dependabot[bot] opened a new pull request, #13293: URL: https://github.com/apache/maven/pull/13293
Bumps [net.sourceforge.pmd:pmd-core](https://github.com/pmd/pmd) from 7.27.0 to 7.28.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pmd/pmd/releases">net.sourceforge.pmd:pmd-core's releases</a>.</em></p> <blockquote> <h2>PMD 7.28.0 (25-September-2026)</h2> <h2>25-September-2026 - 7.28.0</h2> <p>The PMD team is pleased to announce PMD 7.28.0.</p> <p>This is a minor release.</p> <h3>Table Of Contents</h3> <ul> <li><a href="https://github.com/pmd/pmd/blob/HEAD/#new-and-noteworthy">🚀️ New and noteworthy</a> <ul> <li><a href="https://github.com/pmd/pmd/blob/HEAD/#kotlin-xpath-functions-and-type-attributes">Kotlin XPath functions and type attributes</a></li> </ul> </li> <li><a href="https://github.com/pmd/pmd/blob/HEAD/#new-and-changed-rules">🌟️ New and Changed Rules</a> <ul> <li><a href="https://github.com/pmd/pmd/blob/HEAD/#new-rules">New Rules</a></li> <li><a href="https://github.com/pmd/pmd/blob/HEAD/#changed-rules">Changed Rules</a></li> </ul> </li> <li><a href="https://github.com/pmd/pmd/blob/HEAD/#fixed-issues">🐛️ Fixed Issues</a></li> <li><a href="https://github.com/pmd/pmd/blob/HEAD/#api-changes">🚨️ API Changes</a> <ul> <li><a href="https://github.com/pmd/pmd/blob/HEAD/#experimental-api">Experimental API</a></li> </ul> </li> <li><a href="https://github.com/pmd/pmd/blob/HEAD/#merged-pull-requests">✨️ Merged pull requests</a></li> <li><a href="https://github.com/pmd/pmd/blob/HEAD/#dependency-updates">📦️ Dependency updates</a></li> <li><a href="https://github.com/pmd/pmd/blob/HEAD/#stats">📈️ Stats</a></li> </ul> <h3>🚀️ New and noteworthy</h3> <h4>Kotlin XPath functions and type attributes</h4> <p>Type data is now accessible in XPath rules via new attributes and helper functions (see <a href="https://docs.pmd-code.org/pmd-doc-7.28.0/pmd_languages_kotlin.html#xpath-rule-support">Kotlin XPath rule support</a>):</p> <ul> <li><strong>Type-info Attributes</strong>: <code>@TypeName</code>, <code>@ReturnTypeName</code>, <code>@AnnotationFqNames</code> are exposed on declaration nodes (property, function, class, parameter, catch, for-loop, delegation specifier, annotation nodes). These attributes depend on type resolution: they are only available when <code>auxClasspath</code> is configured and the kotlin-type-mapper analysis has resolved the types.</li> <li><strong>General Attributes</strong>: <code>@Mutable</code>, <code>@Identifier</code>, <code>@Name</code> are exposed on declaration and import related nodes. These attributes don't depend on type resolution, so they're always present regardless of <code>auxClasspath</code>.</li> <li><strong>XPath functions</strong>: <ul> <li><code>pmd-kotlin:typeIs(typeName)</code>: matches if the node's type is <code>typeName</code> or a subtype.</li> <li><code>pmd-kotlin:typeIsExactly(typeName)</code>: matches the exact declared type only (no subtypes).</li> <li><code>pmd-kotlin:hasAnnotation(name)</code>: matches if the node has an annotation with the given simple or FQN.</li> <li><code>pmd-kotlin:modifiers()</code>: returns the modifier keywords of a declaration as a sequence.</li> <li><code>pmd-kotlin:isNullable()</code>: returns <code>true</code> if the node's declared type is nullable (has <code>?</code>).</li> <li><code>pmd-kotlin:hasUnresolvedReference()</code>: returns <code>true</code> if the node contains an unresolved reference.</li> <li><code>pmd-kotlin:matchesSig(signature)</code>: matches call sites by method signature pattern (supports wildcards).</li> </ul> </li> </ul> <h3>🌟️ New and Changed Rules</h3> <h4>New Rules</h4> <ul> <li>The new Java rule <a href="https://docs.pmd-code.org/pmd-doc-7.28.0/pmd_rules_java_bestpractices.html#ondemandimport"><code>OnDemandImport</code></a> reports on-demand imports, also known as wildcard imports. By default, static imports from JUnit and TestNG are allowed. The allowed static and type import packages can be configured with <code>allowStaticImportsFrom</code> and <code>allowTypeImportsFrom</code>.</li> <li>The new Java rule <a href="https://docs.pmd-code.org/pmd-doc-7.28.0/pmd_rules_java_errorprone.html#longliteralendingwithlowercasel"><code>LongLiteralEndingWithLowercaseL</code></a> finds long literals ending with a lowercase <code>l</code>.</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pmd/pmd/commit/79726f0e8f46c1a9954a3f9880f6d15c91bf6387"><code>79726f0</code></a> [release] prepare release pmd_releases/7.28.0</li> <li><a href="https://github.com/pmd/pmd/commit/ba7d31ec89df8ec9b19a4b4036546fd317c76819"><code>ba7d31e</code></a> Prepare pmd release 7.28.0</li> <li><a href="https://github.com/pmd/pmd/commit/fb85046f9aa6d2fd180fcacd804aa7ddfb86799e"><code>fb85046</code></a> Update contributors for 7.28.0</li> <li><a href="https://github.com/pmd/pmd/commit/5569f8c14aa004e238eb8da323b02c816d348aee"><code>5569f8c</code></a> [doc] Update release notes for 7.28.0 (<a href="https://redirect.github.com/pmd/pmd/issues/7106">#7106</a>)</li> <li><a href="https://github.com/pmd/pmd/commit/ca7381c93f1fdc45b621b86ba944ddc3989db4a4"><code>ca7381c</code></a> [doc] Add gradle environment vars example (<a href="https://redirect.github.com/pmd/pmd/issues/7111">#7111</a>)</li> <li><a href="https://github.com/pmd/pmd/commit/388f07a7f249d911fcf6b90768972e1ea3a375e1"><code>388f07a</code></a> [java] Fix <a href="https://redirect.github.com/pmd/pmd/issues/7101">#7101</a>: Skip non-archive files on the auxclasspath (<a href="https://redirect.github.com/pmd/pmd/issues/7102">#7102</a>)</li> <li><a href="https://github.com/pmd/pmd/commit/251ef73774335f3644b481ac8ab74114fad2543a"><code>251ef73</code></a> [cli] Add the missing exit code 5 to the CLI help (<a href="https://redirect.github.com/pmd/pmd/issues/7090">#7090</a>)</li> <li><a href="https://github.com/pmd/pmd/commit/1831734ffc2008a64aeb48c20820416f021c95fe"><code>1831734</code></a> [doc] TOC highlighting improvements (<a href="https://redirect.github.com/pmd/pmd/issues/7089">#7089</a>)</li> <li><a href="https://github.com/pmd/pmd/commit/383ff529c0247fc2ada5a3e3f78f0b71c800b6b6"><code>383ff52</code></a> [java] Fix <a href="https://redirect.github.com/pmd/pmd/issues/7056">#7056</a>: Add JavaLanguageProperty to disable auxClasspath warnings (...</li> <li><a href="https://github.com/pmd/pmd/commit/0a145687301d8e330271e27ff3d9ab279fb565a8"><code>0a14568</code></a> [java] New rule: InternalApiUsage (<a href="https://redirect.github.com/pmd/pmd/issues/6994">#6994</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pmd/pmd/compare/pmd_releases/7.27.0...pmd_releases/7.28.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
