Glossary · Automation software engineering and architecture
Static code analysis
Also known as: Static analysis, SAST
German: Statische Codeanalyse
In software verification, static code analysis is the automated examination of source or object code without executing it, to find defects, rule violations, security vulnerabilities and quality issues.
- Software engineering
In one sentence
Static code analysis examines code without running it to find defects, rule violations, vulnerabilities and quality issues.
Example
The pipeline runs a static analysis tool on the structured text code and blocks the merge because a variable is read before it is written.
How it applies
- Engineering: Static analysis checks coding rules, data flow, possible runtime errors and complexity. Tools exist for C, C++ and IEC 61131-3 languages. Running it in the pipeline gives fast feedback.
- Functional safety: Safety standards recommend static analysis as a verification technique; the tool and its configuration should be recorded, and suppressed findings justified.
- Documentation: Keep the analysis rule set and deviation records under version control. Some documentation teams apply the same idea to content with linters for terminology, style and structure.
Static vs. dynamic analysis
Static analysis examines code without running it and can cover all paths, with some false positives. Dynamic code analysis observes the running program and finds problems only on paths actually executed.