What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Kotlin and Scala results depend on compiler output and are less reliable than Java, confirm before promising coverage
- Find Security Bugs is a separate third party plugin, confirm its current maintenance status
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
SpotBugs analyzes compiled bytecode rather than source. Detectors walk the instruction stream of each method, track the stack and local variable state, and report when the observed behavior matches a known bug pattern. Working at the bytecode level has a specific consequence: SpotBugs sees what the compiler actually produced, including desugared constructs, synthetic methods and inlined constants, so it catches issues that are invisible in source and it works on code you have as a JAR with no source at all.
The built in catalog covers correctness patterns such as null dereferences, equals and hashCode contract violations, infinite recursion, ignored return values, incorrect synchronization and resource leaks. Security detection is supplied mainly by Find Security Bugs, a separate plugin that adds detectors for SQL injection, command injection, XML external entity processing, unsafe deserialization, weak cryptography, path traversal and hardcoded credentials, with mappings to CWE and OWASP categories. That plugin is what makes SpotBugs a security tool at all, and it is maintained independently of the core project.
Where it fits
It runs as a build plugin under Maven, Gradle or Ant, after compilation and usually in the same job. Because it needs bytecode, it cannot run on a checkout that does not build, which rules out scanning arbitrary source snapshots. Results are commonly forwarded to a code quality server rather than read raw. Developers own it as part of the build, and an application security engineer typically curates which detectors and which confidence thresholds are enabled.
Strengths
- Bytecode analysis sees post compilation reality and works on artifacts without source.
- Zero cost, no server, and build plugin integration that requires almost no maintenance once configured.
- The Find Security Bugs detector set covers the injection and cryptography classes that matter for Java web applications, with CWE mappings.
- Filter files let you exclude by class, package, pattern and confidence, which is how teams make the output manageable.
Limitations
- Requires a successful compile. That is a hard dependency and it excludes several useful workflows.
- Security coverage depends entirely on a third party plugin whose maintenance pace has varied, and detectors can lag behind new framework and language features.
- Analysis is largely intraprocedural with limited cross method taint tracking, so injection through several layers of helper methods often goes unreported.
Who it suits
A sensible baseline for any JVM team that wants free static analysis inside an existing build, especially paired with Find Security Bugs. Not sufficient on its own for an organization that needs cross file taint tracking, non JVM language coverage or vendor support, and not usable at all where you cannot build the code you want to scan.
Used SpotBugs? Recommend it under your own name and title.
Recommend this tool