如何让HP Fortify识别Lombok注解生成的Java方法?
Hey folks, I’ve dealt with this exact Lombok + HP Fortify headache a handful of times—let me walk you through the most reliable fixes I’ve used:
Pre-process your code with Lombok first (most effective fix)
Fortify’s static analyzer doesn’t natively handle Lombok’s compile-time code generation. That means it can’t see the getter/setter methods that@Getteror@Datawould normally create during compilation. The solution here is to let Lombok expand your code into plain Java (without annotations) before Fortify scans it.
If you’re using Maven, add the Lombok Maven plugin to yourpom.xmlto generate the expanded source files:<build> <plugins> <plugin> <groupId>org.projectlombok</groupId> <artifactId>lombok-maven-plugin</artifactId> <version>1.18.24.0</version> <executions> <execution> <phase>generate-sources</phase> <goals> <goal>delombok</goal> </goals> </execution> </executions> </plugin> </plugins> </build> Run `mvn clean generate-sources` and you’ll find the expanded code in `target/generated-sources/delombok`. Point Fortify to scan this directory instead of your original source code—this eliminates the unresolved method errors entirely.Teach Fortify to recognize Lombok annotations
If pre-processing isn’t feasible for your workflow, you can create custom rules in Fortify to map Lombok annotations to the methods they generate:- Open the Fortify Security Content Manager (SCM).
- Head to Rules > Custom Rules > Annotation Rules.
- Create a new rule for
@Getter: set the annotation class tolombok.Getter, and configure it to flag that this annotation generates getter methods (matching patterns likeget[FieldName]()for regular fields oris[FieldName]()for booleans). - Repeat this for other Lombok annotations you use, like
@Setteror@Data.
Update Fortify to the latest version
Older Fortify versions (pre-2021) have spotty Lombok support. HP has added better native handling for common Lombok annotations in newer releases of Fortify Static Code Analyzer (SCA). If you’re running an outdated version, updating might resolve the issue without extra configuration.Ensure Fortify has access to the Lombok JAR
Sometimes Fortify can’t recognize Lombok annotations at all because it doesn’t have the Lombok JAR in its classpath. When running thesourceanalyzercommand, include the Lombok JAR using the-cpflag:sourceanalyzer -cp path/to/your/lombok.jar -b yourBuildID src/main/javaThis helps Fortify identify the annotation types, even if it still needs a little help recognizing the generated methods.
内容的提问来源于stack exchange,提问作者Richard Sand

