Hi, I found a false negative in SonarQube 26.7.0 with sonar-java 8.34 when an earlier length comparison makes a later comparison impossible.
Affected tool
SonarQube 26.7.0.124771; sonar-java 8.34 (build 44906)
Affected checker
SonarQube java:S2589
Minimal reproducer
class SpotbugsSonarqubeS2589LengthConstraints {
int arrayLength(int[] values) {
if (values.length > 20) return 1;
if (values.length > 30) return 2;
return 0;
}
int stringLength(String value) {
if (value.length() > 20) return 1;
if (value.length() > 30) return 2;
return 0;
}
}
Reproduction command
sonar-scanner --version
sonar-scanner -Dsonar.projectKey=spotbugs-sonarqube-reproducer -Dsonar.sources=spotbugs-sonarqube-s2589-fn-length-constraints.java -Dsonar.host.url="$SONAR_HOST_URL" -Dsonar.token="$SONAR_TOKEN"
Current behavior
SonarQube produces no java:S2589 diagnostic.
Expected behavior
SonarQube should report the always-false length comparisons at lines 4 and 10.