Finding defects without execution.
WHAT STATIC TECHNIQUES ARE
Examining artefacts without running them.
WHAT CAN BE REVIEWED
Requirements Designs Code Test cases Documentation
WHY REVIEWING REQUIREMENTS MATTERS MOST
A defect in requirements propagates into everything downstream.
WHAT TO LOOK FOR IN REQUIREMENTS
Ambiguity Contradiction Missing cases Untestable statements Assumptions
WHAT CODE REVIEW FINDS
Logic errors Missing error handling Security weaknesses Maintainability problems
WHAT IT FINDS THAT TESTING DOES NOT
Problems in code paths tests do not reach Issues of clarity and structure
WHAT STATIC ANALYSIS TOOLS FIND
Known defect patterns Unused and unreachable code Type and null problems Security patterns
WHAT THEY COST
False positives requiring configuration.
WHAT TO DO ABOUT THOSE
Tune the rules rather than ignoring output.
WHY
An ignored tool provides nothing.
WHAT TO RUN AUTOMATICALLY
Static analysis, on every change.
WHAT REVIEWS REQUIRE TO BE EFFECTIVE
Small changes Focus Written findings Follow-up that they were addressed