IP Library Granted Patent US 12,099,835
Granted Patent B1
US 12,099,835 · App. 17/686,892 · Granted Sep 24, 2024

Semantic analysis of source code using stubs for external references

Inventors: Cameron Gunnin (Kawasaki, JP); Edward Moriarty (Calgary, CA); Aaron Hurst (San Francisco, CA); Simon Fredrick Vicente Goldsmith (Oakland, CA)
Assignee: Black Duck Software, Inc.
G06F8/75G06F8/436G06F8/73G06N5/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,099,835
App. No.
17/686,892
Granted
Sep 24, 2024
Kind
B1
Abstract

A system receives source code for analysis. The system identifies external references to reference code in source code. The reference code is not included in the source code received for analysis. The system generates code stubs corresponding to the external references. Each code stub describes a semantic context for the corresponding external reference. The system provides the set of source code and the one or more code stubs for analysis of the code, for example, using a code analysis tool.

Claims (37)

1. A method comprising:

receiving a set of source code for analysis;

identifying one or more external references to reference code in the set of source code, the reference code not included in the set of source code for analysis;

for each of the one or more external references, retrieving information for the external reference from a code repository corresponding to the external reference;

generating, by a processor, one or more code stubs each corresponding to the one or more external references, each code stub describing a semantic context for the corresponding external reference based on the retrieved information corresponding to the external reference; and

performing analysis of the set of source code and a code stub selected from a set of code stubs responsive to determining that the code stub maximizes a number of types defined in the code stub that match types used in the set of source code.

2. The method of claim 1 , wherein the set of source code and one or more code stubs is analyzed by a code analysis tool without compiling the source code.

3. The method of claim 1 , wherein the one or more code stubs are sufficient to compile the set of source code to an executable but do not implement logic of one or more external references.

4. The method of claim 1 , wherein at least one of the one or more code stubs is generated prior to receiving the set of source code for analysis.

5. The method of claim 4 , wherein the at least one of the one or more code stubs is selected from a set of stubs based on a set of heuristics.

6. The method of claim 1 , wherein the semantic context of a code stub describes a type, field, function, or scope of the corresponding external reference.

7. The method of claim 1 , wherein the semantic context of a code stub describes metadata about a library of the corresponding external reference.

8. A system comprising:

a memory storing instructions; and

a processor, coupled with the memory and to execute the instructions, the instructions when executed cause the processor to:

receive a set of source code for analysis;

identify one or more external references to reference code in the set of source code, the reference code not included in the set of source code for analysis;

for each of the one or more external references, retrieve information for the external reference from a code repository corresponding to the external reference;

generate one or more code stubs each corresponding to the one or more external references, each code stub describing a semantic context for the corresponding external reference based on the retrieved information corresponding to the external reference; and

performing analysis of the set of source code and a code stub selected from a set of code stubs responsive to determining that the code stub maximizes a number of types defined in the code stub that match types used in the set of source code.

9. The system of claim 8 , wherein the set of source code and one or more code stubs is analyzed by a code analysis tool without compiling the source code.

10. The system of claim 8 , wherein the one or more code stubs are sufficient to compile the set of source code to an executable but do not implement logic of one or more external references.

11. The system of claim 8 , wherein at least one of the one or more code stubs is generated prior to receiving the set of source code for analysis.

12. The system of claim 11 , wherein the at least one of the one or more code stubs is selected from a set of stubs based on a set of heuristics.

13. The system of claim 8 , wherein the semantic context of a code stub describes a type, field, function, or scope of the corresponding external reference.

14. The system of claim 8 , wherein the semantic context of a code stub describes metadata about a library of the corresponding external reference.

15. The system of claim 8 , wherein the semantic context of a code stub describes a type, field, function, or scope of the corresponding external reference.

16. A non-transitory computer readable medium comprising stored instructions, which when executed by a processor, cause the processor to:

receive a set of source code for analysis;

identify one or more external references to reference code in the set of source code, the reference code not included in the set of source code for analysis;

for each of the one or more external references, retrieve information for the external reference from a code repository corresponding to the external reference;

generate one or more code stubs each corresponding to the one or more external references, each code stub describing a semantic context for the corresponding external reference based on the retrieved information corresponding to the external reference; and

performing analysis of the set of source code and a code stub selected from a set of code stubs responsive to determining that the code stub maximizes a number of types defined in the code stub that match types used in the set of source code.

17. The non-transitory computer readable medium of claim 16 , wherein the one or more code stubs are sufficient to compile the set of source code to an executable but do not implement logic of one or more external references.

18. The non-transitory computer readable medium of claim 16 , wherein generating the one or more code stubs comprises retrieving information for an external reference from a code repository corresponding to the external reference.

19. The non-transitory computer readable medium of claim 16 , wherein the semantic context of a code stub describes a type, field, function, or scope of the corresponding external reference.

20. The non-transitory computer readable medium of claim 16 , wherein the semantic context of a code stub describes metadata about a library of the corresponding external reference.

Assignments (4)
SECURITY INTEREST Recorded Sep 30, 2024
From: BLACK DUCK SOFTWARE, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 069083/0149 →
CHANGE OF NAME Recorded Aug 9, 2024
From: SOFTWARE INTEGRITY GROUP, INC.
To: BLACK DUCK SOFTWARE, INC.
Reel/Frame 068535/0318 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2024
From: SYNOPSYS, INC.
To: SOFTWARE INTEGRITY GROUP, INC.
Reel/Frame 066664/0821 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2022
From: GUNNIN, CAMERON; MORIARTY, EDWARD; HURST, AARON; GOLDSMITH, SIMON FREDRICK VICENTE
To: SYNOPSYS, INC.
Reel/Frame 061747/0283 →
Cited By (2)
US 12,468,808 US 12,705,035