microsoft / AttackSurfaceAnalyzer
Source Code Overview

Analysis scope, overview of main, test, generated, deployment, build, and other code.

Source Code Analysis Scope
Files includes and excluded from analyses
razor
csproj
Razor
txt
cshtml
gitattributes
resx
props
editorconfig
  • 20 extensions are included in analyses: cs, razor, md, yml, json, csproj, Razor, css, gitignore, ps1, txt, js, cshtml, sql, sh, svg, gitattributes, resx, props, editorconfig
  • 6 criteria are used to exclude files from analysis:
    • exclude files with path like ".*/[.][a-zA-Z0-9_]+.*" (Hidden files and folders) (11 files).
    • exclude files with path like ".*[.]resx" (The resx resource files) (1 file).
    • exclude files with path like ".*/git[-]history[.]txt" (Git history) (1 file).
    • exclude files with path like ".*/git[-][a-zA-Z0-9_]+[.]txt" (Git data exports for sokrates analyses) (0 files).
    • exclude files with path like ".*/sokrates_conventions[.]json" (Sokrates scoping conventions) (1 file).
    • exclude files with path like ".*[.]txt" (Text files) (2 files).
Overview of Analyzed Files
Basic stats on analyzed files
Intro
For analysis purposes we separate files in scope into several categories: main, test, generated, deployment and build, and other.

  • The main category contains all manually created source code files that are being used in the production.
  • Files in the main category are used as input for other analyses: logical decomposition, concerns, duplication, file size, unit size, and conditional complexity.
  • Test source code files are used only for testing of the product. These files are normally not deployed to production.
  • Build and deployment source code files are used to configure or support build and deployment process.
  • Generated source code files are automatically generated files that have not been manually changed after generation.
  • While a source code folder may contain a number of files, we are primarily interested in the source code files that are being written and maintained by developers.
  • Files containing binaries, documentation, or third-party libraries, for instance, are excluded from analysis. The exception are third-party libraries that have been changed by developers.

main16318 LOC (68%) 150 files
test1042 LOC (4%) 10 files
generated0 LOC (0%) 0 files
build and deployment219 LOC (<1%) 7 files
other6363 LOC (26%) 20 files
Main Code
All manually created or maintained source code that defines logic of the product that is run in a production environment.
razor
cshtml
props
Explore:   circles  |  sunburst
  • The following criteria are used to filter files:
    • files with paths like ".*".
  • 150 files match defined criteria (16,318 lines of code, 100.0% vs. main code):
    • 100 *.cs files (13,338 lines of code)
    • 36 *.razor files (1,876 lines of code)
    • 7 *.yml files (635 lines of code)
    • 1 *.css files (296 lines of code)
    • 3 *.ps1 files (116 lines of code)
    • 2 *.cshtml files (48 lines of code)
    • 1 *.props files (9 lines of code)
  • " *.cs" is biggest, containing 81.74% of code.
  • " *.props" is smallest, containing 0.06% of code.


*.cs13338 LOC (81%) 100 files
*.razor1876 LOC (11%) 36 files
*.yml635 LOC (3%) 7 files
*.css296 LOC (1%) 1 files
*.ps1116 LOC (<1%) 3 files
*.cshtml48 LOC (<1%) 2 files
*.props9 LOC (<1%) 1 files
Test Code
Used only for testing of the product. Normally not deployed in a production environment.
csproj
Explore:   circles  |  sunburst
  • The following criteria are used to filter files:
    • files with paths like ".*[-]test[-].*".
    • files with paths like ".*/[Tt]ests/.*".
    • files with paths like ".*/TestData/.*".
    • files with any line of content like ".*/simpletest/.*".
  • 10 files match defined criteria (1,042 lines of code, 6.4% vs. main code):
    • 8 *.cs files (936 lines of code)
    • 1 *.csproj files (67 lines of code)
    • 1 *.yml files (39 lines of code)
  • " *.cs" is biggest, containing 89.83% of code.
  • " *.yml" is smallest, containing 3.74% of code.


*.cs936 LOC (89%) 8 files
*.csproj67 LOC (6%) 1 files
*.yml39 LOC (3%) 1 files
Build and Deployment Code
Source code used to configure or support build and deployment process.
csproj
Explore:   circles  |  sunburst
  • The following criteria are used to filter files:
    • files with paths like ".*[.]git[a-z]+".
    • files with paths like ".*/[.]gitattributes".
    • files with paths like ".*/[.]gitignore".
    • files with paths like ".*[.]csproj".
    • files with paths like ".*[.]sh".
    • files with paths like ".*/docker[-]compose[.]yml".
  • 7 files match defined criteria (219 lines of code, 1.3% vs. main code):
    • 3 *.csproj files (152 lines of code)
    • 2 *.sh files (36 lines of code)
    • 2 *.yml files (31 lines of code)
  • " *.csproj" is biggest, containing 69.41% of code.
  • " *.yml" is smallest, containing 14.16% of code.


*.csproj152 LOC (69%) 3 files
*.sh36 LOC (16%) 2 files
*.yml31 LOC (14%) 2 files
Other Code
Explore:   circles  |  sunburst
  • The following criteria are used to filter files:
    • files with paths like ".*[.]json".
    • files with paths like ".*[.]editorconfig".
    • files with paths like ".*[.]md".
    • files with paths like ".*/[.]gitignore".
    • files with paths like ".*/README[.][a-z0-9]+".
    • files with paths like ".*[.]svg".
    • files with paths like ".*[.]txt".
    • files with paths like ".*/LICENSE[.][a-z0-9]+".
    • files with paths like ".*[.](xml|xsd|robot|sql|pgsql|dashboard|profile|ipynb|raml|avsc|al)".
  • 20 files match defined criteria (6,363 lines of code, 39.0% vs. main code):
    • 9 *.json files (5,518 lines of code)
    • 1 *.svg files (543 lines of code)
    • 8 *.md files (282 lines of code)
    • 2 *.sql files (20 lines of code)
  • " *.json" is biggest, containing 86.72% of code.
  • " *.sql" is smallest, containing 0.31% of code.


*.json5518 LOC (86%) 9 files
*.svg543 LOC (8%) 1 files
*.md282 LOC (4%) 8 files
*.sql20 LOC (<1%) 2 files
Analyzers
Info about analyzers used for source code examinations.
  • *.cs files are analyzed with CSharpAnalyzer:
    • All basic standard analyses supported (source code overview, duplication, file size, concerns, findings, metrics, controls)
    • Advanced code cleaning (empty lines and comments removed for LOC calculations, additional cleaning for duplication calculations)
    • Unit size analysis
    • Conditional complexity analysis
    • Advanced heuristic dependency analysis (based on namespace heuristics)
  • *.razor files are analyzed with HtmlAnalyzer:
    • All basic standard analyses supported (source code overview, duplication, file size, concerns, findings, metrics, controls)
    • Advanced code cleaning (empty lines and comments removed for LOC calculations, additional cleaning for duplication calculations)
    • Unit size analysis
    • Conditional complexity analysis
    • Advanced heuristic dependency analysis
  • *.yml files are analyzed with YamlAnalyzer:
    • All basic standard analyses supported (source code overview, duplication, file size, concerns, findings, metrics, controls)
    • Advanced code cleaning (empty lines and comments removed for LOC calculations, additional cleaning for duplication calculations)
    • No unit size analysis
    • No conditional complexity analysis
    • No dependency analysis
  • *.css files are analyzed with CssAnalyzer:
    • All basic standard analyses supported (source code overview, duplication, file size, concerns, findings, metrics, controls)
    • Advanced code cleaning (empty lines and comments removed for LOC calculations, additional cleaning for duplication calculations)
    • No unit size analysis
    • No conditional complexity analysis
    • No dependency analysis
  • *.ps1 files are analyzed with DefaultLanguageAnalyzer:
    • All basic standard analyses supported (source code overview, duplication, file size, concerns, findings, metrics, controls)
    • Basic code cleaning (empty lines removed for LOC calculations and duplication calculations)
    • No unit size analysis
    • No conditional complexity analysis
    • No dependency analysis
  • *.cshtml files are analyzed with HtmlAnalyzer:
    • All basic standard analyses supported (source code overview, duplication, file size, concerns, findings, metrics, controls)
    • Advanced code cleaning (empty lines and comments removed for LOC calculations, additional cleaning for duplication calculations)
    • Unit size analysis
    • Conditional complexity analysis
    • Advanced heuristic dependency analysis
  • *.props files are analyzed with XmlAnalyzer:
    • All basic standard analyses supported (source code overview, duplication, file size, concerns, findings, metrics, controls)
    • Advanced code cleaning (empty lines and comments removed for LOC calculations, additional cleaning for duplication calculations)
    • No unit size analysis
    • No conditional complexity analysis
    • No dependency analysis


2022-01-31 00:55