show it is possible to automatically fix notable violations of the static analysis rules produced by the state-of-the-art static analyzer SonarJava.
Khashayar Etemadi, Nicolas Harrand, Simon Larsén, Haris Adzemovic, Henry Luong Phu, Ashutosh Verma, Fernanda Madeiral, Douglas Wikström, Martin Monperrus
IEEE Trans. Dependable Secur. Comput.4