Skip to content

Migrate from Commons Lang to native Java Platform functionality - #103

Open
timja wants to merge 1 commit into
jenkinsci:masterfrom
timja:commons-lang3
Open

Migrate from Commons Lang to native Java Platform functionality#103
timja wants to merge 1 commit into
jenkinsci:masterfrom
timja:commons-lang3

Conversation

@timja

@timja timja commented Aug 7, 2026

Copy link
Copy Markdown
Member

No need to use a third-party library when this functionality is available in the Java Platform.

Part of the effort to remove Commons Lang 2 from Jenkins core — jenkinsci/jenkins#16404,
jenkinsci/jenkins#26105. Commons Lang 2 is EOL and carries an unfixed advisory
(GHSA-j288-q9x7-2f5v).

What's changed

  • StringUtils.isEmpty / isNotEmpty / isBlank / isNotBlank → the hudson.Util.fixEmpty* helpers.
  • ArrayUtils.contains(arguments, x)Arrays.asList(arguments).contains(x) in
    JenkinsBrowserStackLocalTest.
  • RandomStringUtils.random(48, letters, numbers) in Tools.getUniqueString is now a small local
    helper over SecureRandom building from the same letter/digit pools. Commons Lang 2 backed that
    call with a plain java.util.Random; since the result is used as a tracking identifier I did not
    want to hand-write a weaker generator. One deliberate narrowing: Commons Lang 2 would draw from the
    full character range if both flags were false, whereas this version assumes at least one is set.
    Both call sites pass (true, true).
  • Removed an import of io.jenkins.cli.shaded.org.apache.commons.lang.StringUtils in
    QualityDashboardPipelineTracker. That is the copy of Commons Lang shaded inside the Jenkins CLI
    jar — almost certainly an IDE auto-import accident, and not something to depend on. It had no call
    sites left after the rewrite.

No new dependency is added — commons-lang3-api requires core 2.479.3 and this plugin's baseline is
2.334.

Testing done

mvn -B -ntp clean verify on Java 11 / macOS: 38 tests, 6 errors — and unmodified master gives
exactly the same 38 tests and 6 errors, so they are pre-existing and unrelated to this change. Five
are HtmlUnit failing on modern JS (Cannot find function createHTMLDocument) and one is ByteBuddy
being unable to self-attach (Can not attach to current VM).

Newer JDKs do not work at all here: maven-license-plugin:1.7 throws ExceptionInInitializerError
on Java 17 and 21, again on unmodified master.

The ban-commons-lang-2 enforcer rule was left disabled because it needs parent POM
6.2116.v7501b_67dc517 or newer; bumping the parent from 3.4 was out of scope here.

Submitter checklist

  • Make sure you are opening from a topic/feature/bugfix branch (right side) and not your main branch!
  • Ensure that the pull request title represents the desired changelog entry
  • Please describe what you did
  • Link to relevant issues in GitHub or Jira
  • Link to relevant pull requests, esp. upstream and downstream changes
  • Ensure you have provided tests that demonstrate the feature works or the issue is fixed

🤖 This pull request was generated with AI assistance (Claude Code) as part of a bulk migration
across Jenkins plugins. If anything here looks wrong, please comment on this PR or contact
@parameter.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant