What is Static Analysis?
Last updated
Static analysis is the examination of source code without executing it, using rule-based pattern matching to detect known issues like security vulnerabilities, coding standard violations, and common bug patterns. Tools like SonarQube, Semgrep, and Codacy are static analyzers.
Why does static analysis matter for engineering teams?
Static analysis is fast and deterministic, and it catches known vulnerability patterns such as SQL injection and buffer overflows. Many CI pipelines run it as the first check. However, it finds only what its rules describe, and it cannot judge what a change was meant to do.
How does Argus handle static analysis?
Argus runs static analyzers as a pre-pass, not as a replacement for your own setup. The backend image bundles staticcheck (Go), ESLint (TypeScript/JavaScript, with two built-in async rules and the repo's own config ignored), and Semgrep (--config auto). Before the LLM review, the analyzers for the PR's dominant language run on the changed files, and up to 10 results per file go into that file's review prompt as hints for the model to confirm or discard. Analyzer results are never posted on their own. On Deep Review, a finding within 3 lines of an analyzer result gets a judge score floor. Keep your own Semgrep, SonarQube, or CodeQL rules in CI for policy coverage.