[BUG][code-analyzer] PMD NullPointerException scanning two LWC JavaScript files
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 48/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- java, javascript
Línea de trabajo
Start by running the documented sf code-analyzer run command with the AppExchange and Recommended:Security selectors against the workspace containing owJobDetail.js and owJobList.js. Investigate the PMD processing error and request a reduced reproduction because the source files are private. Done means both files are analyzed without a NullPointerException, or unsupported syntax produces a diagnostic identifying its location.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Have you tried to resolve this issue yourself first?
- I confirm I have gone through the above steps and still have an issue to report.
Bug Description
Salesforce Code Analyzer's PMD engine throws a NullPointerException while scanning two Lightning Web Component JavaScript files, owJobDetail.js and owJobList.js. The scan produces an HTML report, but PMD does not complete analysis of those files.
The error occurred with Code Analyzer 5.13.0 and reproduced with 5.16.0 using the AppExchange and Recommended:Security rule selectors. I need a complete scan for a managed-package security review.
Output / Logs
PMD issued a processing error for owJobDetail.js:
NullPointerException: Cannot invoke "org.mozilla.javascript.ast.Name.visit(org.mozilla.javascript.ast.NodeVisitor)" because "this.varName" is null
PMD issued the same processing error for owJobList.js.
The run generated an HTML report with 15 violations (12 High, 3 Moderate), but PMD did not complete analysis of these two JavaScript files.
Steps To Reproduce
- From the root of a Salesforce project containing the two LWC JavaScript files, run:
sf code-analyzer run --rule-selector AppExchange --rule-selector Recommended:Security --workspace packages/ondaworx-job-board --output-file ../ow-job-board-security-review/CodeAnalyzerReport-v5.16.html
- Observe PMD processing errors for owJobDetail.js and owJobList.js.
- The same error occurred with plugin versions 5.13.0 and 5.16.0 on this Mac. The source is in a private managed-package repository, so I have not attached it publicly.
Expected Behavior
PMD should analyse both JavaScript files and either report rule violations or complete without a processing error. If the syntax is unsupported, it should provide a diagnostic that identifies the relevant syntax and location.
Operating System
macOS 26.5.2
Salesforce CLI Version
@salesforce/cli/2.141.6 darwin-x64 node-v22.22.3
Code Analyzer Plugin (code-analyzer) Version
code-analyzer 5.16.0
Node Version
v26.5.0
Java Version
openjdk version "21.0.12.1" 2026-08-18
Python Version
No response
Additional Context (Screenshots, Files, etc)
This scan is needed for a Salesforce managed-package security review. I have reproduced the error twice on this Mac with different plugin versions. I have not tested it on a second computer. I can provide further diagnostic information or a reduced reproduction if requested.
Workaround
No workaround found. Updating Code Analyzer from 5.13.0 to 5.16.0 did not resolve the error.
Urgency
High
- Lenguaje dominante
- TypeScript
- Estrellas
- 241
- Forks
- 51
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de forcedotcom/code-analyzer
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
forcedotcom/code-analyzer#2094 ·
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
forcedotcom/code-analyzer#2093 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
forcedotcom/code-analyzer#2091 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
forcedotcom/code-analyzer#2090 ·
-
Dificultad 3/5 1-2 días Aptitud para principiantes 72/100
forcedotcom/code-analyzer#2104 ·
Todos los issues de forcedotcom/code-analyzer
Issues similares
-
Add: CanalPlusActionEurope.nlAbiertocheck:passed streams:add
Dificultad 1/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 2 días
-
beta technical-medium ui
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
walletbeat/walletbeat#1625 ·
Los mantenedores suelen responder en 1 día
-
[Good First Issue]: Add unit tests for NetworkVersionInfoPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. AbiertoGood First Issue hacktoberfest
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
hiero-ledger/hiero-sdk-js#4489 ·
Los mantenedores suelen responder en 1 día
-
[Bug] The clients language filter cannot select the rows the page labels as unknownPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
apache/rocketmq-dashboard#6103 ·
Los mantenedores suelen responder en 4 días
-
Bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
payloadcms/payload#18652 ·
Los mantenedores suelen responder en 1 día