How do SpotBugs and find-sec-bugs differ from Checkstyle/PMD, and how do you wire them up in Maven?
answer
- SpotBugs = bytecode, needs compile
- find-sec-bugs nests inside spotbugs <plugins>
- effort vs threshold
- excludeFilterFile / @SuppressFBWarnings
- PMD has CPD for duplicates
basics
~20 sCheckstyle and PMD read your source code; SpotBugs reads compiled bytecode, so it must run after compilation. find-sec-bugs is a SpotBugs plugin adding security bug patterns. You add it under the spotbugs plugin's <plugins> and run spotbugs:check.
solid answer
~40 sCheckstyle (style) and PMD (smells/CPD) analyze source files. SpotBugs analyzes the compiled .class bytecode, so it needs the classes to exist — it binds after compile, typically at verify. find-sec-bugs isn't a separate Maven plugin: it's a SpotBugs detector plugin you nest inside spotbugs-maven-plugin's <plugins>, adding ~135 security patterns (SQL injection, path traversal, weak crypto, hardcoded keys). Key SpotBugs knobs: effort (Min/Default/Max — deeper = slower but more findings), threshold (confidence), an excludeFilterFile for suppressions, and failOnError to gate. Because it's bytecode-based it can find things source tools miss (e.g. null deref across methods) but can't see code that didn't compile, and reports use bytecode-ish locations.
code
xml · 7 lines<plugins>
<plugin>
<groupId>com.h3xstream.findsecbugs</groupId>
<artifactId>findsecbugs-plugin</artifactId>
<version>1.13.0</version>
</plugin>
</plugins>go deeper
SpotBugs checks compiled code; find-sec-bugs adds security checks.
Knows the nesting, effort vs threshold, and the bytecode dependency.
Balances effort/threshold against noise and curates exclude filters so security findings stay actionable.
Decides where security static analysis fits in the pipeline vs SAST/dependency scanning and sets the suppression governance.
## Source vs bytecode analysis - **Checkstyle** parses *source* and checks formatting/style conventions; it knows nothing about runtime behavior. - **PMD** parses *source* into an AST to find smells (unused code, complexity, empty blocks) and includes **CPD** for duplicate detection. - **SpotBugs** analyzes *compiled bytecode*, so it can reason about data flow, null dereferences, resource leaks, and concurrency issues that aren't obvious in source. The trade: it requires successful compilation and produces bytecode-flavored locations. ## find-sec-bugs **find-sec-bugs** is a *plugin for SpotBugs* (not a standalone Maven plugin) contributing security detectors: SQL/LDAP/command injection, path traversal, XXE, weak hashing/ciphers, hardcoded passwords, insecure randomness. You enable it by nesting it inside the spotbugs-maven-plugin configuration. ```xml <plugin> <groupId>com.github.spotbugs</groupId> <artifactId>spotbugs-maven-plugin</artifactId> <version>4.8.6.6</version> <configuration> <effort>Max</effort> <threshold>Low</threshold> <excludeFilterFile>config/spotbugs-exclude.xml</excludeFilterFile> <plugins> <plugin> <groupId>com.h3xstream.findsecbugs</groupId> <artifactId>findsecbugs-plugin</artifactId> <version>1.13.0</version> </plugin> </plugins> </configuration> <executions> <execution> <phase>verify</phase> <goals><goal>check</goal></goals> </execution> </executions> </plugin> ``` ## effort vs threshold - **effort** (Min/Default/Max): how hard SpotBugs works — Max finds more but is slower and noisier. - **threshold** (Low/Medium/High): minimum *confidence* a bug must have to be reported; Low = report even uncertain findings. For security you usually run high effort and a low threshold, then suppress noise via the exclude filter. ## Suppressions SpotBugs uses an **excludeFilterFile** (XML matching by Bug pattern/class/method) or the `@SuppressFBWarnings` annotation in code. This is different from Checkstyle's suppressions XML and PMD's `@SuppressWarnings("PMD.Rule")` / ruleset excludes — each tool has its own suppression mechanism.
- Why can't SpotBugs run as early in the lifecycle as Checkstyle?It needs compiled .class files, so it binds after the compile phase (typically verify); Checkstyle reads source and can run at validate.
- Is find-sec-bugs a Maven plugin you add to <build><plugins>?No — it's a SpotBugs detector plugin nested inside spotbugs-maven-plugin's <configuration><plugins>; it doesn't have its own lifecycle binding.
saying these in an interview costs you the question
- Treating find-sec-bugs as its own top-level Maven plugin
- Claiming SpotBugs reads source code
- Running SpotBugs before compile and wondering why it finds nothing