FALSE NEGATIVE: `java:S2200` misses a specific-value check on `Comparator.compare()`

Hi, I found a false negative in SonarQube 26.7.0 with sonar-java 8.34 when the result of Comparator.compare() is checked against 1.

Affected tool

SonarQube 26.7.0.124771; sonar-java 8.34 (build 44906)

Affected checker

SonarQube java:S2200

Minimal reproducer

import java.util.Comparator;

class SpotbugsSonarqubeS2200ComparatorCompare {
  boolean compare(Integer left, Integer right, Comparator<Integer> comparator) {
    return comparator.compare(left, right) == 1;
  }
}

Reproduction command

sonar-scanner --version
sonar-scanner -Dsonar.projectKey=spotbugs-sonarqube-reproducer -Dsonar.sources=spotbugs-sonarqube-s2200-fn-comparator-compare.java -Dsonar.host.url="$SONAR_HOST_URL" -Dsonar.token="$SONAR_TOKEN"

Current behavior

SonarQube produces no java:S2200 diagnostic.

Expected behavior

SonarQube should report java:S2200 at line 5 because only the sign of a comparator result is guaranteed. The bundled S2200 documentation explicitly covers both Comparator.compare() and Comparable.compareTo().

Hello @marktiwnzhao ,

Thanks for your feedback! You’re right, we don’t check in this rule Comparator case, only Comparable one. I’ve created JIRA ticket to fix this.