dependabot[bot] opened a new pull request, #13293:
URL: https://github.com/apache/maven/pull/13293

   Bumps [net.sourceforge.pmd:pmd-core](https://github.com/pmd/pmd) from 7.27.0 
to 7.28.0.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/pmd/pmd/releases";>net.sourceforge.pmd:pmd-core's 
releases</a>.</em></p>
   <blockquote>
   <h2>PMD 7.28.0 (25-September-2026)</h2>
   <h2>25-September-2026 - 7.28.0</h2>
   <p>The PMD team is pleased to announce PMD 7.28.0.</p>
   <p>This is a minor release.</p>
   <h3>Table Of Contents</h3>
   <ul>
   <li><a href="https://github.com/pmd/pmd/blob/HEAD/#new-and-noteworthy";>🚀️ 
New and noteworthy</a>
   <ul>
   <li><a 
href="https://github.com/pmd/pmd/blob/HEAD/#kotlin-xpath-functions-and-type-attributes";>Kotlin
 XPath functions and type attributes</a></li>
   </ul>
   </li>
   <li><a href="https://github.com/pmd/pmd/blob/HEAD/#new-and-changed-rules";>🌟️ 
New and Changed Rules</a>
   <ul>
   <li><a href="https://github.com/pmd/pmd/blob/HEAD/#new-rules";>New 
Rules</a></li>
   <li><a href="https://github.com/pmd/pmd/blob/HEAD/#changed-rules";>Changed 
Rules</a></li>
   </ul>
   </li>
   <li><a href="https://github.com/pmd/pmd/blob/HEAD/#fixed-issues";>🐛️ Fixed 
Issues</a></li>
   <li><a href="https://github.com/pmd/pmd/blob/HEAD/#api-changes";>🚨️ API 
Changes</a>
   <ul>
   <li><a 
href="https://github.com/pmd/pmd/blob/HEAD/#experimental-api";>Experimental 
API</a></li>
   </ul>
   </li>
   <li><a href="https://github.com/pmd/pmd/blob/HEAD/#merged-pull-requests";>✨️ 
Merged pull requests</a></li>
   <li><a href="https://github.com/pmd/pmd/blob/HEAD/#dependency-updates";>📦️ 
Dependency updates</a></li>
   <li><a href="https://github.com/pmd/pmd/blob/HEAD/#stats";>📈️ Stats</a></li>
   </ul>
   <h3>🚀️ New and noteworthy</h3>
   <h4>Kotlin XPath functions and type attributes</h4>
   <p>Type data is now accessible in XPath rules via new attributes and helper 
functions (see <a 
href="https://docs.pmd-code.org/pmd-doc-7.28.0/pmd_languages_kotlin.html#xpath-rule-support";>Kotlin
 XPath rule support</a>):</p>
   <ul>
   <li><strong>Type-info Attributes</strong>: <code>@TypeName</code>, 
<code>@ReturnTypeName</code>, <code>@AnnotationFqNames</code>
   are exposed on declaration nodes (property, function, class, parameter, 
catch, for-loop, delegation specifier,
   annotation nodes). These attributes depend on type resolution: they are only 
available when <code>auxClasspath</code>
   is configured and the kotlin-type-mapper analysis has resolved the 
types.</li>
   <li><strong>General Attributes</strong>: <code>@Mutable</code>, 
<code>@Identifier</code>, <code>@Name</code>
   are exposed on declaration and import related nodes. These attributes don't 
depend on type resolution, so
   they're always present regardless of <code>auxClasspath</code>.</li>
   <li><strong>XPath functions</strong>:
   <ul>
   <li><code>pmd-kotlin:typeIs(typeName)</code>: matches if the node's type is 
<code>typeName</code> or a subtype.</li>
   <li><code>pmd-kotlin:typeIsExactly(typeName)</code>: matches the exact 
declared type only (no subtypes).</li>
   <li><code>pmd-kotlin:hasAnnotation(name)</code>: matches if the node has an 
annotation with the given simple or FQN.</li>
   <li><code>pmd-kotlin:modifiers()</code>: returns the modifier keywords of a 
declaration as a sequence.</li>
   <li><code>pmd-kotlin:isNullable()</code>: returns <code>true</code> if the 
node's declared type is nullable (has <code>?</code>).</li>
   <li><code>pmd-kotlin:hasUnresolvedReference()</code>: returns 
<code>true</code> if the node contains an unresolved reference.</li>
   <li><code>pmd-kotlin:matchesSig(signature)</code>: matches call sites by 
method signature pattern (supports wildcards).</li>
   </ul>
   </li>
   </ul>
   <h3>🌟️ New and Changed Rules</h3>
   <h4>New Rules</h4>
   <ul>
   <li>The new Java rule <a 
href="https://docs.pmd-code.org/pmd-doc-7.28.0/pmd_rules_java_bestpractices.html#ondemandimport";><code>OnDemandImport</code></a>
 reports on-demand imports, also known as wildcard imports.
   By default, static imports from JUnit and TestNG are allowed. The allowed 
static and type import packages
   can be configured with <code>allowStaticImportsFrom</code> and 
<code>allowTypeImportsFrom</code>.</li>
   <li>The new Java rule  <a 
href="https://docs.pmd-code.org/pmd-doc-7.28.0/pmd_rules_java_errorprone.html#longliteralendingwithlowercasel";><code>LongLiteralEndingWithLowercaseL</code></a>
 finds long literals ending with a lowercase <code>l</code>.</li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/pmd/pmd/commit/79726f0e8f46c1a9954a3f9880f6d15c91bf6387";><code>79726f0</code></a>
 [release] prepare release pmd_releases/7.28.0</li>
   <li><a 
href="https://github.com/pmd/pmd/commit/ba7d31ec89df8ec9b19a4b4036546fd317c76819";><code>ba7d31e</code></a>
 Prepare pmd release 7.28.0</li>
   <li><a 
href="https://github.com/pmd/pmd/commit/fb85046f9aa6d2fd180fcacd804aa7ddfb86799e";><code>fb85046</code></a>
 Update contributors for 7.28.0</li>
   <li><a 
href="https://github.com/pmd/pmd/commit/5569f8c14aa004e238eb8da323b02c816d348aee";><code>5569f8c</code></a>
 [doc] Update release notes for 7.28.0 (<a 
href="https://redirect.github.com/pmd/pmd/issues/7106";>#7106</a>)</li>
   <li><a 
href="https://github.com/pmd/pmd/commit/ca7381c93f1fdc45b621b86ba944ddc3989db4a4";><code>ca7381c</code></a>
 [doc] Add gradle environment vars example (<a 
href="https://redirect.github.com/pmd/pmd/issues/7111";>#7111</a>)</li>
   <li><a 
href="https://github.com/pmd/pmd/commit/388f07a7f249d911fcf6b90768972e1ea3a375e1";><code>388f07a</code></a>
 [java] Fix <a 
href="https://redirect.github.com/pmd/pmd/issues/7101";>#7101</a>: Skip 
non-archive files on the auxclasspath (<a 
href="https://redirect.github.com/pmd/pmd/issues/7102";>#7102</a>)</li>
   <li><a 
href="https://github.com/pmd/pmd/commit/251ef73774335f3644b481ac8ab74114fad2543a";><code>251ef73</code></a>
 [cli] Add the missing exit code 5 to the CLI help (<a 
href="https://redirect.github.com/pmd/pmd/issues/7090";>#7090</a>)</li>
   <li><a 
href="https://github.com/pmd/pmd/commit/1831734ffc2008a64aeb48c20820416f021c95fe";><code>1831734</code></a>
 [doc] TOC highlighting improvements (<a 
href="https://redirect.github.com/pmd/pmd/issues/7089";>#7089</a>)</li>
   <li><a 
href="https://github.com/pmd/pmd/commit/383ff529c0247fc2ada5a3e3f78f0b71c800b6b6";><code>383ff52</code></a>
 [java] Fix <a 
href="https://redirect.github.com/pmd/pmd/issues/7056";>#7056</a>: Add 
JavaLanguageProperty to disable auxClasspath warnings (...</li>
   <li><a 
href="https://github.com/pmd/pmd/commit/0a145687301d8e330271e27ff3d9ab279fb565a8";><code>0a14568</code></a>
 [java] New rule: InternalApiUsage (<a 
href="https://redirect.github.com/pmd/pmd/issues/6994";>#6994</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/pmd/pmd/compare/pmd_releases/7.27.0...pmd_releases/7.28.0";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=net.sourceforge.pmd:pmd-core&package-manager=maven&previous-version=7.27.0&new-version=7.28.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to