Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 4, 2025

Bumps org.sonarsource.java:java-frontend from 8.17.1.39878 to 8.18.0.40025.

Release notes

Sourced from org.sonarsource.java:java-frontend's releases.

8.18.0.40025

Release notes - SonarJava - 8.18

False Positive

SONARJAVA-5678 Fix a FP case in S7479

SONARJAVA-5697 S2441 FP when Serializable is not available due to missing semantics

Bug

SONARJAVA-5685 Revert security impact from last rule metadata update

Task

SONARJAVA-5645 Update RSPEC before 8.18 release

SONARJAVA-5653 Prototyping more telemetry

SONARJAVA-5670 Make SonarComponents in JavaFrontend not @​Nullable.

SONARJAVA-5673 Create proxy object for sending telemetry

SONARJAVA-5675 Update dependency versions

SONARJAVA-5682 Replace use of deprecated Charsets.UTF_8 constant

SONARJAVA-5686 Report the scanner app using telemetry

SONARJAVA-5687 Delete unused test projects under "its"

SONARJAVA-5689 Aggregate telemetry measures at project level

SONARJAVA-5691 Report dependencies

SONARJAVA-5692 Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.18.0 in /java-checks-test-sources/default

SONARJAVA-5693 Report whether the analysis is autoscan

SONARJAVA-5695 Report speed of analysis and analysis errors

SONARJAVA-5698 Report Eclipse parser type errors

SONARJAVA-5703 Fix Quality Flaws caused by commons-lang3 new version

False Negative

SONARJAVA-5683 S2077 not triggered by SQL interpolation performed with String#format

Commits
  • 7537787 SONARJAVA-5703 Fix Quality Flaws caused by commons-lang3 new version (#5266)
  • 1728919 SONARJAVA-5692 Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.18.0 in...
  • c7463f6 Update rule metadata (#5264)
  • 6c9e827 SONARJAVA-5697 S2441 and S2118 Fix FP with missing semantics of Serializable ...
  • f684952 SONARJAVA-5698 Report Eclipse parser type errors (#5261)
  • 2214434 SONARJAVA-5683 S2077 Fix FN on strings built with String.format()/formatted()...
  • ff79c5b SONARJAVA-5695 Report speed of analysis and analysis errors
  • 9455861 [NO JIRA] Fix Quality Flaws: Use static imports of Mockito mock, spy, when, t...
  • 194cf05 [NO JIRA] Fix cirrus-ci container size: Prevent tasks running orchestrator fr...
  • d09e22e SONARJAVA-5693 Report telemetry indicating autoscan (#5257)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.sonarsource.java:java-frontend](https://github.com/SonarSource/sonar-java) from 8.17.1.39878 to 8.18.0.40025.
- [Release notes](https://github.com/SonarSource/sonar-java/releases)
- [Commits](SonarSource/sonar-java@8.17.1.39878...8.18.0.40025)

---
updated-dependencies:
- dependency-name: org.sonarsource.java:java-frontend
  dependency-version: 8.18.0.40025
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 4, 2025
@sonarqubecloud
Copy link

sonarqubecloud bot commented Sep 4, 2025

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Sep 26, 2025

Looks like org.sonarsource.java:java-frontend is up-to-date now, so this is no longer needed.

@dependabot dependabot bot closed this Sep 26, 2025
@dependabot dependabot bot deleted the dependabot/maven/org.sonarsource.java-java-frontend-8.18.0.40025 branch September 26, 2025 13:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant