<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6848648350075612078</id><updated>2011-08-03T13:46:50.504-07:00</updated><category term='data flow static analysis'/><category term='code metrics'/><category term='software quality management'/><category term='development life cycle'/><category term='software development management'/><category term='software development life cycle'/><category term='release management'/><category term='static analysis'/><category term='static code analysis'/><category term='development management'/><category term='code review'/><title type='text'>Static Code Analysis Blog: Static Analysis Best Practices</title><subtitle type='html'>For static source code analysis, data flow static analysis, and code metrics analysis. Also covers  industry-recognized coding guidelines and best practices for static code analysis tools/source code analyzers.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://staticcodeanalysis.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://staticcodeanalysis.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Parasoft - Software Development Management</name><uri>http://www.blogger.com/profile/03687871739357200850</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/_rEnPhrlGGM4/SkpNhFaDOtI/AAAAAAAAAAM/UBC_f0VVEz8/S220/20th-logo-circle-color_200px.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6848648350075612078.post-414367816681038272</id><published>2009-12-30T11:33:00.000-08:00</published><updated>2009-12-30T11:39:46.687-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='static code analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='static analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='code review'/><title type='text'>Static  Analysis - Keep your source code out of court</title><content type='html'>A recent article by Michael Barr mentions how static analysis and peer code reviews can prevent your source code from showing up in court: &lt;br /&gt;&lt;br /&gt;&lt;I&gt;"Don't let your firmware source code end up in court! Adopt a coding standard that will prevent bugs and start following it; don't wait a day. Run lint and other static analysis and code complexity tools yourself, rather than waiting for an expert witness to do it for you. Make peer code reviews a regular part of every working day on your team. And establish a testing environment and regimen that allows for regression testing at the unit and system level. These best practices won't ensure perfect quality, but they will show you tried your best."&lt;/I&gt;&lt;br /&gt;&lt;br /&gt;Read the complete &lt;A HREF="http://www.embedded.com/design/testissue/221901488;jsessionid=N1LXG0M5QSZB5QE1GHPSKH4ATMY32JVN?pgno=1"&gt;The lawyers are coming!&lt;/A&gt; article to learn more.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6848648350075612078-414367816681038272?l=staticcodeanalysis.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://staticcodeanalysis.blogspot.com/feeds/414367816681038272/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/12/static-analysis-keep-you-source-code.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/414367816681038272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/414367816681038272'/><link rel='alternate' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/12/static-analysis-keep-you-source-code.html' title='Static  Analysis - Keep your source code out of court'/><author><name>Parasoft - Software Development Management</name><uri>http://www.blogger.com/profile/03687871739357200850</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/_rEnPhrlGGM4/SkpNhFaDOtI/AAAAAAAAAAM/UBC_f0VVEz8/S220/20th-logo-circle-color_200px.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6848648350075612078.post-5569742173556150898</id><published>2009-11-03T08:02:00.000-08:00</published><updated>2009-11-03T08:20:08.164-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='static code analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='static analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='code review'/><title type='text'>Static Code Analysis at Cisco Systems</title><content type='html'>To comply with corporate quality and security initiatives, Cisco Systems adopted static analysis as well as unit testing and code review. Read the &lt;A HREF="http://www.parasoft.com/jsp/printables/Cisco_Systems_Case_Study.pdf?path=/jsp/products"&gt;Static Analysis at Cisco Systems Case Study&lt;/A&gt; to learn how they automated these practices and seamlessly integrated them into their existing processes to deliver compliant code without impeding productivity.&lt;br /&gt;&lt;br /&gt;You can also access this case study and other case studies at the Parasoft Resource Centers for:&lt;br /&gt;&lt;UL&gt;&lt;br /&gt;&lt;LI&gt;&lt;a href="http://www.parasoft.com/jsp/solutions/java_solution.jsp?javaSolution=2"&gt;Java Testing&lt;/a&gt;&lt;br /&gt;&lt;LI&gt;&lt;a href="http://www.parasoft.com/jsp/solutions/compliance.jsp?compliance=2"&gt;Compliance (including FDA, Security, PCI DSS, DO-178B)&lt;/a&gt;&lt;br /&gt;&lt;LI&gt;&lt;a href="http://www.parasoft.com/jsp/solutions/application_security_solution.jsp?appSecSol=2"&gt;Application Security&lt;/a&gt;&lt;br /&gt;&lt;/UL&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6848648350075612078-5569742173556150898?l=staticcodeanalysis.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://staticcodeanalysis.blogspot.com/feeds/5569742173556150898/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/11/static-code-analysis-at-cisco-systems.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/5569742173556150898'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/5569742173556150898'/><link rel='alternate' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/11/static-code-analysis-at-cisco-systems.html' title='Static Code Analysis at Cisco Systems'/><author><name>Parasoft - Software Development Management</name><uri>http://www.blogger.com/profile/03687871739357200850</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/_rEnPhrlGGM4/SkpNhFaDOtI/AAAAAAAAAAM/UBC_f0VVEz8/S220/20th-logo-circle-color_200px.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6848648350075612078.post-8617823931520795517</id><published>2009-08-28T14:44:00.000-07:00</published><updated>2009-08-28T14:52:50.132-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='static code analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='static analysis'/><title type='text'>Using Static Analysis for Embedded Software Optimization</title><content type='html'>A recent article by Nick McNamara mentions how static code analysis is useful for embedded software optimization: &lt;br /&gt;&lt;br /&gt;&lt;I&gt;"The ESO approach is based around four identifiable and measurable phases: analysis, development, test and maintenance. Firstly, the code base is analysed using any number of tools and techniques to understand worst-case execution time behaviour, or performance of static source-code analysis.&lt;br /&gt;&lt;br /&gt;A typical embedded system may contain up to a million lines of source code, or even more. Checking this huge volume of code by hand is clearly not a practical option. Static analysis tries to identify code sequences that might result in buffer overflows, resource leaks, or many other reliability and security problems. Source code analysers do an excellent job at locating a significant class of defects that are not detected by compilers during standard builds and often go undetected during run-time testing or typical field operation. "&lt;/I&gt;&lt;br /&gt;&lt;br /&gt;Read the complete &lt;A HREF="http://www.embedded.com/design/219401445?pgno=1"&gt;Reducing costs with embedded software optimization&lt;/A&gt; for more on how static code analysis adds value in this context.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6848648350075612078-8617823931520795517?l=staticcodeanalysis.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://staticcodeanalysis.blogspot.com/feeds/8617823931520795517/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/08/using-static-analysis-for-embedded.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/8617823931520795517'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/8617823931520795517'/><link rel='alternate' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/08/using-static-analysis-for-embedded.html' title='Using Static Analysis for Embedded Software Optimization'/><author><name>Parasoft - Software Development Management</name><uri>http://www.blogger.com/profile/03687871739357200850</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/_rEnPhrlGGM4/SkpNhFaDOtI/AAAAAAAAAAM/UBC_f0VVEz8/S220/20th-logo-circle-color_200px.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6848648350075612078.post-5744049902083789253</id><published>2009-08-17T09:33:00.000-07:00</published><updated>2009-08-17T09:57:31.228-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='release management'/><category scheme='http://www.blogger.com/atom/ns#' term='software quality management'/><category scheme='http://www.blogger.com/atom/ns#' term='software development life cycle'/><category scheme='http://www.blogger.com/atom/ns#' term='development management'/><category scheme='http://www.blogger.com/atom/ns#' term='static code analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='software development management'/><category scheme='http://www.blogger.com/atom/ns#' term='static analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='development life cycle'/><title type='text'>Static Analysis in Policy-Driven Development</title><content type='html'>In an article introducing &lt;A HREF="http://www.parasoft.com"&gt;Parasoft&lt;/A&gt; &lt;A HREF="http://www.parasoft.com/alm"&gt;Concerto&lt;/A&gt; -- a new software development management tool that facilitates end-to-end SLDC process visibility and control to ensure that quality software can be produced consistently &amp; efficiently -- &lt;A HREF="http://searchsoftwarequality.techtarget.com/news/article/0,289142,sid92_gci1364383,00.html?track=NL-516&amp;ad=720753&amp;asrc=EM_USC_8971235&amp;uid=6329764"&gt;SearchSoftwareQuality.com&lt;/A&gt; explains how static code analysis operates in the context of policy-driven development. &lt;br /&gt;&lt;br /&gt;They explain that Parasoft Concerto takes a requirement, wraps it with a policy and drives it through the infrastructure. When it's completed, Concerto checks that it met policy expectations. The key is being able to to passively monitor and be unobtrusive to a developer's work; Concerto nudges them each time their actions don't align with policy expectations.&lt;br /&gt;&lt;br /&gt;For example, &lt;A HREF="http://www.parasoft.com/static_analysis_resourcese"&gt;static code analysis&lt;/A&gt; identifies an error and the developer tries to mark the requirement as complete. With policy-driven task management, the developer would be notified that there is still an error that needs to be remediated.&lt;br /&gt;&lt;br /&gt;You can read the complete article at  &lt;A HREF="http://searchsoftwarequality.techtarget.com/news/article/0,289142,sid92_gci1364383,00.html?track=NL-516&amp;ad=720753&amp;asrc=EM_USC_8971235&amp;uid=6329764"&gt;SearchSoftwareQuality.com&lt;/A&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6848648350075612078-5744049902083789253?l=staticcodeanalysis.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://staticcodeanalysis.blogspot.com/feeds/5744049902083789253/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/08/static-analysis-in-policy-driven.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/5744049902083789253'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/5744049902083789253'/><link rel='alternate' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/08/static-analysis-in-policy-driven.html' title='Static Analysis in Policy-Driven Development'/><author><name>Parasoft - Software Development Management</name><uri>http://www.blogger.com/profile/03687871739357200850</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/_rEnPhrlGGM4/SkpNhFaDOtI/AAAAAAAAAAM/UBC_f0VVEz8/S220/20th-logo-circle-color_200px.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6848648350075612078.post-8614247458723342400</id><published>2009-08-06T10:42:00.000-07:00</published><updated>2009-08-06T10:45:48.857-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='static code analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='static analysis'/><title type='text'>Static Analysis Symposium</title><content type='html'>The Sixteenth International Static Analysis Symposium (SAS 2009), to be held in Los Angeles August 9-11, is designed to present theoretical, practical, and application advances in the area of static analysis. Get more details at the &lt;A HREF="http://sas09.cs.ucdavis.edu/"&gt;Static Analysis Symposium site&lt;/A&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6848648350075612078-8614247458723342400?l=staticcodeanalysis.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://staticcodeanalysis.blogspot.com/feeds/8614247458723342400/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/08/static-analysis-symposium.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/8614247458723342400'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/8614247458723342400'/><link rel='alternate' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/08/static-analysis-symposium.html' title='Static Analysis Symposium'/><author><name>Parasoft - Software Development Management</name><uri>http://www.blogger.com/profile/03687871739357200850</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/_rEnPhrlGGM4/SkpNhFaDOtI/AAAAAAAAAAM/UBC_f0VVEz8/S220/20th-logo-circle-color_200px.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6848648350075612078.post-7997431815197774203</id><published>2009-07-31T16:54:00.000-07:00</published><updated>2009-07-31T16:58:32.955-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='static code analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='static analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='code review'/><title type='text'>Making Static Analysis a Part of Code Review</title><content type='html'>A recent article by S. Tucker Taft and Robert B.K. Dewar begins: &lt;br /&gt;&lt;br /&gt;&lt;I&gt;"As static analysis tools have become more sophisticated, their role in the software development process has become a subject of debate. Can a project team use a static analysis tool instead of other, presumably more labor-intensive steps in the normal process of coding, testing, verifying, validating, and ultimately, certifying critical software? The answer is an unequivocal 'yes.'"&lt;/I&gt;&lt;br /&gt;&lt;br /&gt;Read the complete &lt;A HREF="http://www.embedded-computing.com/articles/id/?4014"&gt;Making Static Analysis a Part of Code Review&lt;/A&gt; article for their thoughts on how static analysis tools can ease the difficulty of reviewing unfamiliar code.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6848648350075612078-7997431815197774203?l=staticcodeanalysis.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://staticcodeanalysis.blogspot.com/feeds/7997431815197774203/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/07/making-static-analysis-part-of-code.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/7997431815197774203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/7997431815197774203'/><link rel='alternate' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/07/making-static-analysis-part-of-code.html' title='Making Static Analysis a Part of Code Review'/><author><name>Parasoft - Software Development Management</name><uri>http://www.blogger.com/profile/03687871739357200850</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/_rEnPhrlGGM4/SkpNhFaDOtI/AAAAAAAAAAM/UBC_f0VVEz8/S220/20th-logo-circle-color_200px.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6848648350075612078.post-74346365443004262</id><published>2009-07-07T11:46:00.000-07:00</published><updated>2009-07-07T12:32:41.027-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='code metrics'/><category scheme='http://www.blogger.com/atom/ns#' term='data flow static analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='static code analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='static analysis'/><title type='text'>Static Code Analysis Best Practices</title><content type='html'>In this interview, Adam Kolawa—Parasoft CEO and co-founder—discusses why, when, and how to apply three different types of static source code analysis: static code analysis, data flow static analysis, and code metrics analysis. Read on to learn how static analysis can help your team ensure that code meets uniform expectations around security, reliability, performance, and maintainability—and how to get started as painlessly as possible.&lt;br /&gt;&lt;br /&gt;&lt;H2&gt;What do you mean by “static analysis”?&lt;/H2&gt;&lt;br /&gt;I mean statically analyzing code to monitor whether it meets uniform expectations around security, reliability, performance, and maintainability. Done properly, this static code analysis provides a foundation for producing solid code by exposing structural errors and preventing entire classes of errors. At Parasoft, we’ve found that the most effective static analysis encompasses static code analysis, data flow static analysis, and code metrics analysis.&lt;br /&gt;&lt;br /&gt;&lt;H2&gt;Let’s take a closer look at those three breeds of static analysis. First off, static code analysis. What is it and why is it valuable?&lt;/H2&gt;&lt;br /&gt;By static code analysis, I mean scanning the source code and checking whether it has patterns known to cause defects or impede reuse and agility. This involves monitoring compliance to coding standard rules—rules for preventing improper language usage, satisfying industry standards (MISRA, JSF, Ellemtel, etc.), and enforcing internal coding guidelines. &lt;br /&gt;&lt;br /&gt;If you nip these issues in the bud by finding and fixing dangerous code as it is introduced, you significantly reduce the amount of testing and debugging required later on—when the difficulty and cost of dealing with each defect increases by over an order of magnitude. &lt;br /&gt;&lt;br /&gt;Many categories of defects can be prevented in this manner, including defects related to memory leaks, resource leaks, and security vulnerabilities. In fact, simply using static code analysis to enforce proper input validation can prevent approximately 70% of the security problems cited by OWASP, the industry-leading security community.&lt;br /&gt;&lt;br /&gt;&lt;H2&gt;What’s data flow static analysis and why is it valuable?&lt;/H2&gt;&lt;br /&gt;Data flow static analysis statically simulates application execution paths, which may cross multiple units, components, and files. It’s like testing without actually executing the code. It can automatically detect potential runtime errors such as resource leaks, NullPointerExceptions, SQL injections, and other security vulnerabilities. This enables early and effortless detection of critical runtime errors that might otherwise take weeks to find. &lt;br /&gt;&lt;br /&gt;While static code analysis is an error prevention practice, data flow static analysis is an error-detection practice. Like all error-detection practices, it’s not 100% accurate and you can’t expect that it will uncover each and every bug lurking in your application.&lt;br /&gt;&lt;br /&gt;The main difference between static code analysis and data flow static analysis is that with pattern-based static code analysis, you can absolutely guarantee that certain classes of defects will not occur as long as you find and fix the coding constructs known to cause these defects. With data flow static analysis, you are identifying defects that could actually occur when real application paths are exercised—not just dangerous coding constructs. But you have to realize that you will inevitably overlook some bugs, and might have a higher ratio of false positives than you encounter with static code analysis.&lt;br /&gt;&lt;br /&gt;&lt;H2&gt;If data flow static analysis can’t find all the bugs, how do you automatically detect the remaining bugs?&lt;/H2&gt;&lt;br /&gt;&lt;CENTER&gt;***&lt;/CENTER&gt;&lt;br /&gt;To read more, download Parasoft's complete &lt;A HREF="http://www.parasoft.com/jsp/printables/When_Why_How_Code_Analysis.pdf?path=/jsp/products/article_reg.jsp"&gt;"Static Analysis Best Practices"&lt;/A&gt; paper as a PDF. You can also access this paper at the &lt;A HREF="http://www.parasoft.com/static_analysis_resources"&gt;Static Code Analysis Resources&lt;/A&gt; center.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6848648350075612078-74346365443004262?l=staticcodeanalysis.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://staticcodeanalysis.blogspot.com/feeds/74346365443004262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/07/static-code-analysis-best-practices.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/74346365443004262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/74346365443004262'/><link rel='alternate' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/07/static-code-analysis-best-practices.html' title='Static Code Analysis Best Practices'/><author><name>Parasoft - Software Development Management</name><uri>http://www.blogger.com/profile/03687871739357200850</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/_rEnPhrlGGM4/SkpNhFaDOtI/AAAAAAAAAAM/UBC_f0VVEz8/S220/20th-logo-circle-color_200px.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6848648350075612078.post-5732657084726185060</id><published>2009-06-25T10:52:00.000-07:00</published><updated>2009-07-07T11:48:34.426-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='static code analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='static analysis'/><title type='text'>Static Code Analysis</title><content type='html'>&lt;P&gt;This blog provides resources related to static analysis, including pattern-based static code analysis, data flow static analysis, and code metrics. It also presents industry-recognized coding guidelines and covers best practices for static code analysis tools/source code analyzers.&lt;/P&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6848648350075612078-5732657084726185060?l=staticcodeanalysis.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://staticcodeanalysis.blogspot.com/feeds/5732657084726185060/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/06/static-code-analysis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/5732657084726185060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6848648350075612078/posts/default/5732657084726185060'/><link rel='alternate' type='text/html' href='http://staticcodeanalysis.blogspot.com/2009/06/static-code-analysis.html' title='Static Code Analysis'/><author><name>Parasoft - Software Development Management</name><uri>http://www.blogger.com/profile/03687871739357200850</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/_rEnPhrlGGM4/SkpNhFaDOtI/AAAAAAAAAAM/UBC_f0VVEz8/S220/20th-logo-circle-color_200px.jpg'/></author><thr:total>0</thr:total></entry></feed>
