Skip to content

Build Time Validation

Arnab Nandy edited this page Sep 3, 2026 · 1 revision

Build-Time Validation

BugDNA includes a build-time source scanner for exception-handling hazards that often become production failures but are separate from runtime fingerprinting.

Maven

Run the scanner directly:

mvn bugdna:scan

Or bind it to verification:

<plugin>
    <groupId>io.github.arnabnandy7</groupId>
    <artifactId>bugdna-maven-plugin</artifactId>
    <version>1.1.2</version>
    <executions>
        <execution>
            <goals>
                <goal>scan</goal>
            </goals>
        </execution>
    </executions>
</plugin>

Options:

Property Default Description
bugdna.failOnIssues true Fail the build when findings are present.
bugdna.includeTests false Include test source roots.
bugdna.skip false Skip the scan.

Gradle

Apply the plugin:

plugins {
    id 'io.github.arnabnandy7.bugdna' version '1.1.2'
}

bugdna {
    failOnIssues = true
    includeTests = false
}

Run the scanner:

./gradlew bugdnaScan

Rules

The scanner currently reports:

  • Empty catch blocks
  • Generic Exception, Throwable, or RuntimeException catch/throw/throws usage
  • Likely unhandled checked-exception APIs outside try blocks or methods with throws

The unhandled-exception rule is intentionally heuristic. Java compilation remains the source of truth for exact checked-exception enforcement.


← Command-Line Interface · Wiki home · Architecture and Data Handling →

Clone this wiki locally