Hi Sonar Community,
Based on the community’s feedback, we’ve added 7 new rules for the Groovy analyzer and then improved rules for a variety of other languages. The new Groovy rules are aiming to bring Sonar in line with other scanning tools in Groovy community so you’re not surprised by any of Sonar’s findings
New Groovy Rules:
- Rule S108: Nested blocks of code should not be left empty
- Rule S9370: “RuntimeException” should not be caught directly
- Rule S9376: “servletContext” should not be used directly in controllers and taglibs
- Rule S9373: “volatile” should not be used with “long” or “double” fields
- Rule S9378: Nested synchronized blocks should be avoided
- Rule S9372: Unused parameters should be removed from private methods and constructors
- Rule S9371: “NullPointerException” should not be explicitly thrown
Improved Rules:
- Fix False Positive for Shell S7682: Avoid requiring return after exit
- Fix False Positive for Shell S1764: Identical expressions should not be used on both sides of a binary operator
- Fix False Positive for Apex S5378: Should not raise when the query explicitly declares WITH SYSTEM\_MODE
- Fix False Negative with Apex S7992 does not report SOQL queries bounded only by a foreign-key equality
- Fix False Positive with Go S117: Local variable and function parameter names should comply with a naming convention
Try scanning your Groovy projects, or Gradle build scripts, and let us know what you think of the changes. And if there are any other rules you’d like to see for Groovy, let us know!