You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

IssueMetricFormulaFactoryImpl.java 12KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240
  1. /*
  2. * SonarQube
  3. * Copyright (C) 2009-2021 SonarSource SA
  4. * mailto:info AT sonarsource DOT com
  5. *
  6. * This program is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation; either
  9. * version 3 of the License, or (at your option) any later version.
  10. *
  11. * This program is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public License
  17. * along with this program; if not, write to the Free Software Foundation,
  18. * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  19. */
  20. package org.sonar.server.measure.live;
  21. import java.util.List;
  22. import java.util.Optional;
  23. import java.util.Set;
  24. import org.sonar.api.issue.Issue;
  25. import org.sonar.api.measures.CoreMetrics;
  26. import org.sonar.api.measures.Metric;
  27. import org.sonar.api.rule.Severity;
  28. import org.sonar.api.rules.RuleType;
  29. import org.sonar.server.measure.Rating;
  30. import static java.util.Arrays.asList;
  31. import static org.sonar.server.measure.Rating.RATING_BY_SEVERITY;
  32. import static org.sonar.server.security.SecurityReviewRating.computePercent;
  33. import static org.sonar.server.security.SecurityReviewRating.computeRating;
  34. public class IssueMetricFormulaFactoryImpl implements IssueMetricFormulaFactory {
  35. private static final List<IssueMetricFormula> FORMULAS = asList(
  36. new IssueMetricFormula(CoreMetrics.CODE_SMELLS, false,
  37. (context, issues) -> context.setValue(issues.countUnresolvedByType(RuleType.CODE_SMELL, false))),
  38. new IssueMetricFormula(CoreMetrics.BUGS, false,
  39. (context, issues) -> context.setValue(issues.countUnresolvedByType(RuleType.BUG, false))),
  40. new IssueMetricFormula(CoreMetrics.VULNERABILITIES, false,
  41. (context, issues) -> context.setValue(issues.countUnresolvedByType(RuleType.VULNERABILITY, false))),
  42. new IssueMetricFormula(CoreMetrics.SECURITY_HOTSPOTS, false,
  43. (context, issues) -> context.setValue(issues.countUnresolvedByType(RuleType.SECURITY_HOTSPOT, false))),
  44. new IssueMetricFormula(CoreMetrics.VIOLATIONS, false,
  45. (context, issues) -> context.setValue(issues.countUnresolved(false))),
  46. new IssueMetricFormula(CoreMetrics.BLOCKER_VIOLATIONS, false,
  47. (context, issues) -> context.setValue(issues.countUnresolvedBySeverity(Severity.BLOCKER, false))),
  48. new IssueMetricFormula(CoreMetrics.CRITICAL_VIOLATIONS, false,
  49. (context, issues) -> context.setValue(issues.countUnresolvedBySeverity(Severity.CRITICAL, false))),
  50. new IssueMetricFormula(CoreMetrics.MAJOR_VIOLATIONS, false,
  51. (context, issues) -> context.setValue(issues.countUnresolvedBySeverity(Severity.MAJOR, false))),
  52. new IssueMetricFormula(CoreMetrics.MINOR_VIOLATIONS, false,
  53. (context, issues) -> context.setValue(issues.countUnresolvedBySeverity(Severity.MINOR, false))),
  54. new IssueMetricFormula(CoreMetrics.INFO_VIOLATIONS, false,
  55. (context, issues) -> context.setValue(issues.countUnresolvedBySeverity(Severity.INFO, false))),
  56. new IssueMetricFormula(CoreMetrics.FALSE_POSITIVE_ISSUES, false,
  57. (context, issues) -> context.setValue(issues.countByResolution(Issue.RESOLUTION_FALSE_POSITIVE, false))),
  58. new IssueMetricFormula(CoreMetrics.WONT_FIX_ISSUES, false,
  59. (context, issues) -> context.setValue(issues.countByResolution(Issue.RESOLUTION_WONT_FIX, false))),
  60. new IssueMetricFormula(CoreMetrics.OPEN_ISSUES, false,
  61. (context, issues) -> context.setValue(issues.countByStatus(Issue.STATUS_OPEN, false))),
  62. new IssueMetricFormula(CoreMetrics.REOPENED_ISSUES, false,
  63. (context, issues) -> context.setValue(issues.countByStatus(Issue.STATUS_REOPENED, false))),
  64. new IssueMetricFormula(CoreMetrics.CONFIRMED_ISSUES, false,
  65. (context, issues) -> context.setValue(issues.countByStatus(Issue.STATUS_CONFIRMED, false))),
  66. new IssueMetricFormula(CoreMetrics.TECHNICAL_DEBT, false,
  67. (context, issues) -> context.setValue(issues.sumEffortOfUnresolved(RuleType.CODE_SMELL, false))),
  68. new IssueMetricFormula(CoreMetrics.RELIABILITY_REMEDIATION_EFFORT, false,
  69. (context, issues) -> context.setValue(issues.sumEffortOfUnresolved(RuleType.BUG, false))),
  70. new IssueMetricFormula(CoreMetrics.SECURITY_REMEDIATION_EFFORT, false,
  71. (context, issues) -> context.setValue(issues.sumEffortOfUnresolved(RuleType.VULNERABILITY, false))),
  72. new IssueMetricFormula(CoreMetrics.SQALE_DEBT_RATIO, false,
  73. (context, issues) -> context.setValue(100.0 * debtDensity(context)),
  74. asList(CoreMetrics.TECHNICAL_DEBT, CoreMetrics.DEVELOPMENT_COST)),
  75. new IssueMetricFormula(CoreMetrics.SQALE_RATING, false,
  76. (context, issues) -> context
  77. .setValue(context.getDebtRatingGrid().getRatingForDensity(debtDensity(context))),
  78. asList(CoreMetrics.TECHNICAL_DEBT, CoreMetrics.DEVELOPMENT_COST)),
  79. new IssueMetricFormula(CoreMetrics.EFFORT_TO_REACH_MAINTAINABILITY_RATING_A, false,
  80. (context, issues) -> context.setValue(effortToReachMaintainabilityRatingA(context)), asList(CoreMetrics.TECHNICAL_DEBT, CoreMetrics.DEVELOPMENT_COST)),
  81. new IssueMetricFormula(CoreMetrics.RELIABILITY_RATING, false,
  82. (context, issues) -> context.setValue(RATING_BY_SEVERITY.get(issues.getHighestSeverityOfUnresolved(RuleType.BUG, false).orElse(Severity.INFO)))),
  83. new IssueMetricFormula(CoreMetrics.SECURITY_RATING, false,
  84. (context, issues) -> context.setValue(RATING_BY_SEVERITY.get(issues.getHighestSeverityOfUnresolved(RuleType.VULNERABILITY, false).orElse(Severity.INFO)))),
  85. new IssueMetricFormula(CoreMetrics.SECURITY_REVIEW_RATING, false,
  86. (context, issues) -> {
  87. Optional<Double> percent = computePercent(issues.countHotspotsByStatus(Issue.STATUS_TO_REVIEW, false), issues.countHotspotsByStatus(Issue.STATUS_REVIEWED, false));
  88. context.setValue(computeRating(percent.orElse(null)));
  89. }),
  90. new IssueMetricFormula(CoreMetrics.SECURITY_HOTSPOTS_REVIEWED, false,
  91. (context, issues) -> computePercent(issues.countHotspotsByStatus(Issue.STATUS_TO_REVIEW, false), issues.countHotspotsByStatus(Issue.STATUS_REVIEWED, false))
  92. .ifPresent(context::setValue)),
  93. new IssueMetricFormula(CoreMetrics.SECURITY_HOTSPOTS_REVIEWED_STATUS, false,
  94. (context, issues) -> context.setValue(issues.countHotspotsByStatus(Issue.STATUS_REVIEWED, false))),
  95. new IssueMetricFormula(CoreMetrics.SECURITY_HOTSPOTS_TO_REVIEW_STATUS, false,
  96. (context, issues) -> context.setValue(issues.countHotspotsByStatus(Issue.STATUS_TO_REVIEW, false))),
  97. new IssueMetricFormula(CoreMetrics.NEW_CODE_SMELLS, true,
  98. (context, issues) -> context.setLeakValue(issues.countUnresolvedByType(RuleType.CODE_SMELL, true))),
  99. new IssueMetricFormula(CoreMetrics.NEW_BUGS, true,
  100. (context, issues) -> context.setLeakValue(issues.countUnresolvedByType(RuleType.BUG, true))),
  101. new IssueMetricFormula(CoreMetrics.NEW_VULNERABILITIES, true,
  102. (context, issues) -> context.setLeakValue(issues.countUnresolvedByType(RuleType.VULNERABILITY, true))),
  103. new IssueMetricFormula(CoreMetrics.NEW_SECURITY_HOTSPOTS, true,
  104. (context, issues) -> context.setLeakValue(issues.countUnresolvedByType(RuleType.SECURITY_HOTSPOT, true))),
  105. new IssueMetricFormula(CoreMetrics.NEW_VIOLATIONS, true,
  106. (context, issues) -> context.setLeakValue(issues.countUnresolved(true))),
  107. new IssueMetricFormula(CoreMetrics.NEW_BLOCKER_VIOLATIONS, true,
  108. (context, issues) -> context.setLeakValue(issues.countUnresolvedBySeverity(Severity.BLOCKER, true))),
  109. new IssueMetricFormula(CoreMetrics.NEW_CRITICAL_VIOLATIONS, true,
  110. (context, issues) -> context.setLeakValue(issues.countUnresolvedBySeverity(Severity.CRITICAL, true))),
  111. new IssueMetricFormula(CoreMetrics.NEW_MAJOR_VIOLATIONS, true,
  112. (context, issues) -> context.setLeakValue(issues.countUnresolvedBySeverity(Severity.MAJOR, true))),
  113. new IssueMetricFormula(CoreMetrics.NEW_MINOR_VIOLATIONS, true,
  114. (context, issues) -> context.setLeakValue(issues.countUnresolvedBySeverity(Severity.MINOR, true))),
  115. new IssueMetricFormula(CoreMetrics.NEW_INFO_VIOLATIONS, true,
  116. (context, issues) -> context.setLeakValue(issues.countUnresolvedBySeverity(Severity.INFO, true))),
  117. new IssueMetricFormula(CoreMetrics.NEW_TECHNICAL_DEBT, true,
  118. (context, issues) -> context.setLeakValue(issues.sumEffortOfUnresolved(RuleType.CODE_SMELL, true))),
  119. new IssueMetricFormula(CoreMetrics.NEW_RELIABILITY_REMEDIATION_EFFORT, true,
  120. (context, issues) -> context.setLeakValue(issues.sumEffortOfUnresolved(RuleType.BUG, true))),
  121. new IssueMetricFormula(CoreMetrics.NEW_SECURITY_REMEDIATION_EFFORT, true,
  122. (context, issues) -> context.setLeakValue(issues.sumEffortOfUnresolved(RuleType.VULNERABILITY, true))),
  123. new IssueMetricFormula(CoreMetrics.NEW_RELIABILITY_RATING, true,
  124. (context, issues) -> {
  125. String highestSeverity = issues.getHighestSeverityOfUnresolved(RuleType.BUG, true).orElse(Severity.INFO);
  126. context.setLeakValue(RATING_BY_SEVERITY.get(highestSeverity));
  127. }),
  128. new IssueMetricFormula(CoreMetrics.NEW_SECURITY_RATING, true,
  129. (context, issues) -> {
  130. String highestSeverity = issues.getHighestSeverityOfUnresolved(RuleType.VULNERABILITY, true).orElse(Severity.INFO);
  131. context.setLeakValue(RATING_BY_SEVERITY.get(highestSeverity));
  132. }),
  133. new IssueMetricFormula(CoreMetrics.NEW_SECURITY_REVIEW_RATING, true,
  134. (context, issues) -> {
  135. Optional<Double> percent = computePercent(issues.countHotspotsByStatus(Issue.STATUS_TO_REVIEW, true), issues.countHotspotsByStatus(Issue.STATUS_REVIEWED, true));
  136. context.setLeakValue(computeRating(percent.orElse(null)));
  137. }),
  138. new IssueMetricFormula(CoreMetrics.NEW_SECURITY_HOTSPOTS_REVIEWED, true,
  139. (context, issues) -> computePercent(issues.countHotspotsByStatus(Issue.STATUS_TO_REVIEW, true), issues.countHotspotsByStatus(Issue.STATUS_REVIEWED, true))
  140. .ifPresent(context::setLeakValue)),
  141. new IssueMetricFormula(CoreMetrics.NEW_SECURITY_HOTSPOTS_REVIEWED_STATUS, true,
  142. (context, issues) -> context.setLeakValue(issues.countHotspotsByStatus(Issue.STATUS_REVIEWED, true))),
  143. new IssueMetricFormula(CoreMetrics.NEW_SECURITY_HOTSPOTS_TO_REVIEW_STATUS, true,
  144. (context, issues) -> context.setLeakValue(issues.countHotspotsByStatus(Issue.STATUS_TO_REVIEW, true))),
  145. new IssueMetricFormula(CoreMetrics.NEW_SQALE_DEBT_RATIO, true,
  146. (context, issues) -> context.setLeakValue(100.0 * newDebtDensity(context)),
  147. asList(CoreMetrics.NEW_TECHNICAL_DEBT, CoreMetrics.NEW_DEVELOPMENT_COST)),
  148. new IssueMetricFormula(CoreMetrics.NEW_MAINTAINABILITY_RATING, true,
  149. (context, issues) -> context.setLeakValue(context.getDebtRatingGrid().getRatingForDensity(
  150. newDebtDensity(context))),
  151. asList(CoreMetrics.NEW_TECHNICAL_DEBT, CoreMetrics.NEW_DEVELOPMENT_COST)));
  152. private static final Set<Metric> FORMULA_METRICS = IssueMetricFormulaFactory.extractMetrics(FORMULAS);
  153. private static double debtDensity(IssueMetricFormula.Context context) {
  154. double debt = Math.max(context.getValue(CoreMetrics.TECHNICAL_DEBT).orElse(0.0), 0.0);
  155. Optional<Double> devCost = context.getValue(CoreMetrics.DEVELOPMENT_COST);
  156. if (devCost.isPresent() && Double.doubleToRawLongBits(devCost.get()) > 0L) {
  157. return debt / devCost.get();
  158. }
  159. return 0.0;
  160. }
  161. private static double newDebtDensity(IssueMetricFormula.Context context) {
  162. double debt = Math.max(context.getLeakValue(CoreMetrics.NEW_TECHNICAL_DEBT).orElse(0.0), 0.0);
  163. Optional<Double> devCost = context.getLeakValue(CoreMetrics.NEW_DEVELOPMENT_COST);
  164. if (devCost.isPresent() && Double.doubleToRawLongBits(devCost.get()) > 0L) {
  165. return debt / devCost.get();
  166. }
  167. return 0.0;
  168. }
  169. private static double effortToReachMaintainabilityRatingA(IssueMetricFormula.Context context) {
  170. double developmentCost = context.getValue(CoreMetrics.DEVELOPMENT_COST).orElse(0.0);
  171. double effort = context.getValue(CoreMetrics.TECHNICAL_DEBT).orElse(0.0);
  172. double upperGradeCost = context.getDebtRatingGrid().getGradeLowerBound(Rating.B) * developmentCost;
  173. return upperGradeCost < effort ? (effort - upperGradeCost) : 0.0;
  174. }
  175. @Override
  176. public List<IssueMetricFormula> getFormulas() {
  177. return FORMULAS;
  178. }
  179. @Override
  180. public Set<Metric> getFormulaMetrics() {
  181. return FORMULA_METRICS;
  182. }
  183. }