IP Library Granted Patent US 11,836,485
Granted Patent B1
US 11,836,485 · App. 16/543,842 · Granted Dec 5, 2023

Software code review

Inventors: James Cancilla (Milton, CA); Ian Horbatiuk (Toronto, CA)
Assignee: Rapid7, Inc.
G06F8/73G06F8/72G06F8/75G06F8/71
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,836,485
App. No.
16/543,842
Granted
Dec 5, 2023
Kind
B1
Abstract

Methods and systems for reviewing software code. The methods involve detecting a change in source code associated with an application and determining an effect on the application of the detected change based at least in part on a context profile associated with application.

Claims (41)

1. A method comprising:

performing, by a software reviewing system implemented by one or more processors of one or more computing devices:

identifying one or more code paths associated with an application, wherein the identifying comprises performing a static code analysis on source code associated with the application;

building, based at least in part on the one or more code paths, a model of the application, wherein the model comprises one or more trees linking different portions of the source code associated with the application;

receiving, over a network, changed source code comprising a change in the source code for the application;

in at least substantially real time with the receiving the changed source code:

recognizing, based on the changed source code, a particular pre-existing context profile for the application from among a plurality of pre-existing context profiles of other known applications stored in a database based on a comparison of the change source code and code of another known application, wherein the particular pre-existing context profile indicates an application type, an application language, and a programming framework of the application,

determining, at least partly by referencing the changed source code to the model of the application, an effect of the changed source code on the application,

wherein the determining the effect comprises:

performing a second static code analysis on the changed source code,

generating, based on the second static code analysis of the changed source code and the particular pre-existing context profile, a tree of linked nodes of the application, wherein the tree includes at least one code path of a plurality of nodes,

identifying, from among the plurality of nodes, a first node on the at least one code path that corresponds to the change in the source code, and at least one node downstream from the first node,

determining, based on the identified first node of the at least one code path that corresponds to the change in the source code and the at least one downstream node of the at least one code path, a portion of the application affected by the change in the source code, and

determining, based on referencing the affected portion of the application to one or more entry points and exit points of the application, at least one exit point of the application affected by the change in the source code, and

generating, via a user interface, a summary of the effect of the changed source code on the application, wherein the summary indicates the tree of linked nodes, the first node that corresponds to the change in the source code, a portion of the at least one code path affected by the change, and the at least one exit point affected by the change in the source code; and

receiving user input via the user interface indicating approval or rejection of the change in the source code.

2. The method of claim 1 wherein determining the particular pre-existing context profile associated with the application includes identifying annotations in the changed source code specific to the programming framework of the application.

3. The method of claim 1 , wherein the application language is Java and the programming framework is a Model-View-Controller (MVC) web application framework.

4. The method of claim 1 , wherein individual nodes in the tree correspond to individual software classes defined by the source code.

5. A system comprising:

a software reviewing system implemented by one or more processors and a coupled memory, configured to:

identify one or more code paths associated with an application, wherein, to identify the one or more code paths based on a static code analysis on source code associated with the application;

build, based at least in part on the one or more code paths, a model of the application, wherein the model comprises one or more trees linking different portions of the source code associated with the application;

receive, over a network, changed source code comprising a change in the source code for the application;

in at least substantially real time with the changed source code being received:

recognize, based on the changed source code, a particular pre-existing context profile for the application from among a plurality of pre-existing context profiles of other known applications stored in a database based on a comparison of the change source code and code of another known application, wherein the particular pre-existing context profile indicates an application type, an application language, and a programming framework of the application,

determine, at least partly by referencing the changed source code to the model of the application, an effect of the changed source code on the application, wherein to determine the effect, the one or more processors are configured to:

perform a second static code analysis on the changed source code,

generate, based on the second static code analysis of the changed source code and the particular pre-existing context profile, a tree of linked nodes of the application, wherein the tree includes at least one code path of a plurality of nodes,

identify, from among the plurality of nodes, a first node on the at least one code path that corresponds to the change in the source code, and at least one node downstream from the first node,

determine, based on the identified first node of the at least one code path that corresponds to the change in the source code and the at least one downstream node of the at least one code path, a portion of the application affected by the change in the source code,

determine, based on referencing the affected portion of the application to the one or more entry points and exit points of the application, at least one exit point of the application affected by the change in the source code, and

generate, via a user interface, a summary of the effect of the changed source code on the application, wherein the summary indicates the tree of linked nodes, the first node that corresponds to the change in the source code, a portion of the at least one code path affected by the change, and identifies the at least one exit point affected by the change in the source code; and

receive user input via the user interface indicating approval or rejection of the change in the source code.

6. The system of claim 5 , wherein the software reviewing system identifies annotations in the changed source code specific to the programming framework of the application.

7. The system of claim 5 , wherein the application language is Java and the programming framework is a Model-View-Controller (MVC) web application framework.

8. The system of claim 5 , wherein the summary indicates multiple software levels or layers of the application and associates individual nodes in the tree to individual ones of the software levels or layers.

9. The system of claim 5 , wherein

the change in the source code for the application is received in response to submission of the changed source code to a source control repository, and

the user interface permits inspection and modification of the source code based on the summary.

10. The system of claim 5 , wherein the particular pre-existing context profile indicates that the source code includes one or more serverless functions executable on a serverless execution service.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2019
From: CANCILLA, JAMES; HORBATIUK, IAN
To: RAPID7, INC.
Reel/Frame 051263/0052 →
Cited By (5)
US 12,223,315 US 12,386,615 US 12,461,741 US 12,578,961 US 12,645,561