Hi, I found a false negative in SonarQube 26.7.0 with sonar-java 8.34 when the result of Comparator.compare() is checked against 1.
Affected tool
SonarQube 26.7.0.124771; sonar-java 8.34 (build 44906)
Affected checker
SonarQube java:S2200
Minimal reproducer
import java.util.Comparator;
class SpotbugsSonarqubeS2200ComparatorCompare {
boolean compare(Integer left, Integer right, Comparator<Integer> comparator) {
return comparator.compare(left, right) == 1;
}
}
Reproduction command
sonar-scanner --version
sonar-scanner -Dsonar.projectKey=spotbugs-sonarqube-reproducer -Dsonar.sources=spotbugs-sonarqube-s2200-fn-comparator-compare.java -Dsonar.host.url="$SONAR_HOST_URL" -Dsonar.token="$SONAR_TOKEN"
Current behavior
SonarQube produces no java:S2200 diagnostic.
Expected behavior
SonarQube should report java:S2200 at line 5 because only the sign of a comparator result is guaranteed. The bundled S2200 documentation explicitly covers both Comparator.compare() and Comparable.compareTo().