Skip to content

Remove usages of Commons Lang 2 - #218

Open
timja-bot wants to merge 1 commit into
jenkinsci:masterfrom
timja-bot:commons-lang3
Open

Remove usages of Commons Lang 2#218
timja-bot wants to merge 1 commit into
jenkinsci:masterfrom
timja-bot:commons-lang3

Conversation

@timja-bot

Copy link
Copy Markdown

No need to depend on a third-party library here when the Java Platform provides this
functionality natively.

Part of the effort to remove Commons Lang 2 from Jenkins core — jenkinsci/jenkins#16404,
jenkinsci/jenkins#26105. Commons Lang 2 is EOL and carries an unfixed advisory
(GHSA-j288-q9x7-2f5v).

What's changed

  • ReverseProxySecurityRealm: the seven StringUtils.isBlank / isNotBlank calls become null
    checks plus String.isBlank(). (ReverseProxyAuthenticationProvider uses Spring's StringUtils,
    which is untouched.)
  • Bumped the parent POM to 6.2211.v27f680c93c53 so the ban-commons-lang-2 enforcer rule is
    available, and enabled it. The reformatting in that file is mvn spotless:apply output.

No dependency was added — this plugin did not declare Commons Lang, it came in transitively from
core.

Testing done

mvn -B -ntp clean verify passes locally on Java 21 / macOS.

The ban-commons-lang-2 enforcer rule is enabled in this PR, so the build fails if an
org.apache.commons.lang.* import comes back.

Submitter checklist

  • Make sure you are opening from a topic/feature/bugfix branch (right side) and not your main branch!
  • Ensure that the pull request title represents the desired changelog entry
  • Please describe what you did
  • Link to relevant issues in GitHub or Jira
  • Link to relevant pull requests, esp. upstream and downstream changes
  • Ensure you have provided tests that demonstrate the feature works or the issue is fixed

🤖 This pull request was generated with AI assistance (Claude Code) as part of a bulk migration
across Jenkins plugins. If anything here looks wrong, please comment on this PR or contact @timja.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants