Skip to content

[refactor] Rework analyzer labeling - #5127

Open
gulyasgergely902 wants to merge 1 commit into
Ericsson:masterfrom
gulyasgergely902:rework-analyzer-labeling
Open

gulyasgergely902 wants to merge 1 commit into
Ericsson:masterfrom
gulyasgergely902:rework-analyzer-labeling

Conversation

@gulyasgergely902

Copy link
Copy Markdown
Collaborator

This change reworks how checker labels are working inside CodeChecker.

The guideline files are now separated from the rules. Each type of rule (CWE, Sei-Cert, OWASP, etc.) have a separate file collecting all the rules the given type has. Every rule has its ID and optionally its title and URL. The guideline files are now only serves as a collection of rule IDs.

Label files also got reworked: containing less data for any given checker, guideline definitions are discarded and now derived from the rule ID based on which guideline contains the given rule. Every rule is now added by rule:<rule_name>. Profiles are also reworked, the generic profiles (default, sensitive and extreme) are now contained in eachother meaning only the smallest set must be defined and the checker will automatically be in every broader set. E.g. if a checker must be in sensitive and extreme, only sensitive has to be defined, it will be in extreme automatically.

This change was made to prevent user mistakes when editing labelling, guidelines or rules. Every component (rules, guidelines, labels) has its own source of truth now which makes easier the further development.

@gulyasgergely902 gulyasgergely902 added this to the release 6.30.0 milestone Oct 5, 2026
@gulyasgergely902
gulyasgergely902 force-pushed the rework-analyzer-labeling branch 3 times, most recently from bfab3bd to dc342dd Compare October 7, 2026 09:31
This change reworks how checker labels are working inside CodeChecker.

The guideline files are now separated from the rules. Each type of rule
(CWE, Sei-Cert, OWASP, etc.) have a separate file collecting all the rules
the given type has. Every rule has its ID and optionally its title and URL.
The guideline files are now only serves as a collection of rule IDs.

Label files also got reworked: containing less data for any given checker,
guideline definitions are discarded and now derived from the rule ID based
on which guideline contains the given rule. Every rule is now added by
`rule:<rule_name>`. Profiles are also reworked, the generic profiles (default,
sensitive and extreme) are now contained in eachother meaning only the
smallest set must be defined and the checker will automatically be in every
broader set. E.g. if a checker must be in sensitive and extreme, only sensitive
has to be defined, it will be in extreme automatically.

This change was made to prevent user mistakes when editing labelling, guidelines
or rules. Every component (rules, guidelines, labels) has its own source of truth
now which makes easier the further development.
@gulyasgergely902
gulyasgergely902 force-pushed the rework-analyzer-labeling branch from dc342dd to 57bad77 Compare October 7, 2026 09:41

@barnabasdomozi barnabasdomozi left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please fix the failing test cases.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants