---
name: springboot-verification
description: "Verify a Spring Boot project before a pull request, large change, or release. Check the build, code rules, tests, coverage, known security flaws, format, and Git diff."
---

# Spring Boot Check Loop

Run this before a pull request, after a large change, and before a release.

Use the build tool already used by the project. Prefer `./mvnw` or `./gradlew` when present. Do not add a new tool or plugin just to run this check.

Stop when a required check fails. Fix the cause, then run the failed check again.

## 1. Build

For Maven:

```bash
./mvnw -T 4 clean verify -DskipTests
```

For Gradle:

```bash
./gradlew clean assemble -x test
```

If there is no wrapper, use `mvn` or `gradle`.

## 2. Check Code Rules

Run only tasks that the project has.

For Maven:

```bash
./mvnw -T 4 spotbugs:check pmd:check checkstyle:check
```

For Gradle:

```bash
./gradlew checkstyleMain pmdMain spotbugsMain
```

A missing plugin is not a code failure. Mark that check as skipped and name the missing plugin.

## 3. Run Tests and Coverage

For Maven:

```bash
./mvnw -T 4 test
./mvnw jacoco:report
```

For Gradle:

```bash
./gradlew test jacocoTestReport
```

Check these items:

- Total tests
- Passed, failed, and skipped tests
- Line coverage
- Branch coverage
- Failed test names

Use the coverage rule set by the project. If none exists, use 80% as a guide, not a hard rule.

Common report paths:

- Maven tests: `target/surefire-reports/`
- Maven coverage: `target/site/jacoco/index.html`
- Gradle tests: `build/reports/tests/test/index.html`
- Gradle coverage: `build/reports/jacoco/test/html/index.html`

If no tests exist, mark the test step as incomplete. Do not report it as passed.

## 4. Scan for Security Issues

Run a dependency scan only when the project has the OWASP plugin.

For Maven:

```bash
./mvnw org.owasp:dependency-check-maven:check
```

For Gradle:

```bash
./gradlew dependencyCheckAnalyze
```

Scan Git history for secrets only when `git-secrets` is set up:

```bash
git secrets --scan
```

Do not show secret values in the report. Show only the file name, line number, and type of issue.

A scan can fail due to a blocked download or old data. Report this as a scan error, not as proof that the project is safe.

## 5. Check Format

Use a check task when one exists:

```bash
./mvnw spotless:check
./gradlew spotlessCheck
```

Do not run a task that edits files unless the user asks for it. If asked, use:

```bash
./mvnw spotless:apply
./gradlew spotlessApply
```

After a format fix, run the tests again.

## 6. Review the Diff

Check both saved and staged changes:

```bash
git status --short
git diff --stat
git diff
git diff --cached
```

Look for:

- Debug code such as `System.out`
- Debug logs with no guard
- Wrong or unclear HTTP status codes
- Error text that does not help the user
- Missing input checks
- Missing or too-wide transactions
- New config with no docs
- Keys, passwords, or private data
- Generated files that should not be saved
- Test files that were disabled or removed
- Database changes with no safe upgrade path

If the folder is not a Git repo, mark the diff check as skipped.

## Example

A Maven project has `mvnw`, JaCoCo, Checkstyle, and Spotless. It does not have PMD or SpotBugs.

Run:

```bash
./mvnw -T 4 clean verify -DskipTests
./mvnw checkstyle:check
./mvnw -T 4 test
./mvnw jacoco:report
./mvnw spotless:check
git status --short
git diff --stat
git diff
git diff --cached
```

Mark PMD and SpotBugs as skipped. Do not try to add them.

## Report

```text
Verification Report
===================
Build:        [PASS / FAIL]
Code rules:   [PASS / FAIL / SKIPPED]
Tests:        [PASS / FAIL / INCOMPLETE]
              [X passed, Y failed, Z skipped]
Coverage:     [X% lines, Y% branches]
Security:     [PASS / FAIL / SCAN ERROR / SKIPPED]
Format:       [PASS / FAIL / SKIPPED]
Diff:         [X files changed]

Overall:      [READY / NOT READY]

Checks skipped:
1. [Check and reason]

Issues to fix:
1. [File and clear issue]
2. [File and clear issue]
```

Use `READY` only when all required checks pass. A skipped optional tool is allowed. A skipped required check is not allowed.

## Keep Checking

After a large edit, run the full loop again.

During long work, run a short loop every 30 to 60 minutes:

```bash
./mvnw -T 4 test
```

Also run the code check used by the project. Treat warnings as failures when the project or release rules say so.