4 ms·
Agree on inaccuracy, but I don't think that this reduces its value as much as you posit. Ultimately other forms of static analysis won't guarantee my code is g
by pentaphobe 3y ago
Agree on inaccuracy, but I don't think that this reduces its value as much as you posit.
Ultimately other forms of static analysis won't guarantee my code is good, but I still use linters.
Similarly, tests (unit, integration, etc..) won't prove that nothing can go wrong - but I'm not going to stop writing them.
I'd love to be using a "perfect" language which could prove my program correct at compile time, and would presumedly also make static analysis borderline magical for these use cases - but until that's an option I think there's a place for all these tools. (Beyond simply ticking compliance boxes)
With all that said, false negatives are indeed a hard problem - and one not helped by large orgs having painful bureaucracy around false _positives_.
Some of this appears to be the fault of tooling (need better filtration, deferral, weighting) but much of it seems a side effect of institutional silo's rather than a lack of perfect analyses.
TLDR; pobody's nerfect, but more info generally better than less