FALSE POSITIVE: java:S2259 ignores a known-true instanceof check

Hi, I found a false positive in SonarQube 26.7.0 with sonar-java 8.34 when a known concrete runtime type makes an instanceof check true.

Affected tool

SonarQube 26.7.0.124771; sonar-java 8.34 (build 44906)

Affected checker

SonarQube java:S2259

Minimal reproducer

class S2259KnownTrueInstanceof {
  abstract class Person {}
  class Faculty extends Person {}
  class Professor extends Faculty {}
  class Student extends Person {}

  void test() {
    Person value = new Professor();
    Person result = null;
    if (value instanceof Faculty) {
      result = new Student();
    }
    result.toString();
  }
}

Reproduction command

sonar-scanner --version
sonar-scanner -Dsonar.projectKey=s2259-reproducer -Dsonar.sources=sonarqube-s2259-fp-known-true-instanceof.java -Dsonar.host.url="$SONAR_HOST_URL" -Dsonar.token="$SONAR_TOKEN"

Current behavior

SonarQube reports sonarqube-s2259-fp-known-true-instanceof.java:13: java:S2259: A NullPointerException could be thrown; result is nullable here.

Expected behavior

S2259 should not report this dereference because Professor extends Faculty, so the instanceof branch always assigns a non-null Student to result.