Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 4, 2025

Bumps org.sonarsource.java:java-frontend from 8.17.1.39878 to 8.18.0.40025.

Release notes

Sourced from org.sonarsource.java:java-frontend's releases.

8.18.0.40025

Release notes - SonarJava - 8.18

False Positive

SONARJAVA-5678 Fix a FP case in S7479

SONARJAVA-5697 S2441 FP when Serializable is not available due to missing semantics

Bug

SONARJAVA-5685 Revert security impact from last rule metadata update

Task

SONARJAVA-5645 Update RSPEC before 8.18 release

SONARJAVA-5653 Prototyping more telemetry

SONARJAVA-5670 Make SonarComponents in JavaFrontend not @​Nullable.

SONARJAVA-5673 Create proxy object for sending telemetry

SONARJAVA-5675 Update dependency versions

SONARJAVA-5682 Replace use of deprecated Charsets.UTF_8 constant

SONARJAVA-5686 Report the scanner app using telemetry

SONARJAVA-5687 Delete unused test projects under "its"

SONARJAVA-5689 Aggregate telemetry measures at project level

SONARJAVA-5691 Report dependencies

SONARJAVA-5692 Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.18.0 in /java-checks-test-sources/default

SONARJAVA-5693 Report whether the analysis is autoscan

SONARJAVA-5695 Report speed of analysis and analysis errors

SONARJAVA-5698 Report Eclipse parser type errors

SONARJAVA-5703 Fix Quality Flaws caused by commons-lang3 new version

False Negative

SONARJAVA-5683 S2077 not triggered by SQL interpolation performed with String#format

Commits
  • 7537787 SONARJAVA-5703 Fix Quality Flaws caused by commons-lang3 new version (#5266)
  • 1728919 SONARJAVA-5692 Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.18.0 in...
  • c7463f6 Update rule metadata (#5264)
  • 6c9e827 SONARJAVA-5697 S2441 and S2118 Fix FP with missing semantics of Serializable ...
  • f684952 SONARJAVA-5698 Report Eclipse parser type errors (#5261)
  • 2214434 SONARJAVA-5683 S2077 Fix FN on strings built with String.format()/formatted()...
  • ff79c5b SONARJAVA-5695 Report speed of analysis and analysis errors
  • 9455861 [NO JIRA] Fix Quality Flaws: Use static imports of Mockito mock, spy, when, t...
  • 194cf05 [NO JIRA] Fix cirrus-ci container size: Prevent tasks running orchestrator fr...
  • d09e22e SONARJAVA-5693 Report telemetry indicating autoscan (#5257)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.sonarsource.java:java-frontend](https://github.com/SonarSource/sonar-java) from 8.17.1.39878 to 8.18.0.40025.
- [Release notes](https://github.com/SonarSource/sonar-java/releases)
- [Commits](SonarSource/sonar-java@8.17.1.39878...8.18.0.40025)

---
updated-dependencies:
- dependency-name: org.sonarsource.java:java-frontend
  dependency-version: 8.18.0.40025
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 4, 2025
Copy link

sonarqubecloud bot commented Sep 4, 2025

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file java Pull requests that update java code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants