Skip to content

Validation: real SpotBugs source annotations - #40

Closed
joaodinissf wants to merge 1 commit into
codex/validation-20260926-1484from
codex/validation-20260926-annotations
Closed

joaodinissf wants to merge 1 commit into
codex/validation-20260926-1484from
codex/validation-20260926-annotations

Conversation

@joaodinissf

Copy link
Copy Markdown
Owner

Fork-only annotation validation

Exercise the candidate SARIF merger using an actual SpotBugs 4.10.4 finding report, a clean sibling report, and the original two-line Java source committed in this draft.

The workflow requires successful Code Scanning processing. Expected results: NP_ALWAYS_NULL and NP_LOAD_OF_KNOWN_NULL_VALUE, both resolved to line 2 of .github/tests/analysis/annotation-source/com/example/Example.java.

This separate harness replaces the build workflow to avoid an additional full reactor build. It uses read-only content permissions and security-event upload permission; it has no package, release, or deployment steps. The four candidate stack branches are unchanged. This draft is not a request to merge or publish.

Use the candidate merger and an actual SpotBugs finding report alongside a
clean sibling. Point the preserved source bases at the committed fixture
and require successful Code Scanning processing. This fork-only harness
replaces the build workflow to avoid another full reactor build; it has
read-only content access and no publishing or deployment steps.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@joaodinissf
joaodinissf force-pushed the codex/validation-20260926-1486 branch from d80364a to 6fe8869 Compare September 26, 2026 11:31
@joaodinissf
joaodinissf force-pushed the codex/validation-20260926-annotations branch from 98939b0 to 2439265 Compare September 26, 2026 11:31
@@ -0,0 +1,2 @@
package com.example;
public class Example { public static void main(String[] args) { String s = null; System.out.println(s.length()); } }
@@ -0,0 +1,2 @@
package com.example;
public class Example { public static void main(String[] args) { String s = null; System.out.println(s.length()); } }
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants