Share E-Book

AuthorG. Ann Campbell, Patroklos P. Papapetrou, (foreword by) Olivier Gaudin

SonarQube is a powerful open source tool for continuous inspection, a process that makes code quality analysis and reporting an integral part of the development lifecycle. Its unique dashboards, rule-based defect analysis, and tight build integration result in improved code quality without disruption to developer workflow. It supports many languages, including Java, C, C++, C#, PHP, and JavaScript. SonarQube in Action teaches you how to effectively use SonarQube following the continuous inspection model. This practical book systematically explores SonarQube's core Seven Axes of Quality (design, duplications, comments, unit tests, complexity, potential bugs, and coding rules). With well-chosen examples, it helps you learn to use SonarQube's review functionality and IDE integration to implement continuous inspection best practices in your own quality management process.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

Passage locations
Tags
No tags
ISBN: 1617290955
Publish Year: 2013
Language: 英文
Pages: 392
File Format: PDF
File Size: 19.5 MB
Support Statistics
¥.00 · 0times
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

M A N N I N G G. Ann Campbell Patroklos P. Papapetrou FOREWORD BY Olivier Gaudin IN ACTION www.it-ebooks.info
SonarQube in ActionDownload from Wow! eBook <www.wowebook.com>www.it-ebooks.info
Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
SonarQube in Action G. ANN CAMPBELL PATROKLOS P. PAPAPETROU M A N N I N G SHELTER ISLANDDownload from Wow! eBook <www.wowebook.com>www.it-ebooks.info
For online information and ordering of this and other Manning books, please visit www.manning.com. The publisher offers discounts on this book when ordered in quantity. For more information, please contact Special Sales Department Manning Publications Co. 20 Baldwin Road PO Box 761 Shelter Island, NY 11964 Email: orders@manning.com ©2014 by Manning Publications Co. All rights reserved. No part of this publication may be reproduced, stored in a retrieval system, or transmitted, in any form or by means electronic, mechanical, photocopying, or otherwise, without prior written permission of the publisher. Many of the designations used by manufacturers and sellers to distinguish their products are claimed as trademarks. Where those designations appear in the book, and Manning Publications was aware of a trademark claim, the designations have been printed in initial caps or all caps. Recognizing the importance of preserving what has been written, it is Manning’s policy to have the books we publish printed on acid-free paper, and we exert our best efforts to that end. Recognizing also our responsibility to conserve the resources of our planet, Manning books are printed on paper that is at least 15 percent recycled and processed without the use of elemental chlorine. Manning Publications Co. Development editor: Susanna Kline 20 Baldwin Road Copyeditor: Tiffany Taylor PO Box 261 Proofreader: Toma Mulligan Shelter Island, NY 11964 Typesetter: Dottie Marsico Cover designer: Marija Tudor ISBN 9781617290954 Printed in the United States of America 1 2 3 4 5 6 7 8 9 10 – EBM – 18 17 16 15 14 13Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
To the software architects, programmers, testers, project managers, executives, and end users of every piece of software ever written. We hope this book will make your lives easier.Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
brief contents PART 1 WHAT THE NUMBERS ARE TELLING YOU .........................1 1 ■ An introduction to SonarQube 3 2 ■ Issues and coding standards 26 3 ■ Ensuring that your code is doing things right 42 4 ■ Working with duplicate code 64 5 ■ Optimizing source code documentation 82 6 ■ Keeping your source code files elegant 96 7 ■ Improving your application design 113 PART 2 SETTLING IN WITH SONARQUBE . ...............................135 8 ■ Planning a strategy and expanding your insight 137 9 ■ Continuous Inspection with SonarQube 156 10 ■ Letting SonarQube drive code reviews 178 11 ■ IDE integration 205 PART 3 ADMINISTERING AND EXTENDING...............................221 12 ■ Security: users, groups, and roles 223 13 ■ Rule profile administration 237 14 ■ Making SonarQube fit your needs 262 15 ■ Managing your projects 287 16 ■ Writing your own plugin 305vii Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
contents foreword xvii preface xix acknowledgments xxi about this book xxiii about the cover illustration xxviii PART 1 WHAT THE NUMBERS ARE TELLING YOU ................1 1 An introduction to SonarQube 3 1.1 Why SonarQube 4 Proven technologies 6 ■ Multilingual: SonarQube speaks your language 6 1.2 Running your first analysis 7 Installation considerations 7 ■ Analyzing with SonarQube Runner 8 ■ Analyzing multilanguage projects 9 ■ Seeing the output: SonarQube’s front page 9 ■ Drilling in: the dashboard 10 1.3 Seven Axes of Quality 13 Potential bugs and coding rules 14 ■ Tests 15 ■ Comments and duplications 15 ■ Architecture and design 16 Complexity 18 1.4 The languages SonarQube covers 18ix Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
CONTENTSx1.5 Interface conventions 20 Hierarchy: packages and classes in a metric drilldown 20 ■ File details 21 Trend arrows 22 1.6 Related plugins 23 Technical debt 23 ■ Views 24 1.7 Summary 24 2 Issues and coding standards 26 2.1 Looking at your issues 27 2.2 What issues mean, and why they’re potential problems 30 Bugs 31 ■ Potential bugs 31 ■ Indications of (potential) programmer error 32 ■ Things that may lead to future programmer error 34 ■ Inefficiencies 35 ■ Style inconsistencies (future productivity obstacles) 36 2.3 Where do issues come from? 36 Picking a rule profile 37 ■ Viewing profiles and changing the default 38 2.4 Related plugins 40 SCM Activity 40 2.5 Summary 41 3 Ensuring that your code is doing things right 42 3.1 Knowing how much of your code is doing things right 43 Understanding unit-test metrics 44 ■ Getting reports on unit-test coverage metrics 47 3.2 Explaining metrics on a file level 50 Hunting source code lines with low coverage 50 ■ Finding problems in your unit tests 54 3.3 Configuring your favorite code-coverage tool 57 Changing the default selection 57 3.4 Integration testing 58 Displaying integration testing coverage on the dashboard 59 Getting IT information in the source code Coverage tab 60 3.5 Related plugins 61 3.6 Summary 63Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
CONTENTS xi4 Working with duplicate code 64 4.1 The hidden cost of duplicate code 65 4.2 Identifying duplications 66 Finding your first duplication 67 ■ Finding duplications on a larger scale 69 ■ SonarQube’s duplication metrics 69 Drilling in: from the duplications widget to the Duplications tab 70 4.3 Realizing the impact of code duplication 73 The DRY principle: minimizing and eliminating duplications 73 Duplications vs. size and complexity 74 4.4 Finding duplications across multiple projects 74 Turning on cross-project duplication detection 75 ■ Cross-project duplications in source code tab 75 4.5 Cleaning up your duplications 77 Introduction to refactoring patterns 77 ■ Applying patterns to remove code duplication 77 ■ Time for a new commons library? 79 4.6 Related plugins 80 4.7 Summary 81 5 Optimizing source code documentation 82 5.1 To document or not? 83 5.2 Even commenting has its own metrics 84 How SonarQube calculates metrics 84 ■ What the numbers are telling you 86 5.3 Identifying undocumented code 87 Finding files to improve documentation 88 ■ Viewing the generic tab in the source code viewer 89 5.4 Simplifying your documentation strategy 90 Picking a documentation tool 90 ■ Defining a straightforward process 91 5.5 Related plugins 92 Widget Lab 93 ■ Doxygen 93 5.6 Summary 94Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
CONTENTSxii6 Keeping your source code files elegant 96 6.1 Keeping complexity low 97 Hunting those huge files 97 ■ Complexity: what it looks like and how to fix it 99 6.2 Lack of Cohesion of Methods: files that do too much 101 Getting reports about the LCOM metric 102 ■ Counting responsibilities 103 ■ Refactoring for fewer responsibilities 106 6.3 RFC and couplings: classes with too many friends 108 Response for Class 108 ■ Couplings 110 6.4 Summary 112 7 Improving your application design 113 7.1 Layering your code 114 Looking at dashboard widgets 114 ■ Understanding cycles and unwanted dependencies 115 ■ Moving from project to package level 117 7.2 Discovering dependencies and eliminating cycles 118 Navigating the Dependency Structure Matrix 119 ■ How the DSM works 121 ■ Identifying cycles 124 ■ Library management for Mavenites 127 ■ Browsing the library-dependency tree 127 Who uses this library 131 7.3 Defining your architectural rule set 132 7.4 Summary 134 PART 2 SETTLING IN WITH SONARQUBE . ..................... 135 8 Planning a strategy and expanding your insight 137 8.1 Planning your strategy 138 Picking a metric 139 ■ Holding your ground 141 ■ Moving the goal posts 141 ■ Boy Scout approach: leave the class better than you found it 142 ■ SonarQube time: worst first 143 Re-architect 143 ■ The end game 144 8.2 History and trending 145 Time Machine 145 ■ Events and database cleanup 149 8.3 Everything’s a component 150 Project component view 150 ■ No package history 152Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
CONTENTS xiii8.4 Related plugins 153 Tab Metrics 153 ■ Widget Lab 154 8.5 Summary 154 9 Continuous Inspection with SonarQube 156 9.1 Introducing Continuous Inspection 157 What and how? 157 ■ Life before and after Continuous Inspection 158 ■ The big picture 159 9.2 Triggering your analysis with CI 160 Jenkins setup 162 ■ Other CI systems 167 ■ Best practices 168 9.3 Monitoring quality evolution 169 Exploring differential views in the project dashboard 169 Differential views in the issues drilldown 172 ■ Differential views in the source code viewer 173 ■ Choosing differential periods 173 ■ The Compare service 174 9.4 Related plugins 175 Cutoff 175 ■ Build Breaker 176 9.5 Summary 177 10 Letting SonarQube drive code reviews 178 10.1 Reviewing code in SonarQube 179 Issues: a starting point 179 ■ Confirm, comment, and assign: the simplest workflow options 181 ■ False positives: sometimes SonarQube gets it wrong 183 ■ Changing severity: not every issue is that bad 186 ■ Altering the code to make SonarQube turn a blind eye 186 ■ Viewing the audit trail 188 10.2 Creating manual issues: when the rules aren’t enough 188 Why you would want extra issues 188 ■ Making manual issues 189 10.3 Tracking issues 190 Life cycle of an issue 190 ■ Tracking squashed issues 194 Searching issues 195 10.4 Planning your work with SonarQube’s action plans 196 Why bother with action plans? 196 ■ Managing action plans 196 ■ Using action plans 197 ■ Tracking action plans 198Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
CONTENTSxiv10.5 Structuring a code review 198 Why: talking about code 199 ■ Who 200 ■ When 200 Where 200 ■ How 201 10.6 Related plugins 202 JIRA 202 ■ Taglist 202 ■ Widget Lab 204 10.7 Summary 204 11 IDE integration 205 11.1 What’s supported 206 Generic support 207 ■ Eclipse support 208 11.2 Setting up Eclipse integration 210 Installing the plugin 210 ■ Configuring the server 211 Project association 211 11.3 Working your assigned issues 212 Finding your assigned issues 214 ■ Finding and fixing the code 216 11.4 Running a local analysis 216 11.5 Related plugins 218 Issues Report 218 11.6 Summary 219 PART 3 ADMINISTERING AND EXTENDING..................... 221 12 Security: users, groups, and roles 223 12.1 Creating users and groups 224 Managing users 224 ■ Personalization: what users can manage for themselves 226 ■ Managing groups 227 12.2 Roles: who can do what 229 Project Administrator role 230 ■ User role 231 ■ Code Viewer role 232 ■ Best practices for roles 232 12.3 System administrators 233 12.4 Related plugins 234 LDAP 235 ■ OpenID 235 ■ Crowd 235 ■ PAM 236 12.5 Summary 236Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
CONTENTS xv13 Rule profile administration 237 13.1 Making your own profile: copy and modify 238 Copy or start from scratch? 238 ■ Your first profile edits and their quality implications 240 ■ Adding rules: how to find them and why you’d want to 242 13.2 Profile inheritance 243 Establishing inheritance 243 ■ Managing the relationship 245 13.3 Rule editing 246 Customizing individual rules: editing rule parameters 246 Cookie-cutter rules: the ones you can duplicate 248 ■ Extend Description: the rest of the story 250 ■ Notes: profile-specific records on individual rules 250 13.4 Alerts: knowing when your metrics have crossed the line 252 13.5 How to track profile changes 254 Changelog: who did what, when 254 ■ Profile versions: when changes go into production 255 ■ Profile comparison 256 13.6 Administrative miscellany 256 Project assignment: which project uses which profile 257 Profile backup and restoration 258 ■ Permalinks 258 13.7 Plugins 259 Switch Off Violations 259 ■ Widget Lab 260 13.8 Summary 261 14 Making SonarQube fit your needs 262 14.1 Exploring filters 263 Adding a new filter 263 ■ Customizing the filter view 265 Advanced filtering 266 ■ SonarQube’s default filters 269 14.2 One size doesn’t fit all: managing global dashboards 270 Creating your first global dashboard 271 ■ Customizing your dashboards 272 ■ Defining default global dashboards 275 14.3 Getting notified by SonarQube 277 Activating the notification mechanism 277 ■ Subscribing to event types 278Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
CONTENTSxvi14.4 Adjusting global settings 279 Database cleaner 280 ■ General 281 ■ Localization 282 Server ID 282 14.5 Housekeeping 282 Backing up your SonarQube configuration 282 ■ Working with the update center 283 14.6 Summary 286 15 Managing your projects 287 15.1 Working with project dashboards 288 15.2 Adopting Continuous Inspection more quickly 289 Assigning quality profiles 290 ■ Defining your own metrics 291 Excluding source code from analysis 296 ■ Understanding versions, snapshots, and events 297 15.3 Exploring the rest of the project configuration 299 Changing permissions 300 ■ Setting project links 300 Modifying the project key 302 ■ Deleting projects 303 Miscellaneous settings 304 15.4 Summary 304 16 Writing your own plugin 305 16.1 Understanding SonarQube’s architecture 306 16.2 Implementing the Redmine plugin 307 Creating the plugin Maven project 308 ■ Defining the plugin’s available configuration 310 ■ Describing the metrics: what you’ll calculate and store 313 ■ Implementing your analyzer with a sensor 314 ■ Creating your first widget 318 ■ Supporting internationalization 321 ■ A decorator example 322 16.3 Adding support for new programming languages 324 16.4 Summary 325 appendix A Installation and setup 327 appendix B Analysis 338 index 355Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
foreword The software industry is still a young industry in which software quality means for many people “pain,” “cost,” “constraint,” “nice to have,” “one-shot effort,” or “external reviews.” Fortunately, with the Agile movement, the industry has started to realize dur- ing the last decade that software quality also means “fun,” “built-in,” “rewarding,” and “higher productivity.” Ann Campbell and Patroklos Papapetrou belong to the latter group, and they strongly believe that software quality should be a daily concern shared by all stakeholders in the industry for long-term success. Software quality is divided into external and internal quality. External quality looks at how well the software fulfills its functional requirements: in other words, whether you’re building the right software. Internal quality looks at how well the software is designed/implemented to constantly welcome new changes: in other words, whether you’re building the software right. Industry statistics show that on average, 80% of the cost of software is spent on maintenance; there is considerable variability depending on internal quality. This makes internal quality a key component for the future cost of software. This is the reason why managing code quality of applications has become a major concern for any company that builds or is involved in building software. Traditional approaches to managing code quality propose to test code from time to time, mainly at the end of a development phase. In the best case, this approach leads to delays and re-work; in the worse case, it leads to the shipment of poor-quality, expensive-to-main- tain software. There is therefore an urgent need for a new approach: one that clearly gives ownership of code quality back to the development team; one that emphasizes quality throughout the development phase and has a shorter feedback loop to ensurexvii Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info
FOREWORDxviiirapid resolution of quality problems; in short, a model that builds in quality from the start, rather than considering it after the fact. This is the mission we have set ourselves at SonarSource: to provide tooling for support of this new approach called Continuous Inspection. This is what we believe we have achieved with SonarQube, the open source platform to continuously manage technical debt. SonarQube has a large ecosystem, is widely adopted, and has a very large community. Ann and Patroklos are part of this community and among the most active members, contributing not only by their feedback but also by expanding the ecosystem. When they approached me with the idea of writing a book, I was thrilled, because this is clearly something that is missing in the SonarQube ecosystem. Having Ann and Patroklos writing it also meant it would have some great insight from the community and, more important, that it would contain the end-user perspective on the solution. This book will be your companion in your journey with SonarQube. It will take you from why you should use SonarQube to installation, configuration, administration, and utilization of services, up to extending the platform. You can use it either by read- ing through from A to Z or as a support reference for information about a specific topic. But that isn’t all! Ann and Patroklos also discuss the process surrounding the tool, challenge existing and missing functionality, and provide numerous tips for using SonarQube, all based on their own experience. Whatever your level of familiarity with the product, you’ll learn from this book. This is what, in my opinion, makes this book a unique source of information for a successful implementation. Enjoy! OLIVIER GAUDIN CEO AND COFOUNDER SONARSOURCEDownload from Wow! eBook <www.wowebook.com>www.it-ebooks.info
preface “Would you like to help me write a book about Sonar?” My reaction was immediate: “Yes!” I knew Patroklos Papapetrou from the Sonar mailing list, and I was aware that he was pitching Sonar in Action (now SonarQube in Action, to match the technology’s new name) to Manning. What I didn’t know was that he wanted a coauthor. Because I was a native English speaker and active (and helpful) on the list, he thought of me. I had only been a member of the list for about six months, but I’d been aware of Sonar since late 2008 when my boss came across a mention of Sonar and asked me to evaluate it. I was coding in Java at the time, but I had started my programming career with Perl and C. Lint was your friend, and bugs were found the hard way—by the users. So I found Sonar intriguing. It promised to scan each line of code and point out all kinds of things that were wrong or could go wrong. But to use it, you had to be building with Maven. Unfortunately, we were in an Ant-build shop. Sonar was off the table. Fast-forward to early 2010. Sonar was approximately three years old, but already it was gaining broad acceptance among community and enterprise users and being downloaded more than 2,000 times a month. Patroklos had found the Sonar website while researching software quality tools, and it was a classic boy-meets-software story. (Cue the sappy music.) It didn’t take long before he was in love and Sonar was one of his favorite tools. Meanwhile, I had begun moving our Ant builds to Jenkins (it was still called Hud- son then), and I stumbled across the Sonar plugin for Hudson. It works differently now, but at the time, it performed a shallow “Maven-ization” of a non-Maven project and ran an analysis. Hmmm. Maybe Sonar was back on the table.xix Download from Wow! eBook <www.wowebook.com>www.it-ebooks.info