Static analysis
also: static analyzer, static analysis tool, static analysis tools
Checking code for problems by reading it with automated tools, without running it. Linting and type checking are two common kinds.
Any automated examination of source code without executing it, including linting, type checking, security scanning, and detection of dead or overly complex code. It contrasts with dynamic analysis, such as running tests, which observes code while it runs.
An inspector reviewing a building's blueprints for missing fire exits before construction starts. Nothing is built yet, but some problems are obvious on paper.
Static analysis is the cheapest safety check you can ask for. It runs in seconds, needs no test data, and catches whole classes of mistakes in agent-written code before anything runs.
Static analysis flagged a possible SQL injection in the search endpoint: user input is glued straight into the database query, so an attacker could sneak in their own commands. I'll pass the input in safely.
Run all the static analysis we have: lint, typecheck, and the security scanner. Summarize anything serious before you make fixes.
Treating static analysis as a replacement for tests. It catches certain mistakes by reading code, but it can't confirm the app actually does what users need.