android / security-certification-resources
Source Code Overview

Analysis scope, overview of main, test, generated, deployment, build, and other code.

Source Code Analysis Scope
Files includes and excluded from analyses
patch
properties
pro
txt
  • 13 extensions are included in analyses: java, xml, patch, md, gradle, properties, gitignore, py, json, bat, pro, txt, sh
  • 8 criteria are used to exclude files from analysis:
    • exclude files with path like ".*/[.][a-zA-Z0-9_]+.*" (Hidden files and folders) (9 files).
    • exclude files with path like ".*/gradle/wrapper/.*" (Gradle) (6 files).
    • exclude files with path like ".*/git[-]history[.]txt" (Git history) (1 file).
    • exclude files with path like ".*/git[-][a-zA-Z0-9_]+[.]txt" (Git data exports for sokrates analyses) (0 files).
    • exclude files with path like ".*/proguard[-]rules[.]pro" (ProGuard) (1 file).
    • exclude files with path like ".*/docs/.*" (Documentation) (7 files).
    • exclude files with path like ".*/sokrates_conventions[.]json" (Sokrates scoping conventions) (1 file).
    • exclude files with path like ".*[.]txt" (Text files) (0 files).
Overview of Analyzed Files
Basic stats on analyzed files
Intro
For analysis purposes we separate files in scope into several categories: main, test, generated, deployment and build, and other.

  • The main category contains all manually created source code files that are being used in the production.
  • Files in the main category are used as input for other analyses: logical decomposition, concerns, duplication, file size, unit size, and conditional complexity.
  • Test source code files are used only for testing of the product. These files are normally not deployed to production.
  • Build and deployment source code files are used to configure or support build and deployment process.
  • Generated source code files are automatically generated files that have not been manually changed after generation.
  • While a source code folder may contain a number of files, we are primarily interested in the source code files that are being written and maintained by developers.
  • Files containing binaries, documentation, or third-party libraries, for instance, are excluded from analysis. The exception are third-party libraries that have been changed by developers.

main13082 LOC (63%) 125 files
test953 LOC (4%) 8 files
generated0 LOC (0%) 0 files
build and deployment715 LOC (3%) 25 files
other5898 LOC (28%) 115 files
Main Code
All manually created or maintained source code that defines logic of the product that is run in a production environment.
Explore:   circles  |  sunburst
  • The following criteria are used to filter files:
    • files with paths like ".*".
  • 125 files match defined criteria (13,082 lines of code, 100.0% vs. main code):
    • 117 *.java files (11,222 lines of code)
    • 8 *.py files (1,860 lines of code)
  • " *.java" is biggest, containing 85.78% of code.
  • " *.py" is smallest, containing 14.22% of code.


*.java11222 LOC (85%) 117 files
*.py1860 LOC (14%) 8 files
Test Code
Used only for testing of the product. Normally not deployed in a production environment.
Explore:   circles  |  sunburst
  • The following criteria are used to filter files:
    • files with paths like ".*/[Tt]ests/.*".
    • files with paths like ".*_test[.].*".
    • files with any line of content like ".*/simpletest/.*".
  • 8 files match defined criteria (953 lines of code, 7.3% vs. main code). All matches are in *.java files.


*.java953 LOC (100%) 8 files
Build and Deployment Code
Source code used to configure or support build and deployment process.
Explore:   circles  |  sunburst
  • The following criteria are used to filter files:
    • files with paths like ".*[.]gradle".
    • files with paths like ".*/AndroidManifest[.]xml".
    • files with paths like ".*[.]bat".
    • files with paths like ".*[.]git[a-z]+".
    • files with paths like ".*/[.]gitignore".
    • files with paths like ".*[.]sh".
  • 25 files match defined criteria (715 lines of code, 5.5% vs. main code):
    • 6 *.bat files (366 lines of code)
    • 18 *.gradle files (331 lines of code)
    • 1 *.sh files (18 lines of code)
  • " *.bat" is biggest, containing 51.19% of code.
  • " *.sh" is smallest, containing 2.52% of code.


*.bat366 LOC (51%) 6 files
*.gradle331 LOC (46%) 18 files
*.sh18 LOC (2%) 1 files
Other Code
patch
properties
Explore:   circles  |  sunburst
  • The following criteria are used to filter files:
    • files with paths like ".*[.]md".
    • files with paths like ".*/README[.][a-z0-9]+".
    • files with paths like ".*[.]json".
    • files with paths like ".*/[.]gitignore".
    • files with paths like ".*[.]properties".
    • files with paths like ".*[.]patch".
    • files with paths like ".*[.]txt".
    • files with paths like ".*[.](xml|xsd|robot|sql|pgsql|dashboard|profile|ipynb|raml|avsc|al)".
  • 115 files match defined criteria (5,898 lines of code, 45.1% vs. main code):
    • 65 *.xml files (2,731 lines of code)
    • 6 *.json files (1,487 lines of code)
    • 24 *.patch files (1,255 lines of code)
    • 14 *.md files (315 lines of code)
    • 6 *.properties files (110 lines of code)
  • " *.xml" is biggest, containing 46.3% of code.
  • " *.properties" is smallest, containing 1.87% of code.


*.xml2731 LOC (46%) 65 files
*.json1487 LOC (25%) 6 files
*.patch1255 LOC (21%) 24 files
*.md315 LOC (5%) 14 files
*.properties110 LOC (1%) 6 files
Analyzers
Info about analyzers used for source code examinations.
  • *.java files are analyzed with JavaAnalyzer:
    • All basic standard analyses supported (source code overview, duplication, file size, concerns, findings, metrics, controls)
    • Advanced code cleaning (empty lines and comments removed for LOC calculations, additional cleaning for duplication calculations)
    • Unit size analysis
    • Conditional complexity analysis
    • Advanced heuristic dependency analysis (based on package names)
  • *.py files are analyzed with PythonAnalyzer:
    • All basic standard analyses supported (source code overview, duplication, file size, concerns, findings, metrics, controls)
    • Advanced code cleaning (empty lines and comments removed for LOC calculations, additional cleaning for duplication calculations)
    • Unit size analysis
    • Conditional complexity analysis
    • Basic heuristic dependency analysis


2022-02-03 05:25