You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让HP Fortify识别Lombok注解生成的Java方法?

Fixing HP Fortify's Unresolved Lombok Annotation Methods (e.g. @Getter) in Java Scans

Hey folks, I’ve dealt with this exact Lombok + HP Fortify headache a handful of times—let me walk you through the most reliable fixes I’ve used:

  • Pre-process your code with Lombok first (most effective fix)
    Fortify’s static analyzer doesn’t natively handle Lombok’s compile-time code generation. That means it can’t see the getter/setter methods that @Getter or @Data would normally create during compilation. The solution here is to let Lombok expand your code into plain Java (without annotations) before Fortify scans it.
    If you’re using Maven, add the Lombok Maven plugin to your pom.xml to generate the expanded source files:

    <build>
      <plugins>
        <plugin>
          <groupId>org.projectlombok</groupId>
          <artifactId>lombok-maven-plugin</artifactId>
          <version>1.18.24.0</version>
          <executions>
            <execution>
              <phase>generate-sources</phase>
              <goals>
                <goal>delombok</goal>
              </goals>
            </execution>
          </executions>
        </plugin>
      </plugins>
    </build>
    Run `mvn clean generate-sources` and you’ll find the expanded code in `target/generated-sources/delombok`. Point Fortify to scan this directory instead of your original source code—this eliminates the unresolved method errors entirely.
    
    
  • Teach Fortify to recognize Lombok annotations
    If pre-processing isn’t feasible for your workflow, you can create custom rules in Fortify to map Lombok annotations to the methods they generate:

    1. Open the Fortify Security Content Manager (SCM).
    2. Head to Rules > Custom Rules > Annotation Rules.
    3. Create a new rule for @Getter: set the annotation class to lombok.Getter, and configure it to flag that this annotation generates getter methods (matching patterns like get[FieldName]() for regular fields or is[FieldName]() for booleans).
    4. Repeat this for other Lombok annotations you use, like @Setter or @Data.
  • Update Fortify to the latest version
    Older Fortify versions (pre-2021) have spotty Lombok support. HP has added better native handling for common Lombok annotations in newer releases of Fortify Static Code Analyzer (SCA). If you’re running an outdated version, updating might resolve the issue without extra configuration.

  • Ensure Fortify has access to the Lombok JAR
    Sometimes Fortify can’t recognize Lombok annotations at all because it doesn’t have the Lombok JAR in its classpath. When running the sourceanalyzer command, include the Lombok JAR using the -cp flag:

    sourceanalyzer -cp path/to/your/lombok.jar -b yourBuildID src/main/java
    

    This helps Fortify identify the annotation types, even if it still needs a little help recognizing the generated methods.

内容的提问来源于stack exchange,提问作者Richard Sand

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 10:10:31