---
title: "skill by agenticluke · skilld"
canonical_url: "https://skilld.dev/gh/agenticluke/spring-boot-check-plus"
meta:
  description: "Verify a Spring Boot project before a pull request, large change, or release. Check the build, code rules, tests, coverage, known security flaws, format, and… From agenticluke/spring-boot-check-plus."
  "og:description": "Verify a Spring Boot project before a pull request, large change, or release. Check the build, code rules, tests, coverage, known security flaws, format, and… From agenticluke/spring-boot-check-plus."
  "og:title": "skill by agenticluke"
  "twitter:description": "Verify a Spring Boot project before a pull request, large change, or release. Check the build, code rules, tests, coverage, known security flaws, format, and… From agenticluke/spring-boot-check-plus."
  "twitter:title": "skill by agenticluke"
---

`

[All skills](https://skilld.dev/skills)

[![agenticluke avatar](https://skilld.dev/_img/avatar?url=https%3A%2F%2Fgithub.com%2Fagenticluke.png%3Fsize%3D96)](https://skilld.dev/gh/agenticluke)

# **/skill**

[@8712845](https://github.com/agenticluke/spring-boot-check-plus/commit/871284505d9a270617ac83b427f172bff378da73 "Your agent reads SKILL.md at commit 8712845")

by [agenticluke](https://skilld.dev/gh/agenticluke)· [agenticluke](https://skilld.dev/gh/agenticluke)/ [spring-boot-check-plus](https://skilld.dev/gh/agenticluke/spring-boot-check-plus)

Verify a Spring Boot project before a pull request, large change, or release. Check the build, code rules, tests, coverage, known security flaws, format, and Git diff.

- 1 file
- 4.4 KB
- Updated 2 weeks ago
- [GitHub](https://github.com/agenticluke/spring-boot-check-plus/blob/871284505d9a270617ac83b427f172bff378da73/skill/SKILL.md "View SKILL.md on GitHub")

## SKILL.md

4.4 KB

**≈44** tokens always: the name and description. **≈1.1k** when used: this file.

## Spring Boot Check Loop

Run this before a pull request, after a large change, and before a release.

Use the build tool already used by the project. Prefer `./mvnw` or `./gradlew` when present. Do not add a new tool or plugin just to run this check.

Stop when a required check fails. Fix the cause, then run the failed check again.

### 1. Build

For Maven:

```
./mvnw -T 4 clean verify -DskipTests
```

For Gradle:

```
./gradlew clean assemble -x test
```

If there is no wrapper, use `mvn` or `gradle`.

### 2. Check Code Rules

Run only tasks that the project has.

For Maven:

```
./mvnw -T 4 spotbugs:check pmd:check checkstyle:check
```

For Gradle:

```
./gradlew checkstyleMain pmdMain spotbugsMain
```

A missing plugin is not a code failure. Mark that check as skipped and name the missing plugin.

### 3. Run Tests and Coverage

For Maven:

```
./mvnw -T 4 test
./mvnw jacoco:report
```

For Gradle:

```
./gradlew test jacocoTestReport
```

Check these items:

- Total tests
- Passed, failed, and skipped tests
- Line coverage
- Branch coverage
- Failed test names

Use the coverage rule set by the project. If none exists, use 80% as a guide, not a hard rule.

Common report paths:

- Maven tests: `target/surefire-reports/`
- Maven coverage: `target/site/jacoco/index.html`
- Gradle tests: `build/reports/tests/test/index.html`
- Gradle coverage: `build/reports/jacoco/test/html/index.html`

If no tests exist, mark the test step as incomplete. Do not report it as passed.

### 4. Scan for Security Issues

Run a dependency scan only when the project has the OWASP plugin.

For Maven:

```
./mvnw org.owasp:dependency-check-maven:check
```

For Gradle:

```
./gradlew dependencyCheckAnalyze
```

Scan Git history for secrets only when `git-secrets` is set up:

```
git secrets --scan
```

Do not show secret values in the report. Show only the file name, line number, and type of issue.

A scan can fail due to a blocked download or old data. Report this as a scan error, not as proof that the project is safe.

### 5. Check Format

Use a check task when one exists:

```
./mvnw spotless:check
./gradlew spotlessCheck
```

Do not run a task that edits files unless the user asks for it. If asked, use:

```
./mvnw spotless:apply
./gradlew spotlessApply
```

After a format fix, run the tests again.

### 6. Review the Diff

Check both saved and staged changes:

```
git status --short
git diff --stat
git diff
git diff --cached
```

Look for:

- Debug code such as `System.out`
- Debug logs with no guard
- Wrong or unclear HTTP status codes
- Error text that does not help the user
- Missing input checks
- Missing or too-wide transactions
- New config with no docs
- Keys, passwords, or private data
- Generated files that should not be saved
- Test files that were disabled or removed
- Database changes with no safe upgrade path

If the folder is not a Git repo, mark the diff check as skipped.

### Example

A Maven project has `mvnw`, JaCoCo, Checkstyle, and Spotless. It does not have PMD or SpotBugs.

Run:

```
./mvnw -T 4 clean verify -DskipTests
./mvnw checkstyle:check
./mvnw -T 4 test
./mvnw jacoco:report
./mvnw spotless:check
git status --short
git diff --stat
git diff
git diff --cached
```

Mark PMD and SpotBugs as skipped. Do not try to add them.

### Report

```
Verification Report
===================
Build:        [PASS / FAIL]
Code rules:   [PASS / FAIL / SKIPPED]
Tests:        [PASS / FAIL / INCOMPLETE]
              [X passed, Y failed, Z skipped]
Coverage:     [X% lines, Y% branches]
Security:     [PASS / FAIL / SCAN ERROR / SKIPPED]
Format:       [PASS / FAIL / SKIPPED]
Diff:         [X files changed]

Overall:      [READY / NOT READY]

Checks skipped:
1. [Check and reason]

Issues to fix:
1. [File and clear issue]
2. [File and clear issue]
```

Use `READY` only when all required checks pass. A skipped optional tool is allowed. A skipped required check is not allowed.

### Keep Checking

After a large edit, run the full loop again.

During long work, run a short loop every 30 to 60 minutes:

```
./mvnw -T 4 test
```

Also run the code check used by the project. Treat warnings as failures when the project or release rules say so.

Source: [SKILL.md on GitHub](https://github.com/agenticluke/spring-boot-check-plus/blob/871284505d9a270617ac83b427f172bff378da73/skill/SKILL.md)

## Third-party checks

No third-party reports yet.

## Provenance

[Signed by skilld at 8712845.](https://github.com/agenticluke/spring-boot-check-plus/commit/871284505d9a270617ac83b427f172bff378da73 "871284505d9a270617ac83b427f172bff378da73") This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 weeks ago

## README badge

![README badge for agenticluke/spring-boot-check-plus](https://skilld.dev/b/agenticluke/spring-boot-check-plus?theme=light&label=0)

## Related skills

-
-
-
-
-
-