Skip to content

gradle: False positives from generated code from the version catalog feature #14530

@recke96

Description

@recke96

Using the version catalog feature of gradle (https://docs.gradle.org/current/userguide/platforms.html) with the default libs.versions.toml file produces false positives such as:

.gradle/8.4/dependencies-accessors/1989acdfa2790571c9dc5975340ca543de5bf0a0/sources/org/gradle/accessors/dm/LibrariesForLibsInPluginsBlock.java:609
This method overrides ProviderConvertible.asProvider; it is advisable to add an Override annotation.

This is generated code and should not produce a warning (even if it's just at the note level)

Example source: https://github.com/recke96/HemaTournament/blob/main/gradle/libs.versions.toml
Corresponding alerts: https://github.com/recke96/HemaTournament/security/code-scanning

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions