felipebz / zpa

Parser and static code analysis tool for PL/SQL and Oracle SQL.
https://zpa.felipebz.com
GNU Lesser General Public License v3.0
216 stars 78 forks source link
analysis code-analysis code-quality grammar oracle-forms oracle-sql parser plsql plsql-analyzer plsql-parser sonarqube sql-analyzer static-analysis static-code-analysis

ZPA

Latest release Build Quality Gate Status

ZPA is parser and static code analysis tool for PL/SQL and Oracle SQL.

You can use it in a SonarQube on-premise instance. SonarQube is an open platform to manage code quality.

See some examples in our SonarQube instance!

Do you want to use this analyzer in a project hosted on SonarCloud? Try the zpa-cli!

Installation

Compatibility matrix

ZPA version SonarQube version (min/max)
3.6.0 9.9 / 10.7
3.7.0 (in development) 9.9 / 10.7

ZPA Toolkit

The ZPA Toolkit is visual tool to review the AST (abstract syntax tree) and the symbol table generated by the parser.

The latest ZPA Toolkit can be downloaded from the releases page and it requires JDK 11 or newer.

Contribute

Everyone is welcome to contribute. Please read our contribution guidelines for more information.

There are a few things you need to know about the code. It is divided in these modules:

The API exposed to custom plugins must be located in the package org.sonar.plugins.plsqlopen.api (it's a requirement from the SonarQube server). The classes located outside this package are not prepared for external consumption, so if you use them, your code can break without any further notice.

Running the integration tests

There are two sets of integration tests:

To run the integrations tests, first update the submodules:

git submodule update --init --recursive

Build the main plugin and the custom rules example:

./gradlew build publishToMavenLocal
./gradlew build -p plsql-custom-rules

Then run the tests:

./gradlew integrationTest

By default, the tests will be executed using SonarQube 9.9 LTA. You can change the SonarQube version using the property sonar.runtimeVersion, passing one of LATEST_RELEASE[9.9] (for SonarQube 9.9.x LTA), LATEST_RELEASE[10.7] (latest official release) or a.b.c.d for an exact release including build number:

./gradlew integrationTest -Dsonar.runtimeVersion=LATEST_RELEASE[9.9]