Download Latest Version 4.10.4 source code.zip (7.3 MB)
Email in envelope

Get an email when there's a new version of SpotBugs

Home / 4.10.0
Name Modified Size InfoDownloads / Week
Parent folder
eclipsePlugin.zip 2026-06-08 10.8 MB
spotbugs-4.10.0-SNAPSHOT-source.zip 2026-06-08 4.1 MB
spotbugs-4.10.0-SNAPSHOT.tgz 2026-06-08 16.3 MB
spotbugs-4.10.0-SNAPSHOT.zip 2026-06-08 16.3 MB
4.10.0 source code.tar.gz 2026-06-08 4.7 MB
4.10.0 source code.zip 2026-06-08 7.3 MB
README.md 2026-06-08 17.3 kB
Totals: 7 Items   59.5 MB 0

SpotBugs 4.10.0-SNAPSHOT

CHANGELOG

Refactor

  • Move internal usage of 'javax.annotation.Nonnull' to 'jakarta.annotation.NonNull'. (#3858)
  • Move internal usage of 'javax.annotation.Nullable' to 'jakarta.annotation.Nullable'. (#3861)
  • Renamed methods from edu.umd.cs.findbugs.SwitchHandler to reflect that they return a PC, not an offset (#3869)
  • Make the progress bar more visually appealing by adding some borders (#3896)
  • Reuse DismantleBytecode.isIf introduced in (#3869)

Added

  • Add partial support for org.jspecify.annotations.Nullable, org.jspecify.annotations.NonNull, org.jspecify.annotations.NullUnmarked and org.jspecify.annotations.NullMarked annotations. These are aliased to the closest existing SpotBugs nullness annotations. This is not a complete implementation of the JSpecify spec; scope-level semantics of @NullMarked and @NullUnmarked are not yet supported. (#3996)
  • Recognize jakarta.annotation.Nonnull and jakarta.annotation.Nullable (#3780)
  • Detect use of sun.misc.Unsafe and jdk.internal.misc.Unsafe (#3804)
  • New bug type is introduced: NCR_NOT_PROPERLY_CHECKED_READ. Improper validation of the return value from the read() method in InputStream and Reader classes may result in an array not being fully filled. (#3766)
  • New detector FindImproperSynchronization and introduced new bug types:
    • USO_UNSAFE_METHOD_SYNCHRONIZATION is reported when using synchronized methods with the class' accessible intrinsic lock,
    • USO_UNSAFE_STATIC_METHOD_SYNCHRONIZATION is reported when using static synchronized methods with the class' exposed intrinsic lock,
    • USO_UNSAFE_OBJECT_SYNCHRONIZATION is reported when the lock used for synchronization is visible from the outside,
    • USO_UNSAFE_ACCESSIBLE_OBJECT_SYNCHRONIZATION is reported when the lock used for synchronization is made accessible, with methods that update or return the lock, to the outside,
    • USO_UNSAFE_INHERITABLE_OBJECT_SYNCHRONIZATION is reported when the lock used for synchronization is can be altered by subclasses,
    • USO_UNSAFE_EXPOSED_OBJECT_SYNCHRONIZATION is reported when the lock used for synchronization is later exposed in the subclasses.
    • USBC_UNSAFE_SYNCHRONIZATION_WITH_BACKING_COLLECTION is reported when the backing collection of a lock is visible from the outside,
    • USBC_UNSAFE_SYNCHRONIZATION_WITH_ACCESSIBLE_BACKING_COLLECTION is reported when the backing collection of a lock is made accessible, with methods that update or return the lock, to the outside,
    • USBC_UNSAFE_SYNCHRONIZATION_WITH_INHERITABLE_BACKING_COLLECTION is reported when the backing collection of a lock can be altered by subclasses. (See SEI CERT rule LCK00-J and SEI CERT rule LCK04-J)
  • New detector FindIncreasedAccessibilityOfMethods for new bug type IAOM_DO_NOT_INCREASE_METHOD_ACCESSIBILITY. This detector reports a bug if a class increases the accessibility of overridden or hidden methods. (See SEI CERT rule MET04-J)

Fixed

  • Fix DM_STRING_TOSTRING false negative when toString() is chained before a method call (e.g., s.toString().toLowerCase()); multiple occurrences in the same method are now all reported (#3966)
  • Stop exposing JUnit BOM as a transitive dependency to consumers (#3908)
  • Fix incorrect bug counts and sizes when unioning reports (#3721)
  • Classes containing only methods throwing UnsupportedOperationException with setter-like names are no longer considered as mutable (#1601)
  • Enhanced SARIF output with full description sections - adding markdown is still an open issue (#2339)
  • Added missing null check to MultipleInstantiationsOfSingletons detector (#3823)
  • Fix invalid syntax in findbugsfilter.xsd (#3832)
  • Fix CT_CONSTRUCTOR_THROW FP with public and private constructors (#3822)
  • Fix tool name in usage info, (#3847)
  • Fix the building of relative chains of ./././ in filenames in fbp files (#3852)
  • Fix IllegalArgumentException initializing spotbugs when inside a fat jar on Java 25 (#3875)
  • Do not report DM_DEFAULT_ENCODING for classes compiled with target >= 18 (#3866)
  • Fix FS_BAD_DATE_FORMAT_FLAG_COMBO not suppressed by field-level annotation (#3838)
  • Fix SF_SWITCH_FALLTHROUGH false positives (#3767)
  • Recognize well-known exception-throwing utility methods when looking for exceptions thrown from constructors (#3821)
  • Fix RCN_REDUNDANT_NULLCHECK_OF_NONNULL_VALUE false negative when non-null value is on the left side of null comparison (#3920)
  • Fix IM_BAD_CHECK_FOR_ODD false negative when using Yoda-style comparison (1 == i % 2) (#3886)
  • Fix PluginLoader.close() to continue closing all URLClassLoaders when one close operation fails, suppressing subsequent IOExceptions. (#3958)
  • Fix broken bugDescriptions.html#TYPE links by restoring legacy bug type anchors in generated docs (#2113)
  • Fix EI_EXPOSE_REP false negative in package-private classes that expose mutable state through methods overriding a public super-type (#4027)
  • Fix errors in the 4.40 Eclipse in SpotBugs plugin project (#4052)

Removed

  • Removed old deprecated methods:
  • assertPresentBugPattern(String, IMarker[]) protected method from de.tobject.findbugs.test.AbstractQuickfixTest deprecated since 2014,
  • setFontSizeHelper(Component[], float) protected method from edu.umd.cs.findbugs.gui2.FBFrame deprecated since 2010,
  • matchedPrefixes(String[], String) method from edu.umd.cs.findbugs.gui2.ViewFilter deprecated since 2010,
  • lookupFromUniqueId(String) method from edu.umd.cs.findbugs.BugCollection and edu.umd.cs.findbugs.SortedBugCollection deprecated since 2006,
  • create(BugReporter) method from edu.umd.cs.findbugs.DetectorFactory deprecated since 2008,
  • instantiateDetectorsInPass(BugReporter) method from edu.umd.cs.findbugs.plan.AnalysisPass deprecated since 2008,
  • getMessage(String) method from edu.umd.cs.findbugs.I18N deprecated since 2019,
  • getElementSignature() method from edu.umd.cs.findbugs.OpcodeStack.Item deprecated since 2008,
  • getFieldAnnotation() method from edu.umd.cs.findbugs.OpcodeStack.Item deprecated since 2006,
  • PluginLoader(URL) and PluginLoader(URL, ClassLoader) constructors from edu.umd.cs.findbugs.PluginLoader deprecated since 2010,
  • addSourceDir(String) method from edu.umd.cs.findbugs.Project deprecated since 2017,
  • getImplicitClasspathEntryList() method from edu.umd.cs.findbugs.Project deprecated since 2008,
  • write(String, boolean, String) method from edu.umd.cs.findbugs.Project deprecated since 2007,
  • getInteger(String, int) method from edu.umd.cs.findbugs.SystemProperties deprecated since 2010,
  • getId() method from edu.umd.cs.findbugs.ba.BasicBlock deprecated since 2010,
  • getArgument(InvokeInstruction, ConstantPoolGen, int, int) method from edu.umd.cs.findbugs.ba.Frame deprecated since 2010,
  • findDeclaredExceptions(InvokeInstruction, ConstantPoolGen) method from edu.umd.cs.findbugs.ba.Hierarchy deprecated since 2008,
  • findConcreteMethod(JavaClass, String, String) method from edu.umd.cs.findbugs.ba.Hierarchy deprecated since 2007,
  • findXMethod(JavaClass, String, String, JavaClassAndMethodChooser) method from edu.umd.cs.findbugs.ba.Hierarchy deprecated since 2007,
  • findXMethod(JavaClass[], String, String) method from edu.umd.cs.findbugs.ba.Hierarchy deprecated since 2007,
  • findXMethod(JavaClass[], String, String, JavaClassAndMethodChooser) method from edu.umd.cs.findbugs.ba.Hierarchy deprecated since 2007,
  • findMethod(JavaClass[], String, String) method from edu.umd.cs.findbugs.ba.Hierarchy deprecated since 2007,
  • isConcrete(XMethod) method from edu.umd.cs.findbugs.ba.Hierarchy deprecated since 2007,
  • doesMethodUnconditionallyThrowException(XMethod, JavaClass, Method) method from edu.umd.cs.findbugs.ba.PruneUnconditionalExceptionThrowerEdges deprecated since 2008,
  • nameAndSignatureIsCalled(XMethod) method from edu.umd.cs.findbugs.ba.XFactory deprecated since 2020,
  • isInterned(XMethod) method from edu.umd.cs.findbugs.ba.XFactory deprecated since 2007,
  • canonicalizeString(String) method from edu.umd.cs.findbugs.ba.XFactory deprecated since 2017,
  • findXFieldFromValueNumber(Method, Location, ValueNumber, ValueNumberFrame) method from edu.umd.cs.findbugs.ba.npe.NullDerefAndRedundantComparisonFinder deprecated since 2008,
  • findFieldAnnotationFromValueNumber(Method, Location, ValueNumber, ValueNumberFrame) method from edu.umd.cs.findbugs.ba.npe.NullDerefAndRedundantComparisonFinder deprecated since 2008,
  • findLocalAnnotationFromValueNumber(Method, Location, ValueNumber, ValueNumberFrame) method from edu.umd.cs.findbugs.ba.npe.NullDerefAndRedundantComparisonFinder deprecated since 2008,
  • findAnnotationFromValueNumber(Method, Location, ValueNumber, ValueNumberFrame) method from edu.umd.cs.findbugs.ba.npe.NullDerefAndRedundantComparisonFinder deprecated since 2008,
  • compact(int[], int) method from edu.umd.cs.findbugs.ba.vna.ValueNumberFactory deprecated since 2008,
  • fromResourceName(String) method from edu.umd.cs.findbugs.classfile.ClassDescriptor deprecated since 2008,
  • fromFieldSignature(String) method from edu.umd.cs.findbugs.classfile.ClassDescriptor deprecated since 2008,
  • isClassResource(String) method from edu.umd.cs.findbugs.classfile.ClassDescriptor deprecated since 2008,
  • createClassDescriptorFromSignature(String) method from edu.umd.cs.findbugs.classfile.ClassDescriptor deprecated since 2008,
  • createClassDescriptor(String) method from edu.umd.cs.findbugs.classfile.ClassDescriptor deprecated since 2008,
  • createClassDescriptor(String[]) method from edu.umd.cs.findbugs.classfile.ClassDescriptor deprecated since 2008,
  • createClassDescriptorFromDottedClassName(String) method from edu.umd.cs.findbugs.classfile.ClassDescriptor deprecated since 2008,
  • createClassDescriptor(JavaClass) method from edu.umd.cs.findbugs.classfile.ClassDescriptor deprecated since 2008,
  • canonicalizeString(String) method from edu.umd.cs.findbugs.classfile.DescriptorFactory deprecated since 2017,
  • isContainerField(XField) method from edu.umd.cs.findbugs.detect.UnreadFields deprecated since 2011,
  • getReadFields() method from edu.umd.cs.findbugs.detect.UnreadFields deprecated since 2011,
  • getWrittenFields() method from edu.umd.cs.findbugs.detect.UnreadFields deprecated since 2011,
  • isWrittenOutsideOfInitialization(XField) method from edu.umd.cs.findbugs.detect.UnreadFields deprecated since 2011,
  • isWrittenDuringInitialization(XField) method from edu.umd.cs.findbugs.detect.UnreadFields deprecated since 2011,
  • isWrittenInConstructor(XField) method from edu.umd.cs.findbugs.detect.UnreadFields deprecated since 2011,
  • strongEvidenceForIntendedSerialization(ClassDescriptor) method from edu.umd.cs.findbugs.detect.UnreadFields deprecated since 2011,
  • existsStrongEvidenceForIntendedSerialization(ClassDescriptor) method from edu.umd.cs.findbugs.detect.UnreadFields deprecated since 2011,
  • isReflexive(XField) method from edu.umd.cs.findbugs.detect.UnreadFields deprecated since 2011,
  • RelationalOp(String) private constructor from edu.umd.cs.findbugs.filter.RelationalOp deprecated since 2008,
  • isLibraryFileName(String) method from edu.umd.cs.findbugs.util.Archive deprecated since 2022,
  • replace(String, String, String) method from edu.umd.cs.findbugs.util.Strings deprecated since 2010,
  • toString(Object[]) method from edu.umd.cs.findbugs.util.Strings deprecated since 2010,
  • closeSilently(OutputStream) method from edu.umd.cs.findbugs.util.Util deprecated since 2018,
  • closeSilently(Closeable) method from edu.umd.cs.findbugs.util.Util deprecated since 2018,
  • closeSilently(ZipFile) method from edu.umd.cs.findbugs.util.Util deprecated since 2018,
  • getRefConstantOperand() method from edu.umd.cs.findbugs.visitclass.DismantleBytecode deprecated since 2010,
  • getDottedFieldSig() method from edu.umd.cs.findbugs.visitclass.PreorderVisitor deprecated since 2006,
  • compactValueNumbers(Dataflow<ValueNumberFrame, ValueNumberAnalysis>) method from edu.umd.cs.findbugs.ba.vna.ValueNumberAnalysis deprecated since 2009.
  • Removed old deprecated fields:
  • String RELEASE from edu.umd.cs.findbugs.Version deprecated since 2018.
  • Removed old deprecated classes:
  • edu.umd.cs.findbugs.NewResults class deprecated since 2009,
  • edu.umd.cs.findbugs.classfile.engine.ClassParserUsingBCEL class deprecated since 2007.
  • Remove deprecated 'Priority' annotation originally deprecated in 2011. Switch to 'Confidence' for same behaviour. (#3746)

Cleanup

  • Removed usages of some deprecated methods. (#3842)

CHECKSUM

file checksum (sha256)
spotbugs-4.10.0-SNAPSHOT-javadoc.jar 3edd41461d5aea65df6fc429332db45cf80c2541fee3219935c539335aae4efb
spotbugs-4.10.0-SNAPSHOT-sources.jar 76476f61ce6dc0eb0c38801e21da44e77043ba21226aef6c1b9d21df06d2395a
spotbugs-4.10.0-SNAPSHOT.tgz a19419f5625238c1104ed0f0810801e601b39195f817f15beb762ebce91584ec
spotbugs-4.10.0-SNAPSHOT.zip 876d39cdc59c25158287c61e27a7e30887ff597f3e6f3601cdcad4c372284ceb
spotbugs-annotations-4.10.0-SNAPSHOT-javadoc.jar 6b4deda1c6d0de4c9fa55b53a00aedfabdfd5697b610883c50b008375267e3ee
spotbugs-annotations-4.10.0-SNAPSHOT-sources.jar 87974d23caffbc8c6e66c567747627267b5ed06573cee966d7af6d236b8d65bd
spotbugs-annotations.jar a86d49f3f6ab9805c1af4362656b3a2b19738fa216cfa125ab3f2138087d4aef
spotbugs-ant-4.10.0-SNAPSHOT-javadoc.jar b8891065563621ba23288358279b506a67d868d167b2d9001d14121ad99dc944
spotbugs-ant-4.10.0-SNAPSHOT-sources.jar 91477d93b1fd1bebae35d318427b5238fb458e726478dc1a8ac41ce74838a1e6
spotbugs-ant.jar 22f2fa397e86663adcd4828cc1c91e63aa6cc2bfc56832885b749a86fac5c784
spotbugs.jar 521bef4c29a7fb4e9b2a859314c9787cb266d548f499e43d79743663ddb4a37f
test-harness-4.10.0-SNAPSHOT-javadoc.jar 871cb72038d60dceb3fb2e928d4486dcb67592791cede88bc4f05f68a1c3221a
test-harness-4.10.0-SNAPSHOT-sources.jar 805d2d124b0d4ea513ee9262d4ad6027c3471d45defd80fd7d20e23425d17df7
test-harness-4.10.0-SNAPSHOT.jar bd10d1f11a1b93e4ca4db4d27772f611bd3407f9452dbbd2d1ba62584ddc171f
test-harness-core-4.10.0-SNAPSHOT-javadoc.jar d7e63844711f62edcfcb834abbb2d7f45a81667bbb3c982e1de62c18b0d9e68b
test-harness-core-4.10.0-SNAPSHOT-sources.jar 043a55d99a517c0d9cf702b0c183b4afd3f03af9eff4a86d59bb37df1b35b532
test-harness-core-4.10.0-SNAPSHOT.jar 1f9a0ee8f150dd71f960ca4f59dcf7912a45d0e9e6aefc4585fd44b975454bc0
test-harness-jupiter-4.10.0-SNAPSHOT-javadoc.jar daa20b7d625e52a95a72cfe02c78c20fba66e97932ca0f008332348cedb9bf41
test-harness-jupiter-4.10.0-SNAPSHOT-sources.jar 17144f315686bfd01c02fa4ae7c916060c41de8eed58d5b8470416fa08f46ced
test-harness-jupiter-4.10.0-SNAPSHOT.jar a91146da3e993479cfefd2690781cbd102c6360ecc63a96d88995be3bd60fcbb
Source: README.md, updated 2026-06-08