6 ms·
Inspectopedia: Analyze code against inspections in your IDE or CI pipeline
- KerryBeetge 3y ago[flagged]
- deleted 2y ago[deleted]
- bugbuddy 2y agoThis is super cool of them. It makes me feel like renewing my license.
- armchairhacker 2y agoJetBrains inspections are great, but I wish there was a way to run them programmatically so they could be checked in CI. (EDIT: should have RTFA)
- RockRobotRock 2y agoDo they integrate existing linters in their IDE or have their own secret sauce? Probably a bit of both.
- varikin 2y agoAll the Jetbrains IDEs have their own custom linter. It's pretty good, but my complaint has always been the inability to use it in CI/CD and to generate reports. The way I read this, they pulled their custom linter out of the IDEs and made it a standalone tool that can be added to CI/CD, which is great.
- lpapez 2y ago> JetBrains inspections are great, but I wish there was a way to run them programmatically so they could be checked in CI. Which is literally what the post is about...
- Denvercoder9 2y ago> I wish there was a way to run them programmatically so they could be checked in CI. I haven't used it, but thIs seems to be what their Qodana product is for: https://www.jetbrains.com/qodana/ https://www.jetbrains.com/qodana/
- KerryBeetge 2y agoExactly right.
- s900mhz 2y agoI THINK that’s exactly what this product is? https://www.jetbrains.com/qodana/ https://www.jetbrains.com/qodana/ Edited: Oops, should have refreshed. Someone beat me to it
- RockRobotRock 2y agoPyCharm has saved me from so many stupid mistakes that would easily waste 15 minutes if I hadn't noticed them. I don't know how you could write high level code without an IDE.
- zer00eyz 2y agoI use jet brains products, and I spend a fair bit of time in all sorts of flavors and setups in vim. Neovim will let you configure your env to provide 90 percent of what an ide will do. The 10 percent isnt "missing" its just going to be very different... See how the other half lives and you might find some features you like and bring back home. You might find yourself running vim in pycharm ;)
- jiggawatts 2y agoYou really can’t even begin to approach what the IntelliJ tools can do with a mere text editor. You’ll also spend more time tinkering with your Vim plugins than actually coding.
- xcv123 2y agoYep. With IntelliJ you just install the ideavim editor plugin with default settings then get to work. https://github.com/JetBrains/ideavim https://github.com/JetBrains/ideavim Or you can waste months pissing around with Vim plugins to create a poor mans IDE out of sticks and stones like a caveman.
- Nullabillity 2y agoIdeaVim has the usual Vim emulation problem. It does an okay job emulating baseline Vim, but it doesn't emulate your Vim setup, nor does it even try to integrate the rest of IntelliJ in a way that feels native (compared to something like evil-mode). It's clearly not used by either its developers or the people who keep recommending it. It's the Microsoft POSIX Subsystem of text editors.
- albertzeyer 2y agoI think some free-for-open-source-projects licence or so would make sense here. Or maybe make this completely free? It's good advertisement for their IDEs. Note, I basically have scripted the same functionality as Qodana for our CI, but using the already existing capabilities of the IDE: https://github.com/rwth-i6/returnn/blob/master/tests/pycharm-inspect.py https://github.com/rwth-i6/returnn/blob/master/tests/pycharm... This script generates exactly the same warnings as the IDE does. It downloads some PyCharm Community version and installs it. It uses the bin/inspect.sh tool which is provided by the IDE. The IDE bin/inspect.sh needs an existing PyCharm project (all the XML files etc), so this script creates the project files automatically. This also needs the Python stubs, so this script can create those as well, in the same way the IDE would create them, or alternatively it can download them (I created them in advance for some PyCharm versions). But then, bin/inspect.sh does not generate all the warnings you see in the IDE. The IDE additionally runs pycodestyle, and so I do the same in the script. So, as you see, it took a bit of effort to get to all that within the CI, but now it works and I get the same warnings as in the IDE.
- ellisv 2y agoThere is a community license, which includes a subset of their supported languages. https://www.jetbrains.com/help/qodana/pricing.html#license-comparison-matrix https://www.jetbrains.com/help/qodana/pricing.html#license-c...
- lol768 2y agoMust admit this seems like a very odd way of doing it, to me. Normally JetBrains are pretty decent at supporting OSS endeavours. At present, OSS Java libraries can use Qodana Community, but OSS .NET libraries can't.
- Denvercoder9 2y agoQodana Community for .NET is currently in Early Access: https://www.jetbrains.com/help/qodana/qodana-dotnet-community.html https://www.jetbrains.com/help/qodana/qodana-dotnet-communit...
- wombatrose 2y ago[dead]
- keybored 2y agoIntellij has some nice static analysis for Java.[1] But I want it in my face. Because we had a bug where we used `==` on a boxed primitive. And the inspection didn’t help because it was just sitting there with some faint yellow background or whatever it is if you happened to visit that file. And the light-bulb action thing is effectively active on any line since you get the option of “invert conditional” or “use block in lambda” and useless things like that. Well I’ll just hedge and say that it wasn’t obvious to the three of us how to get an in-your-face warning. [1] EDIT: I realize now that my brain for some reason thought that “in your face” would immediately translate to everybody else as “fail the build”. What a drunken (but not drunk though) mistake.
- red0point 2y agoIf I remember correctly, there is an extensive „Inspection“ settings page where you can enable / disable / set the levels (hoe much in-your/face) of exactly such checks. Maybe this would suit you? https://www.jetbrains.com/help/idea/code-inspection.html#access-inspections-and-settings https://www.jetbrains.com/help/idea/code-inspection.html#acc...
- jupp0r 2y agoYou shouldn't rely on a human reading an in-their-face warning. If you consider a particular static analysis check to be vital, run it in CI and make the PR introducing it red. Everything else is just an upcoming post mortem with "we should have noticed this" waiting to happen to you.
- keybored 2y ago> You shouldn't rely on a human reading an in-their-face warning. If you consider a particular static analysis check to be vital, run it in CI and make the PR introducing it red. That’s what I meant (edited now). I want compilation to fail. Or whatever “CI” is. We didn’t find a way to promote inspections to some kind of static analysis run.
- jupp0r 2y ago
- __jonas 2y agoWhen I was using IDEA a lot I've had this one come up a couple of times and I've really appreciated it every time: https://www.jetbrains.com/help/inspectopedia/SuspiciousNameCombination.html https://www.jetbrains.com/help/inspectopedia/SuspiciousNameC... I thought it was so sweet that someone had thought of this very specific possible mistake and warned me about it to save me a little bit of time and trouble. (Maybe not this exact one since it was in JS not Java I believe, but the same idea)
- deleted 2y ago[deleted]
- joshstrange 2y agoYep, I had some scaling code that swapped width/height in one place by accident and IDEA caught it. I really love this tool.
- MichaelMug 2y agoDoes this do the same thing as SonarQube?
- plutokras 2y agoSeems like that's the case.
- galaxyLogic 2y agoIn WebStorm if I write: let see = someOb.comments; it tells me I have the error : "Unresolved Variable 'comments' ". But the error goes away if I rewrite it as: let see = someOb ['comments']; Why is that?
- GenerocUsername 2y agoAST and Static Code analysis. Much easier to interpolate the hardcoded token rather than a string...despite the string being a final string and not some concatenation or dynamic value
- kroltan 2y agoNot really at all, the type checker understands it is a field reference (it's just an alternative syntax after all, it is absolutely 0% difference in behaviour. However, it's a common typed-javascript idiom to use string-indexing when you're probing a value of unknown type. Even Typescript has settings to accept this.
- galaxyLogic 2y agoI get it it's a nice idiom. But neither version is an error and the "correct" version is more verbose. Less verbose is better in my preference when it is just as clear or even clearer (because it is less verbose). And this is not TypeScript but JavaScript. I guess my question is, how can I make the ob.something NOT be (listed as) an error? When is it not an error (according to WebStorm linter)?
- kroltan 2y agoI don't think "unresolved variable" is listed as an actual error in plain JS in WebStorm? At least by default. In any case, like any inspection, you can adjust its severity to whatever you find appropriate, including "don't show it at all". File > Settings > Editor > Inspections > Javascript and Typescript > General > Unresolved reference. Or directly from the "Show Context Actions" action (Alt+enter or whatever you have it set to, the same combination that shows refactoring actions), you can navigate the inspection like a submenu and select "Edit inspection profile setting". https://i.imgur.com/3XCwxI1.png https://i.imgur.com/3XCwxI1.png
- wslh 2y agoNo Rust.
- jasonlotito 2y agoProbably because RustRover is still in preview. https://www.jetbrains.com/rust/ https://www.jetbrains.com/rust/
- mdaniel 2y agoAnd even that's only partially true: they didn't pull the rust plugin just started to whine about it: https://plugins.jetbrains.com/plugin/8182--deprecated-rust https://plugins.jetbrains.com/plugin/8182--deprecated-rust and https://github.com/intellij-rust/intellij-rust/blob/c6657c02bb62075bf7b7ceb84d000f93dda34dc1/LICENSE https://github.com/intellij-rust/intellij-rust/blob/c6657c02... (MIT)
- rglover 2y ago> The influx of AI-generated code, an ever-evolving threat landscape, and the push for shorter release cycles can jeopardize code quality. All of these factors dictate the need for continuous and accurate code analysis to help development teams spot and fix code issues early on so they can consistently deliver readable, maintainable and secure code. You know, I read stuff like this and I wonder if anybody has thought maybe those things jeopardizing code quality should be discouraged as opposed to adding yet-another-tool.
- alfalfasprout 2y agoSadly, it's like outsourcing. People only learn once it comes back to bite them. It'll typically be in the form of a major security breach or the codebase becoming so painful to work in that it affects the business.
- sb8244 2y agoI mean, once the cat is out of the bag you have to care for it. It can be discouraged, but people will still use it, so helping is still good. Plus it helps non AI use cases at same time
- jasonlotito 2y agoI mean, this isn't adding yet-another-tool. These inspections have existed for years inside of JetBrains IDEs. I feel like this is just an "encyclopedia of inspections." I don't see any other uses for it. They are just providing everything they are testing in the various tools they offer.
- manbash 2y agoI actually don't understand the "AI-generated code" excuse. Code analysis should be part of the pipeline regardless. It's not like people are perfect code developers.
- dmolony 2y agoI think what they mean is 'an influx of AI-generated code (which is frequently garbage)'