Skip to content

Baseline bogus Qodana findings from degraded Maven import - #140

Merged
SibeiC merged 1 commit into
masterfrom
chore/qodana-baseline
Jun 11, 2026
Merged

SibeiC merged 1 commit into
masterfrom
chore/qodana-baseline

Conversation

@SibeiC

@SibeiC SibeiC commented Jun 11, 2026

Copy link
Copy Markdown
Owner

Root cause (finally)

The recurring master Qodana failures (5× today, 1× on 2026-06-04) are a JetBrains bug, not a repo problem. Qodana's Maven sync intermittently never completes its real (dynamic) import: the RemoteMavenServer dies quietly and the project model is left with only the static preimport result — preimport statistics: … interpolated 6 of 21 in idea.log — i.e. only the 6 explicitly-versioned pom dependencies (springdoc, jackson-databind-nullable, bcpkix, caffeine, tika-core, mockwebserver) make it into the model (projectStructure/Libraries.json confirms). Everything managed by the Spring Boot parent / AWS BOM (Lombok, Jackson, Spring, …) is missing, so:

  • the sanity check reports Unresolved reference JsonProperty/NotNull/… on a rotating sample of files, and
  • FieldMayBeFinal (35), FieldCanBeLocal (16), SuspiciousMethodCalls (2), JavadocReference (1) misfire on Lombok @Data/@Getter classes → 54 identical false positives → --fail-threshold 0 trips.

Reproduced deterministically in a local jetbrains/qodana-jvm-community:2026.1 container — with seeded and empty caches, with maven.preimport.project=false, with external.system.auto.import.headless.async=false, and on Spring Boot 4.0.5 as well as 4.1.0. Healthy runs (the full ~11-min import, e.g. this morning's two master passes) report 0 problems on the same code, proving all 54 are artifacts.

Mitigation

Commit the 54 broken-mode fingerprints as a trimmed SARIF baseline and pass --baseline qodana.baseline.sarif.json:

  • broken-mode runs now report UNCHANGED: 54, NEW: 0 and pass (verified locally, exit 0)
  • healthy runs are unaffected (none of the 54 exist there)
  • genuinely new findings still fail the gate

The earlier #138/#139 hardening (linter pin, warmed .m2) stays: it makes healthy scans faster and keeps jars resolvable; this PR handles the import-degradation mode they couldn't.

🤖 Generated with Claude Code

Root cause of the recurring master Qodana failures (5x on 2026-06-11,
1x on 2026-06-04): Qodana's Maven sync intermittently never completes
its real (dynamic) import — the RemoteMavenServer dies and the project
model is left with only the static 'preimport' result, which
interpolates just the 6 explicitly-versioned pom dependencies (logged
as 'preimport statistics: interpolated 6 of 21'). With Spring
Boot-parent/BOM-managed deps (Lombok, Jackson, Spring) missing from
the model, the sanity check reports unresolved references and the
FieldMayBeFinal/FieldCanBeLocal/SuspiciousMethodCalls/JavadocReference
inspections emit 54 identical false positives, tripping
--fail-threshold 0. Reproduced deterministically in a local
jetbrains/qodana-jvm-community:2026.1 container regardless of cache
state, preimport/async-import switches, or Spring Boot version —
healthy runs (full 11-min import) report 0 problems on the same code.

Mitigation until JetBrains fixes the import: commit the 54 broken-mode
fingerprints as a baseline (trimmed SARIF) and pass --baseline to the
scan. Broken-mode runs now report 'UNCHANGED: 54, NEW: 0' and pass
(verified locally, exit 0); healthy runs are unaffected and any
genuinely new finding still fails the gate.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 11, 2026 15:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a Qodana SARIF baseline to neutralize a known degraded-Maven-import failure mode where Qodana emits a fixed set of false-positive findings, allowing CI to pass while still failing on genuinely new issues.

Changes:

  • Added qodana.baseline.sarif.json containing the 54 known bogus findings (fingerprint-based) from the broken import mode.
  • Updated the Qodana GitHub Actions workflow to pass --baseline qodana.baseline.sarif.json alongside the existing --fail-threshold 0.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
qodana.baseline.sarif.json Introduces the SARIF baseline used to mark the known false positives as “unchanged”.
.github/workflows/qodana_code_quality.yml Configures Qodana runs to apply the baseline during scans.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions

Copy link
Copy Markdown

Qodana for JVM

It seems all right 👌

No new problems were found according to the checks applied

💡 Qodana analysis was run in the pull request mode: only the changed files were checked
☁️ View the detailed Qodana report

Contact Qodana team

Contact us at qodana-support@jetbrains.com

@SibeiC
SibeiC merged commit b44f5ac into master Jun 11, 2026
11 checks passed
@SibeiC
SibeiC deleted the chore/qodana-baseline branch June 11, 2026 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants