如何提取仅含缺陷统计的简易Sourceanalyzer/Fortify报告并跟踪构建差异?
Got it, let's break down how to solve your problem step by step—focused on getting the simple severity-based report you need, identifying new defects, and setting up automated alerts.
1. Bypass Complex AWB Templates by Extracting Raw Data
If the built-in AWB templates are too rigid, skip them entirely and pull raw defect data directly. Most build analysis tools like AWB offer command-line exports or APIs that output structured data (CSV/JSON) with all the fields you need:
- Defect severity (Critical/High/Medium/Low)
- Unique defect ID (to spot new issues)
- Build version identifier
Example command (adjust to match your AWB tool's actual syntax):
awb defects export --build $CURRENT_BUILD_ID --format json --output current_defects.json
2. Calculate Severity Counts & Compare Across Builds
Write a lightweight script (Python is perfect for this) to process the exported data, filter to only the severity levels you care about, and compare counts between your current and previous builds.
Here's a quick Python snippet to get you started:
import json from collections import defaultdict # Load defect data from current and previous builds with open('current_defects.json') as f: current_defects = json.load(f) with open('previous_defects.json') as f: previous_defects = json.load(f) # Count defects by severity for each build def count_severity(defects): counts = defaultdict(int) for defect in defects: severity = defect['severity'] if severity in ['Critical', 'High', 'Medium', 'Low']: counts[severity] += 1 return counts current_counts = count_severity(current_defects) previous_counts = count_severity(previous_defects) # Print a clean comparison print("Defect Count Comparison (Previous → Current):") for severity in ['Critical', 'High', 'Medium', 'Low']: print(f"{severity}: {previous_counts.get(severity, 0)} → {current_counts.get(severity, 0)}")
3. Identify New Defects by Unique ID
To catch newly introduced issues, compare the unique IDs of defects between builds. Add this to your script:
# Get sets of defect IDs from each build current_ids = {defect['id'] for defect in current_defects} previous_ids = {defect['id'] for defect in previous_defects} # Find IDs that only exist in the current build new_defect_ids = current_ids - previous_ids # Pull details for new defects new_defects = [d for d in current_defects if d['id'] in new_defect_ids] if new_defects: print("\n⚠️ New Defects Found:") for defect in new_defects: print(f"- ID: {defect['id']}, Severity: {defect['severity']}, Summary: {defect['summary'][:60]}...")
4. Set Up Scheduled Build Server Tasks & Alerts
On your build server (Jenkins, GitLab CI, etc.), configure a weekly scheduled job that:
- Runs the AWB export command to fetch the current build's defect data
- Executes your comparison script
- Checks for trigger conditions:
- Any severity count exceeds your predefined thresholds (e.g., Critical > 3, High > 8)
- New defects are detected
- Sends an email notification if either condition is met. Most CI tools have built-in email plugins, or you can use a simple script with
smtplib(Python) orsendmail(shell) to craft alerts.
For example, in Jenkins, add a "Post-build Action" that runs your script, then use the "Editable Email Notification" plugin to send alerts only when thresholds are breached or new defects are found.
内容的提问来源于stack exchange,提问作者Ginger McMurray

