Repository navigation
Baseline bogus Qodana findings from degraded Maven import - #140
Merged
Merged
Conversation
Root cause of the recurring master Qodana failures (5x on 2026-06-11, 1x on 2026-06-04): Qodana's Maven sync intermittently never completes its real (dynamic) import — the RemoteMavenServer dies and the project model is left with only the static 'preimport' result, which interpolates just the 6 explicitly-versioned pom dependencies (logged as 'preimport statistics: interpolated 6 of 21'). With Spring Boot-parent/BOM-managed deps (Lombok, Jackson, Spring) missing from the model, the sanity check reports unresolved references and the FieldMayBeFinal/FieldCanBeLocal/SuspiciousMethodCalls/JavadocReference inspections emit 54 identical false positives, tripping --fail-threshold 0. Reproduced deterministically in a local jetbrains/qodana-jvm-community:2026.1 container regardless of cache state, preimport/async-import switches, or Spring Boot version — healthy runs (full 11-min import) report 0 problems on the same code. Mitigation until JetBrains fixes the import: commit the 54 broken-mode fingerprints as a baseline (trimmed SARIF) and pass --baseline to the scan. Broken-mode runs now report 'UNCHANGED: 54, NEW: 0' and pass (verified locally, exit 0); healthy runs are unaffected and any genuinely new finding still fails the gate. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Pull request overview
Adds a Qodana SARIF baseline to neutralize a known degraded-Maven-import failure mode where Qodana emits a fixed set of false-positive findings, allowing CI to pass while still failing on genuinely new issues.
Changes:
- Added
qodana.baseline.sarif.jsoncontaining the 54 known bogus findings (fingerprint-based) from the broken import mode. - Updated the Qodana GitHub Actions workflow to pass
--baseline qodana.baseline.sarif.jsonalongside the existing--fail-threshold 0.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
qodana.baseline.sarif.json |
Introduces the SARIF baseline used to mark the known false positives as “unchanged”. |
.github/workflows/qodana_code_quality.yml |
Configures Qodana runs to apply the baseline during scans. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Qodana for JVMIt seems all right 👌 No new problems were found according to the checks applied 💡 Qodana analysis was run in the pull request mode: only the changed files were checked Contact Qodana teamContact us at qodana-support@jetbrains.com
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Root cause (finally)
The recurring master Qodana failures (5× today, 1× on 2026-06-04) are a JetBrains bug, not a repo problem. Qodana's Maven sync intermittently never completes its real (dynamic) import: the RemoteMavenServer dies quietly and the project model is left with only the static preimport result —
preimport statistics: … interpolated 6 of 21inidea.log— i.e. only the 6 explicitly-versioned pom dependencies (springdoc, jackson-databind-nullable, bcpkix, caffeine, tika-core, mockwebserver) make it into the model (projectStructure/Libraries.jsonconfirms). Everything managed by the Spring Boot parent / AWS BOM (Lombok, Jackson, Spring, …) is missing, so:Unresolved reference JsonProperty/NotNull/…on a rotating sample of files, andFieldMayBeFinal(35),FieldCanBeLocal(16),SuspiciousMethodCalls(2),JavadocReference(1) misfire on Lombok@Data/@Getterclasses → 54 identical false positives →--fail-threshold 0trips.Reproduced deterministically in a local
jetbrains/qodana-jvm-community:2026.1container — with seeded and empty caches, withmaven.preimport.project=false, withexternal.system.auto.import.headless.async=false, and on Spring Boot 4.0.5 as well as 4.1.0. Healthy runs (the full ~11-min import, e.g. this morning's two master passes) report 0 problems on the same code, proving all 54 are artifacts.Mitigation
Commit the 54 broken-mode fingerprints as a trimmed SARIF baseline and pass
--baseline qodana.baseline.sarif.json:UNCHANGED: 54, NEW: 0and pass (verified locally, exit 0)The earlier #138/#139 hardening (linter pin, warmed .m2) stays: it makes healthy scans faster and keeps jars resolvable; this PR handles the import-degradation mode they couldn't.
🤖 Generated with Claude Code