Skip to content

Move PATH_TRAVERSAL_IN, REDOS and URLCONNECTION_SSRF_FD SpotBugs suppressions to annotations - #27069

Open
bhumika-aga wants to merge 2 commits into
jenkinsci:masterfrom
bhumika-aga:fix/spotbugs-suppression-annotations
Open

Move PATH_TRAVERSAL_IN, REDOS and URLCONNECTION_SSRF_FD SpotBugs suppressions to annotations#27069
bhumika-aga wants to merge 2 commits into
jenkinsci:masterfrom
bhumika-aga:fix/spotbugs-suppression-annotations

Conversation

@bhumika-aga

Copy link
Copy Markdown

Refs #17340

This is the first of several narrow PRs split out of #26964 (now closed), which triaged the untriaged section of core/src/spotbugs/excludesFilter.xml but mixed too many categories of change to review comfortably. As suggested there, each follow-up PR covers a single category of change.

This PR replaces the broad class-level PATH_TRAVERSAL_IN, REDOS and URLCONNECTION_SSRF_FD exclusions in core/src/spotbugs/excludesFilter.xml with narrowly-scoped @SuppressFBWarnings annotations co-located with the code, each carrying a specific justification.

These are all intentional, controlled file-system / network operations in Jenkins core/agent infrastructure where the path or URL comes from trusted configuration or the Jenkins home/war layout rather than untrusted remote request input. Method-level annotations are used where the sink is a direct member method; class-level annotations are used for the few classes whose sinks occur inside lambdas (which a method-level annotation cannot cover).

This change is purely suppression movement — no behavioral change. The remaining untriaged NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE exclusion (which does require behavioral changes such as explicit exceptions and null guards) is intentionally left in excludesFilter.xml and will be addressed in separate, single-category follow-up PRs.

Testing done

  • mvn clean compile spotbugs:check -pl core — passes (no SpotBugs violations after moving the suppressions inline)
  • mvn spotless:check checkstyle:check -pl core — passes

There is no new automated test because this is a static-analysis suppression move with no runtime behavior change; the SpotBugs build (spotbugs:check) exercises the changed lines and confirms the suppressions are correctly scoped.

Screenshots (UI changes only)

Before

After

Proposed changelog entries

N/A

Proposed changelog category

/label skip-changelog

Proposed upgrade guidelines

N/A

Submitter checklist

  • The issue, if it exists, is well-described.
  • The changelog entries and upgrade guidelines are appropriate for the audience affected by the change (users or developers, depending on the change) and are in the imperative mood (see examples). Fill in the Proposed upgrade guidelines section only if there are breaking changes or changes that may require extra steps from users during upgrade.
  • There is automated testing or an explanation as to why this change has no tests.
  • New public classes, fields, and methods are annotated with @Restricted or have @since TODO Javadocs, as appropriate.
  • New deprecations are annotated with @Deprecated(since = "TODO") or @Deprecated(forRemoval = true, since = "TODO"), if applicable.
  • UI changes do not introduce regressions when enforcing the current default rules of Content Security Policy Plugin. In particular, new or substantially changed JavaScript is not defined inline and does not call eval to ease future introduction of Content Security Policy (CSP) directives (see documentation).
  • For dependency updates, there are links to external changelogs and, if possible, full differentials.
  • For new APIs and extension points, there is a link to at least one consumer.

Desired reviewers

@mention

Before the changes are marked as ready-for-merge:

Maintainer checklist

  • There are at least two (2) approvals for the pull request and no outstanding requests for change.
  • Conversations in the pull request are over, or it is explicit that a reviewer is not blocking the change.
  • Changelog entries in the pull request title and/or Proposed changelog entries are accurate, human-readable, and in the imperative mood.
  • Proper changelog labels are set so that the changelog can be generated automatically.
  • If the change needs additional upgrade steps from users, the upgrade-guide-needed label is set and there is a Proposed upgrade guidelines section in the pull request title (see example).
  • If it would make sense to backport the change to LTS, be a Bug or Improvement, and either the issue or pull request must be labeled as lts-candidate to be considered.

…to annotations

Replace the broad class-level PATH_TRAVERSAL_IN, REDOS and
URLCONNECTION_SSRF_FD exclusions in core/src/spotbugs/excludesFilter.xml
with narrowly-scoped @SuppressFBWarnings annotations co-located with the
code, each carrying a specific justification.

These are all intentional, controlled file-system / network operations in
Jenkins core/agent infrastructure where the path or URL comes from trusted
configuration or the Jenkins home/war layout rather than untrusted remote
request input. Method-level annotations are used where the sink is a direct
member method; class-level annotations are used for classes whose sinks
occur inside lambdas (which a method-level annotation cannot cover).

This change is purely annotation/suppression movement with no behavioral
change. The remaining untriaged NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE
exclusion is left in place for a separate follow-up.
@comment-ops-bot comment-ops-bot Bot added the skip-changelog Should not be shown in the changelog label Jul 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog Should not be shown in the changelog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant