Skip to content

6 Quality Assurance (QA)

CarlosSouza87 edited this page Jun 5, 2023 · 1 revision

👨‍🚀 Quality Assurance (QA)

In this part of the project, we seek to analyze possible vulnerabilities, errors and language-specific rules.Following the “Quality Assurance” policy with bidirectional tracking. Developers should apply this rule in all commits made to the project.

Quality Assurance (QA), which can be translated as “Quality Assurance”, refers to a function of guaranteeing quality in the development of a product or service. Roughly speaking, its performance involves verifying compliance with certain criteria and methods throughout the operational processes.

How is the analysis done?
  • Analysis is performed using static code analysis tools that can detect potential security vulnerabilities, syntax errors, performance issues, poorly formatted code, code duplication, and other violations of good coding practices.

  • Code quality analysis is critical to ensure that the developed software meets the customer's requirements and is free of bugs and vulnerabilities. Such code quality directly affects the quality of the software, and it is important for developers to be able to write clean code and well-structured, to ensure that the software meets quality and security standards.

  • Furthermore, code quality analysis is a critical part of the software development process, allowing developers to identify issues early, saving time and money in the long run. For these reasons, source code quality analysis is an important and indispensable practice in modern software development.

🛠️ SONARCLOUD

To carry out the Q&A method, we used the SonarCloud tool, which is a cloud service, which works through a connection to the cloud-based code repository service that the developer already uses, in which we use github.

  • When registering for SonarCloud for the first time, you need to choose which repository provider you want to connect to. Then, just enter the platform with your credentials already registered in this service so that your SonarCloud account is created and linked to the account at the repository provider.

  • Once complete, you can import organizations from your repository service account into your SonarCloud account and then import repositories from those organizations. Each imported organization becomes a SonarCloud organization and each imported repository becomes a SonarCloud project.

Sonarcloud functionality

SonarCloud is able to identify issues and security hotspots in your code. They are designed to minimize the number of false positives, so if SonarCloud identifies an issue, it is certainly something that should be fixed.

Issues are grouped into three types in SonarCloud:

  • Code smell: these are characteristics of the code that, although they do not prevent the proper functioning of the program, may indicate deeper problems, which negatively affect the maintainability of the code.

  • Bugs: Errors in the code that can prevent the program from working as expected. They affect code reliability.

  • Vulnerabilities: are problems in the code that can be exploited by malicious people to compromise the security of the application.

In the image below, we can visualize the sonarcloud configured in the project and analyzing a task:

This tool is designed to be integrated into the software development process. In order to intervene and prevent issues from reaching production, it works in three different places: the editor, the pull request, and the codebase. Upon completion, the scan results are sent automatically, where they are processed and made available on the dashboard. There the user will find all the results of the analyzed codes in their repositories. You can even sort and filter the results according to a wide range of criteria to get a clear picture of the state of your code.

Clone this wiki locally