Skip to content

Remove usages of Commons Lang 2 - #112

Open
timja-bot wants to merge 1 commit into
jenkinsci:masterfrom
timja:commons-lang3
Open

Remove usages of Commons Lang 2#112
timja-bot wants to merge 1 commit into
jenkinsci:masterfrom
timja:commons-lang3

Conversation

@timja-bot

Copy link
Copy Markdown

No need to depend on a third-party library here when the Java Platform provides this
functionality natively.

Part of the effort to remove Commons Lang 2 from Jenkins core — jenkinsci/jenkins#16404,
jenkinsci/jenkins#26105. Commons Lang 2 is EOL and carries an unfixed advisory
(GHSA-j288-q9x7-2f5v).

What's changed

  • FolderAuthorizationStrategyAPI: the three StringUtils.isBlank(sid) checks become
    sid == null || sid.isBlank().
  • FolderAuthorizationWebAPITest still needs StringUtils.capitalize, which has no JDK equivalent,
    so io.jenkins.plugins:commons-lang3-api is declared with <scope>test</scope> and the import
    moved to Lang 3 — src/main stays dependency-free.

Testing done

mvn -B -ntp clean verify passes locally on Java 21 / macOS.

The ban-commons-lang-2 enforcer rule was left disabled: it needs parent POM 6.2116.v7501b_67dc517 or newer. I tried the bump, but the newer SpotBugs
then fails on a pre-existing US_USELESS_SUPPRESSION_ON_METHOD for NP_BOOLEAN_RETURN_NULL in
AbstractAcl.hasPermission — an unrelated cleanup, so I left the parent alone.

Submitter checklist

  • Make sure you are opening from a topic/feature/bugfix branch (right side) and not your main branch!
  • Ensure that the pull request title represents the desired changelog entry
  • Please describe what you did
  • Link to relevant issues in GitHub or Jira
  • Link to relevant pull requests, esp. upstream and downstream changes
  • Ensure you have provided tests that demonstrate the feature works or the issue is fixed

🤖 This pull request was generated with AI assistance (Claude Code) as part of a bulk migration
across Jenkins plugins. If anything here looks wrong, please comment on this PR or contact @timja.

@timja-bot
timja-bot requested a review from a team as a code owner August 3, 2026 08:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants