Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[BUG][code-analyzer] PMD NullPointerException scanning two LWC JavaScript files

未关闭
#2,100 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
48/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
活跃
技术栈
java, javascript
领域
security, tooling

调研方向

Start by running the documented sf code-analyzer run command with the AppExchange and Recommended:Security selectors against the workspace containing owJobDetail.js and owJobList.js. Investigate the PMD processing error and request a reduced reproduction because the source files are private. Done means both files are analyzed without a NullPointerException, or unsupported syntax produces a diagnostic identifying its location.

由索引模型根据 Issue 内容生成。

描述

Have you tried to resolve this issue yourself first?
  • I confirm I have gone through the above steps and still have an issue to report.
Bug Description

Salesforce Code Analyzer's PMD engine throws a NullPointerException while scanning two Lightning Web Component JavaScript files, owJobDetail.js and owJobList.js. The scan produces an HTML report, but PMD does not complete analysis of those files.

The error occurred with Code Analyzer 5.13.0 and reproduced with 5.16.0 using the AppExchange and Recommended:Security rule selectors. I need a complete scan for a managed-package security review.

Output / Logs
PMD issued a processing error for owJobDetail.js:
NullPointerException: Cannot invoke "org.mozilla.javascript.ast.Name.visit(org.mozilla.javascript.ast.NodeVisitor)" because "this.varName" is null

PMD issued the same processing error for owJobList.js.

The run generated an HTML report with 15 violations (12 High, 3 Moderate), but PMD did not complete analysis of these two JavaScript files.
Steps To Reproduce
  1. From the root of a Salesforce project containing the two LWC JavaScript files, run:

sf code-analyzer run --rule-selector AppExchange --rule-selector Recommended:Security --workspace packages/ondaworx-job-board --output-file ../ow-job-board-security-review/CodeAnalyzerReport-v5.16.html

  1. Observe PMD processing errors for owJobDetail.js and owJobList.js.
  2. The same error occurred with plugin versions 5.13.0 and 5.16.0 on this Mac. The source is in a private managed-package repository, so I have not attached it publicly.
Expected Behavior

PMD should analyse both JavaScript files and either report rule violations or complete without a processing error. If the syntax is unsupported, it should provide a diagnostic that identifies the relevant syntax and location.

Operating System

macOS 26.5.2

Salesforce CLI Version

@salesforce/cli/2.141.6 darwin-x64 node-v22.22.3

Code Analyzer Plugin (code-analyzer) Version

code-analyzer 5.16.0

Node Version

v26.5.0

Java Version

openjdk version "21.0.12.1" 2026-08-18

Python Version

No response

Additional Context (Screenshots, Files, etc)

This scan is needed for a Salesforce managed-package security review. I have reproduced the error twice on this Mac with different plugin versions. I have not tested it on a second computer. I can provide further diagnostic information or a reduced reproduction if requested.

Workaround

No workaround found. Updating Code Analyzer from 5.13.0 to 5.16.0 did not resolve the error.

Urgency

High

主要语言
TypeScript
星标
240
派生
52
PR 合并指标
30 天内没有已合并 PR

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

forcedotcom/code-analyzer 的其他 Issue

查看 forcedotcom/code-analyzer 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。