Repository navigation
Releases: pmd/pmd
Release list
PMD 7.29.0-SNAPSHOT (07-October-2026)
30-October-2026 - 7.29.0-SNAPSHOT
The PMD team is pleased to announce PMD 7.29.0-SNAPSHOT.
This is a minor release.
Table Of Contents
- 🚀️ New and noteworthy
- 🌟️ New and Changed Rules
- 🐛️ Fixed Issues
- 🚨️ API Changes
- ✨️ Merged pull requests
- 📦️ Dependency updates
- 📈️ Stats
🚀️ New and noteworthy
🌟️ New and Changed Rules
Changed Rules
- The Java rule
FinalFieldCouldBeStaticno longer reports casts or conditional expressions
whose constant classification previously depended on a boxed static final field. Direct static field references
are still reported. - The Java rule
UnconditionalIfStatementnow excludes final local boolean constants,
consistently with its existing exclusion of named compile-time constants used for conditional compilation. - The Java rule
UnusedNullCheckInEqualsnow recognizes final local String constants
and unqualified instance String constants as non-null receivers, avoiding unnecessary reports. - The Java rule
AvoidReassigningLoopVariables, withforReassign=skip, now accepts
a final local constant equal to one as the increment of a conditional skip. - The Java rule
UnusedAssignmentnow recognizes final local boolean constants
when analyzing short-circuit conditions, avoiding false positives caused by assignments that cannot execute. - The Java rule
LiteralsFirstInComparisonsnow recognizes final local String constants
and unqualified references to non-static final String constants. This may add violations when such a constant
is the argument of a comparison, or remove them when it is already the receiver. - The Java rule
UseExplicitTypeshas a new propertyallowLongTypeNames. It allows
to usevarwhen the explicit type name would be longer than a given minimum length configured with
this property.
🐛️ Fixed Issues
- core
- groovy
- java
- java-bestpractices
- #5159: [java] UnusedAssignment false positive when using assert
- java-codestyle
- #6903: [java] Enhance UseExplicitTypes to allow verbose long explicit types
- java-design
🚨️ API Changes
- Java constant folding now recognizes final primitive and String variables initialized with constant expressions,
including local variables and unqualified instance fields. Numeric references are converted to their declared type.
Boxed fields and field accesses qualified by expressions (such asthis.CONSTANT) are not compile-time constants.
These changes affectASTExpression.getConstValue(),isCompileTimeConstant(), and the XPath attribute
@CompileTimeConstant; custom Java and XPath rules relying on them may report different results.
✨️ Merged pull requests
📦️ Dependency updates
📈️ Stats
PMD 7.28.0 (25-September-2026)
25-September-2026 - 7.28.0
The PMD team is pleased to announce PMD 7.28.0.
This is a minor release.
Table Of Contents
- 🚀️ New and noteworthy
- 🌟️ New and Changed Rules
- 🐛️ Fixed Issues
- 🚨️ API Changes
- ✨️ Merged pull requests
- 📦️ Dependency updates
- 📈️ Stats
🚀️ New and noteworthy
Kotlin XPath functions and type attributes
Type data is now accessible in XPath rules via new attributes and helper functions (see Kotlin XPath rule support):
- Type-info Attributes:
@TypeName,@ReturnTypeName,@AnnotationFqNames
are exposed on declaration nodes (property, function, class, parameter, catch, for-loop, delegation specifier,
annotation nodes). These attributes depend on type resolution: they are only available whenauxClasspath
is configured and the kotlin-type-mapper analysis has resolved the types. - General Attributes:
@Mutable,@Identifier,@Name
are exposed on declaration and import related nodes. These attributes don't depend on type resolution, so
they're always present regardless ofauxClasspath. - XPath functions:
pmd-kotlin:typeIs(typeName): matches if the node's type istypeNameor a subtype.pmd-kotlin:typeIsExactly(typeName): matches the exact declared type only (no subtypes).pmd-kotlin:hasAnnotation(name): matches if the node has an annotation with the given simple or FQN.pmd-kotlin:modifiers(): returns the modifier keywords of a declaration as a sequence.pmd-kotlin:isNullable(): returnstrueif the node's declared type is nullable (has?).pmd-kotlin:hasUnresolvedReference(): returnstrueif the node contains an unresolved reference.pmd-kotlin:matchesSig(signature): matches call sites by method signature pattern (supports wildcards).
🌟️ New and Changed Rules
New Rules
- The new Java rule
OnDemandImportreports on-demand imports, also known as wildcard imports.
By default, static imports from JUnit and TestNG are allowed. The allowed static and type import packages
can be configured withallowStaticImportsFromandallowTypeImportsFrom. - The new Java rule
LongLiteralEndingWithLowercaseLfinds long literals ending with a lowercasel.
That helps to avoid confusion between numbers ending with1andl. UppercaseLshould be used to define long literals. - The new Java rule
TypeNameMismatchfinds types that are not defined in a .java file
with the same name. Enforcing a match between source file name and type name makes it easier to
find source code for given type. - The new Java rule
CStyleArrayDeclarationfinds C-style declarations of arrays (e.g.int numbers[]).
That helps you use Java-style declarations (e.g.int[] numbers) consistently throughout the codebase. - The new Java rule
InternalApiUsagereports usages of internal or test-only APIs
(e.g. annotated with@VisibleForTesting,@TestOnly,@API(status=INTERNAL)or@ApiStatus.Internal)
from code that shouldn't depend on them. - The new Apex rule
ApexUnitTestClassShouldHaveRunRelevantTestsAnnotationfinds unit tests
that do not use the new@IsTest(critical=true)or@IsTest(testFor='...')annotation parameters for tests.
These parameters help to identify which tests should be executed during aRunRelevantTestsdeployment.
Note: These annotation parameters are Beta and require Salesforce API 66.0+.
Changed Rules
- The property
checkNonStaticMethodsof the ruleNonThreadSafeSingletonis now
deprecated and no longer has any effect. Its implementation did the opposite of what the documentation described.
The rule now always reports both static and non-static methods; previously it reported only static methods
by default.
This may result in additional violations being reported.
If you want to suppress violations for non-static methods, you can use
suppression via XPath, e.g.<property name="violationSuppressXPath" value=".[ancestor-or-self::MethodDeclaration[1][@Static = false()]]" />
- The property
statementOrderMattersof the ruleVariableCanBeInlinedis now deprecated.
Setting it tofalserelaxes the rule under the unsafe assumption that intervening statements have no side
effects, which can lead to false positives. The property will be removed in PMD 8.0.0.
🐛️ Fixed Issues
- apex-bestpractices
- #6988: [apex] New rule: Detect usage of @IsTest(critical=true) / @IsTest(testFor='...') annotations (RunRelevantTests, Beta, API 66.0+)
- core
- #7013: [core] PMDConfiguration - "Can't mix setClasspath with getAuxClasspath!"
- cli
- #7090: [cli] Add the missing exit code 5 to the CLI help
- html
- #6135: [html] HtmlCpdLexer giving IndexOutOfBoundsException when script contains unescaped closing tag
- java
- #6926: [java] IllegalArgumentException (Mismatched list sizes) with inconsistent unresolved generic arity
- #7056: [java] Provide ability to disable auxClasspath warning added in 7.27.0
- #7081: [java] NoSuchFileException when auxClasspath is given as a classpath file (file: URL) (since 7.27.0)
- #7101: [java] ZipException when auxClasspath contains a non-jar file (since 7.27.0)
- java-bestpractices
- java-codestyle
- java-design
- java-documentation
- #6450: [java] DanglingJavadoc: False positive on /// comments for Java < 23
- java-errorprone
- #1050: [java] NullAssignment: False positive inside if statement for first assignment
- #6693: [java] CloneMethodMustImplementCloneable: False positive with throw-via-local
- #7009: [java] ReplaceJavaUtilDate: False negative when using pattern matching
- #7027: [java] New rule: LongLiteralEndingWithLowercaseL
- #7068: [java] UnusedReturnValue: False positive for calls made on Mockito.verify(mock)
- java-multithreading
- java-security
- kotlin
- #6893: [kotlin] Add XPath functions and type attributes
- miscellaneous
- #6961: [doc] When a rule's description has a link to another rule in the exact wrong position, the do...
PMD 7.27.0 (28-August-2026)
28-August-2026 - 7.27.0
The PMD team is pleased to announce PMD 7.27.0.
This is a minor release.
Table Of Contents
- 🚀️ New and noteworthy
- 🌟️ New and Changed Rules
- 🐛️ Fixed Issues
- 🚨️ API Changes
- ✨️ Merged pull requests
- 📦️ Dependency updates
- 📈️ Stats
🚀️ New and noteworthy
Java 27 Support
This release of PMD brings support for Java 27.
There are no new standard language features.
There is one preview language feature:
In order to analyze a project with PMD that uses these preview language features,
you'll need to select the new language version 27-preview:
pmd check --use-version java-27-preview ...
Note: Support for Java 25 preview language features have been removed. The version "25-preview"
is no longer available.
Updated Apex Support
The Apex language support has been bumped to version 67.0 (Summer '26). It supports the new
Multiline String literals.
Kotlin type-aware analysis
Kotlin now supports type-aware analysis via the auxClasspath language property (see #6677).
Resolved type names, return types, and annotation FQNs are available through
KotlinNodeTypeData for use in Java-based rules.
Note: Type data is not yet accessible in XPath rules or the PMD Rule Designer. This will be added in the next version.
🌟️ New and Changed Rules
New Rules
- The new java rule
UnusedReturnValue(Java Error Prone) finds method calls whose result is not used,
although ignoring the result of these method calls is likely a mistake.
The rule is referenced in the quickstart.xml ruleset for Java. - New rule
ProtectedMemberInFinalClass(Java Design) finds protected members defined in final classes.
Such members should use package or private visibility to clarify their intended scope.
The rule replaces now deprecated rulesAvoidProtectedFieldInFinalClassandAvoidProtectedMethodInFinalClassNotExtending
and flags members that were previously not detected by either of these rules, such as nested types or constructors.
The rule is referenced in the quickstart.xml ruleset for Java.
Renamed Rules
- The rule
InstantiableUtilityClass(Java Design) was renamed fromUseUtilityClassto better reflect the problem.
The old name still works but is deprecated.
Changed Rules
- The rule
CommentRequired(Java Documentation)
has a new propertypackageMethodCommentRequirement. It controls whether Javadoc comments are required (or
unwanted) for package-private methods and constructors. Previously, onlypublicandprotectedmethods could
be configured (viapublicMethodCommentRequirementandprotectedMethodCommentRequirement). The new property
defaults toIgnored, so existing rule configurations are unaffected.
This was implemented in #6880. - The rule
BooleanGetMethodName(Java Codestyle) has a new property
includeWrappedType. If set to true (default), the rule treats Boolean and boolean identical.
If set to false, the rule follows the bean convention and treats Boolean like any other object.
Deprecated Rules
- The java rule
CheckSkipResulthas been deprecated for removal
in favor of the new ruleUnusedReturnValue. - The java rule
UselessPureMethodCallhas been deprecated for removal
in favor of the new ruleUnusedReturnValue.
🐛️ Fixed Issues
- apex
- apex-bestpractices
- #5904: [apex] ApexUnitTestShouldNotUseSeeAllDataTrue violation range should only be the annotation and not the entire test method
- java
- #5041: [java] Parsing failed in ParseLock#doParse(): IndexOutOfBoundsException
- #6010: [java] java.lang.OutOfMemoryError: Java heap space when accessing big Jar files with PMD 7
- #6374: [java] Support Java 27
- #6768: [java] Disambiguation IllegalStateException resolving a synthesized record accessor used as a call argument alongside an anonymous class
- #6932: [java] AssertionError when outer class is parsed before inner class with conflicting visibility
- java-bestpractices
- #1237: [java] AbstractClassWithoutAnyMethod: False positive for empty subclasses that inherit methods
- #1287: [java] GuardLogStatement: False positive when using negative guard conditions
- #2033: [jsp] NoClassAttribute: False positive for jsp:useBean
- #5514: [java] ExhaustiveSwitchHasDefault: False positive for non-exhaustive switch statements
- #5670: [java] ExhaustiveSwitchHasDefault: False positive with final fields not initialized in constructor
- #6200: [java] UnusedAssignment: False positive about the ++ unary operator
- #6393: [java] UnusedPrivateMethod: False positive with overloaded private methods called with values returned from methods of an unresolved type
- #6611: [java] UnnecessaryVarargsArrayCreation: False positive when removing the array creates overload ambiguity
- #6965: [java] AbstractClassWithoutAnyMethod: False Positive on derived abstract class
- java-codestyle
- #2974: [java] Merge rules about protected in final class (AvoidProtectedFieldInFinalClass, AvoidProtectedMethodInFinalClassNotExtending)
- #5441: [java] UseDiamondOperator: False positive with interdependent generic vars
- #6958: [java] BooleanGetMethodName should have the option to treat boolean wrapper type differently
- #6274: [java] UselessParentheses: False positive in ternary else expression
- #6651: [java] UnnecessaryImport: False positive when Javadoc {@link} references an array type
- #6709: [java] LambdaCanBeMethodReference: False positive with array creation containing constructor call in receiver
- #6737: [java] TooManyStaticImports: @SuppressWarnings("PMD.TooManyStaticImports") has stopped working
- #6846: [java] VariableDeclarationUsageDistance: False positive with variables grouped at the top of a block
- #6867: [java] UnnecessaryFullyQualifiedName: ContextedAssertionError: This should be unreachable: unknown constant ScopeInfo: MODULE_IMPORT
- #6943: [java] UnnecessaryCast: False positives related to generics
- java-design
- java-documentation
PMD 7.26.0 (29-June-2026)
29-June-2026 - 7.26.0
The PMD team is pleased to announce PMD 7.26.0.
This is a minor release.
Table Of Contents
- 🚀️ New and noteworthy
- 🌟️ New and Changed Rules
- 🐛️ Fixed Issues
- 🚨️ API Changes
- ✨️ Merged pull requests
- 📦️ Dependency updates
- 📈️ Stats
🚀️ New and noteworthy
Swift Changes
The Swift parser now forwards syntax errors as usual processing errors. Before it just logged any errors and
tried to move on, resulting in an incomplete AST with error nodes. As part of this change, the grammar has been
slightly improved around macro declarations, generic parameters and parameter packs.
This means that PMD might fail now on Swift files with processing errors, when it previously ran without
obvious problems. The Swift module in PMD now behaves like other modules in regard to error handling.
Updated PMD Designer
This PMD release ships a new version of the pmd-designer.
For the changes, see PMD Designer Changelog (7.19.3).
🌟️ New and Changed Rules
New Rules
- The new Java rule
WrongTestAnnotationdetects when test annotations from the wrong
testing framework (JUnit 4, JUnit Jupiter, or TestNG) are used in your code, preventing tests from being silently
skipped due to framework mismatches. This helps avoid the silent failure where tests compile but don't execute
because the test runner doesn't recognize the annotation. - The new Java rule
AssertEqualsArgumentOrderdetects assertions
where the expected and actual arguments were swapped. This helps find assertions
that are producing a confusing error message when they fail. - The new Kotlin rule
LocalVariableShadowsParameterdetects local variable
declarations that use the same name as a parameter of the enclosing function. This shadows the parameter
and may lead to confusion about which value is used. - The new Apex rule
InvocableClassNoArgConstructordetects classes that use
@InvocableVariableproperties, but that don't provide a no-arg constructor. Without such a constructor,
runtime exception occur when Salesforce Flow tries to instantiate such classes.
Deprecated Rules
- The rule
UseObjectForClearerAPIwas deprecated. UseExcessiveParameterList
instead. The old rule name still works.
🐛️ Fixed Issues
- apex
- #6806: [apex] ANTLR runtime mismatch 4.9.1 used for code generation does not match the current runtime version 4.13.2
- apex-errorprone
- #6793: [apex] New Rule: Invocable Classes require a no argument constructor
- apex-security
- core
- #6764: [core] ANTLR: Report syntax errors as processing errors
- cpp
- #6641: [cpp]: IndexOutOfBoundsException in CPD when a duplication is at end of file with UTF8-BOM
- cli
- #6741: [cli] Designer: Fix quotes in PMD_OPENJFX_MODULE_PATH setting
- java
- #6812: [java] Rename ASTMethodDeclaration#isOverridden() to isOverride()
- java-bestpractices
- #6627: [java] UnusedPrivateMethod: could not handle javax.annotation
- #6692: [java] ForLoopCanBeForeach: inconsistent detection between i += 1 and i = i + 1 update forms
- #6736: [java] JUnitJupiterTestShouldBePackagePrivate: False negative when the only tests are in a @Nested class
- #6782: [java] UseStandardCharsets: ArrayIndexOutOfBoundsException in line 81
- java-codestyle
- java-design
- java-errorprone
- #2846: [java] New Rule: WrongTestAnnotation
- #5011: [java] TestClassWithoutTestCases: False positive for test classes extending a class with tests (in nested classes)
- #6743: [java] CloseResource: False positive for closeable initialized with (T) null
- #6781: [java] UselessPureMethodCall: False positive for Stream.forEach
- java-performance
- #6740: [java] OptimizableToArrayCall: False positive when new T[0x0] is used instead of new T[0]
- kotlin
- #6677: [kotlin] Add auxClasspath language property
- kotlin-bestpractices
- #6732: [kotlin] New Rule: LocalVariableShadowsParameter
- swift
- #6801: [swift] Report syntax errors as processing errors
🚨️ API Changes
- core
AntlrBaseParserhas been deprecated in favor of
AntlrBaseParserWithErrorHandling, which converts ANTLR's parsing
errors into PMD's processing errors by default.
- java
ASTMethodDeclaration#isOverriddenhas been renamed toisOverride.
The old name has been deprecated and will remain available until PMD 8.
The corresponding XPath attribute@Overriddenis deprecated as well. Use@Overrideinstead.
✨️ Merged pull requests
- #6678: [kotlin] Fix #6677: Add auxClasspath language property - Peter Paul Bakker (@stokpop)
- #6703: [cpp] Fix #6641: CPD: IndexOutOfBoundsException when a duplication is at end of file with UTF8-BOM - Lukas Gräf (@lukasgraef)
- #6713: [java] New rule: AssertEqualsArgumentOrder - Zbynek Konecny (@zbynek)
- #6727: [java] Fix #6692: ForLoopCanBeForeach detect i = i + 1 update form - hyeonjune (@qwerty7878)
- #6728: chore: Fix pmd test setup - Andreas Dangel (@adangel)
- #6730: [core] RuleSetWriter: fix indent-number attribute - Andreas Dangel (@adangel)
- #6733: [kotlin] Fix #6732: Add LocalVariableShadowsParameter rule - Peter Paul Bakker (@stokpop)
- #6735: [java] Fix #2846: New Rule: WrongTestAnnotation - Sören Glimm (@UncleOwen)
- #6738: [java] Fix #6736: Add JTypeMirror.streamClasses() - Sören Glimm (@UncleOwen)
- #6741: [cli] Designer: Fix quotes in PMD_OPENJFX_MODULE_PATH setting - Philip Graf (@acanda)
- #6745: [java] Fix #6239: UseDiamondOperator: Implement heuristic for Super Type Token Pattern - Sören Glimm (@UncleOwen)
- #6748: [java] Fix #6743: CloseResource: False positive for closeable initialized with (T) null - Lukas Gräf (@lukasgraef)
- [#6761](https://github.com/pmd/pmd/p...
PMD 7.25.0 (29-May-2026)
29-May-2026 - 7.25.0
The PMD team is pleased to announce PMD 7.25.0.
This is a minor release.
Table Of Contents
- 🚀️ New and noteworthy
- 🌟️ New and Changed Rules
- 🐛️ Fixed Issues
- 🚨️ API Changes
- ✨️ Merged pull requests
- 📦️ Dependency updates
- 📈️ Stats
🚀️ New and noteworthy
Updated ANTLR library to 4.13.2
We have updated the ANTLR library (parser generator) from 4.9.3 to the latest version 4.13.2,
in order to be able to use the latest version of Apex parser library.
This is an incompatible update: In case you use custom language modules based on ANTLR, you
need to make sure to regenerate all of your lexers and parsers with the new ANTLR version.
For the ANTLR based language modules, that PMD ships (kotlin and swift and various CPD modules),
this is already done.
🌟️ New and Changed Rules
New Rules
- The new Java rule
JUnitJupiterTestNoPrivateModifierfind JUnit test classes and
methods that are private. Test classes, test methods, and lifecycle methods are not required to be public,
but they must not be private. Otherwise, they won’t be found by the test framework. - The new Java rule
UnnecessaryBlockreports blocks that are unnecessary as
they don't introduce a new scope. This rule helps simplify code structure by identifying and flagging
redundant blocks that can make code harder to read and may be misleading. - The new Java rule
VariableDeclarationUsageDistanceflags local variables that are declared
far from their usage, which can make code harder to read. The rule has a propertymaxDistancethat allows to
configure the maximum allowed distance between declaration and usage. - The new Java rule
AssertStatementInTestdetects usages ofassertstatement in tests.
These should be replaced by framework assertion methods such asassertEquals.
Such methods provide better error messages and make test behave correctly when running without-ea.
Changed Rules
- The rule
OnlyOneReturnhas a new propertyallowGuardIfs. When this property is
true, then guard ifs at the beginning of a method are allowed their return statements don't count. - The rules
UseUtilityClassandClassNamingConventionsnow use the
same definition of what a utility class is. The most significant change is, that classes withmain()methods are
no longer considered utility classes byUseUtilityClass. - We are continuously working to improve the precision of violation reporting for various rules.
The goal is to ensure that rules report issues on the correct line and highlight only the relevant lines.
For example, instead of flagging an entire class declaration (including its body), we now generally report only
the class name. For more details, see [java] Single Line Warnings #730
and [java] Review reported locations of rules #3769. While this effort
is still ongoing, the following Java rules have been updated in this release:AbstractClassWithoutAbstractMethodAbstractClassWithoutAnyMethodAtLeastOneConstructorAvoidDollarSignsAvoidCatchingGenericExceptionAvoidSynchronizedStatement(now reports only on synchronized keyword and not the whole synchronized block)ClassNamingConventionsClassWithOnlyPrivateConstructorsShouldBeFinalCommentDefaultAccessModifierCommentRequiredCouplingBetweenObjects(now reports only on class identifier and not whole compilation unit anymore)CyclomaticComplexityDataClassExcessiveImports(now reports only on imports and not the whole compilation unit anymore)ExcessiveParameterListExcessivePublicCountExhaustiveSwitchHasDefault(now reports only on switch keyword and not the whole switch block)GodClassImplicitFunctionalInterfaceJUnit5TestShouldBePackagePrivateLocalHomeNamingConventionLocalInterfaceSessionNamingConventionMissingSerialVersionUIDMissingStaticMethodInNonInstantiatableClassNcssCountNonExhaustiveSwitch(now reports only on switch keyword and not the whole switch block)NoPackagePublicMemberInNonPublicTypeShortClassNameSingleMethodSingletonSwitchDensity(now reports only on switch keyword and not the whole switch block)TestClassWithoutTestCasesTooFewBranchesForSwitch(now reports only on switch keyword and not the whole switch block)TooManyFields(now reports only on class identifier and not the whole class body anymore)TooManyMethods(now reports only on class identifier and not the whole class body anymore)TooManyStaticImports(now reports only on the first static import and not the whole compilation unit anymore)UnnecessaryModifierUseUtilityClass
Renamed rules and properties
- One rule and one property have been renamed to reflect the fact that they work for both JUnit 5 and 6:
- The rule
JUnitJupiterTestShouldBePackagePrivate(Java Best Practices) was re...
- The rule
PMD 7.24.0 (24-April-2026)
24-April-2026 - 7.24.0
The PMD team is pleased to announce PMD 7.24.0.
This is a minor release.
Table Of Contents
🌟️ New Rules
- The new Apex rule
AvoidInterfaceAsMapKeyreportsMapdeclarations
(fields, variables, parameters) whose key type is an interface that has at least one abstract implementing
class definingequalsorhashCode. Using such maps results in potentially duplicated map entries or
not being able to get entries by key. - The new Java rule
OverridingThreadRunfinds overriddenThread::runmethods.
This is not recommended. Instead, implementRunnableand pass an instance to the thread constructor.
🐛️ Fixed Issues
- apex
- #5386: [apex] Apex files ending in "Test" are skipped with a number of rules
- apex-errorprone
- #6492: [apex] New rule: Prevent use of interface -> abstract class with equals/hashCode as key in Map
- apex-security
- #5385: [apex] ApexCRUDViolation not reported even if SOQL doesn't have permissions check on it
- java-bestpractices
- #4272: [java] JUnitTestsShouldIncludeAssert: False positive with assert in lambda
- java-multithreading
- #595: [java] New rule: Implement Runnable instead of extending Thread
- kotlin
- #6003: [kotlin] Support multidollar interpolation (Kotlin 2.2)
✨️ Merged pull requests
- #6493: [apex] New Rule: AvoidInterfaceAsMapKeyRule - Jonny Alexander Power (@JonnyPower)
- #6497: [kotlin] Fix kotlin grammar for parsing multidollar interpolation - Peter Paul Bakker (@stokpop)
- #6555: [java] New rule: OverridingThreadRun to prefer using Runnable - Zbynek Konecny (@zbynek)
- #6556: [java] Fix #4272: False positive in UnitTestShouldIncludeAssert when using assertion in lambda - Lukas Gräf (@lukasgraef)
- #6563: [apex] Remove class name suffix "Test" as indicator of test classes - David Schach (@dschach)
- #6576: [test] chore: Throw a TestAbortedException on disabled tests - UncleOwen (@UncleOwen)
- #6577: [dist] chore: Improve error message for missing JAVA_HOME in AntIT.java - UncleOwen (@UncleOwen)
- #6607: [doc] basic.xml has been gone for a long time - UncleOwen (@UncleOwen)
📦️ Dependency updates
- #6515: chore: bump pmd-regression-tester from 1.6.2 to 1.7.0
- #6552: Bump PMD from 7.22.0 to 7.23.0
- #6564: chore(deps): bump ruby/setup-ruby from 1.295.0 to 1.299.0
- #6565: chore(deps-dev): bump net.bytebuddy:byte-buddy from 1.18.7 to 1.18.8
- #6566: chore(deps): bump com.puppycrawl.tools:checkstyle from 13.3.0 to 13.4.0
- #6567: chore(deps-dev): bump log4j.version from 2.25.3 to 2.25.4
- #6569: chore(deps-dev): bump net.bytebuddy:byte-buddy-agent from 1.18.7 to 1.18.8
- #6570: chore(deps): bump org.apache.groovy:groovy from 5.0.4 to 5.0.5
- #6571: chore(deps-dev): bump io.github.git-commit-id:git-commit-id-maven-plugin from 9.0.2 to 9.1.0
- #6572: chore(deps): bump bigdecimal from 4.0.1 to 4.1.0 in /docs
- #6578: chore(deps): bump marocchino/sticky-pull-request-comment from 3.0.2 to 3.0.3
- #6579: chore(deps): bump crate-ci/typos from 1.44.0 to 1.45.0
- #6580: chore(deps): bump ruby/setup-ruby from 1.299.0 to 1.300.0
- #6581: chore(deps-dev): bump io.github.git-commit-id:git-commit-id-maven-plugin from 9.1.0 to 10.0.0
- #6582: chore(deps): bump org.checkerframework:checker-qual from 3.54.0 to 4.0.0
- #6583: chore(deps-dev): bump ant.version from 1.10.15 to 1.10.16
- #6584: chore(deps): bump bigdecimal from 4.1.0 to 4.1.1 in /docs
- #6588: chore(deps): bump actions/cache from 5.0.4 to 5.0.5
- #6589: chore(deps): bump marocchino/sticky-pull-request-comment from 3.0.3 to 3.0.4
- #6590: chore(deps): bump crate-ci/typos from 1.45.0 to 1.45.1
- #6591: chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1
- #6592: chore(deps): bump actions/create-github-app-token from 3.0.0 to 3.1.1
- #6593: chore(deps): bump scalameta.version from 4.15.2 to 4.16.0
- #6594: chore(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.4 to 0.25.5
- #6595: chore(deps-dev): bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre
- #6596: chore(deps-dev): bump ant.version from 1.10.16 to 1.10.17
- #6599: chore(deps-dev): Bump lodash from 4.17.23 to 4.18.1
- #6600: chore(deps-dev): Bump addressable from 2.8.9 to 2.9.0
- #6613: chore(deps): bump ruby/setup-ruby from 1.300.0 to 1.305.0
- #6614: chore(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.5 to 0.25.6
- #6615: chore(deps): bump scalameta.version from 4.16.0 to 4.16.1
- #6616: chore(deps-dev): bump org.sonarsource.scanner.maven:sonar-maven-plugin from 5.5.0.6356 to 5.6.0.6792
- #6617: chore(deps): bump org.jsoup:jsoup from 1.22.1 to 1.22.2
- #6618: chore(deps): bump bigdecimal from 4.1.1 to 4.1.2 in /docs
📈️ Stats
- 82 commits
- 14 closed tickets & PRs
- Days since last release: 27
PMD 7.23.0 (27-March-2026)
27-March-2026 - 7.23.0
The PMD team is pleased to announce PMD 7.23.0.
This is a minor release.
Table Of Contents
🐛️ Fixed Issues
- core
- #6503: [core] Links in HTML report are broken
- java-errorprone
- #6502: [java] CloseResource: False positive for allowedResourceMethodPatterns entries when using unqualified method calls
- java-security
- #6531: [java] InsecureCryptoIv: False negative with fixed IVs from array initializers
✨️ Merged pull requests
- #6467: [ci] Use typos gh-action - Andreas Dangel (@adangel)
- #6488: [doc] Update security.md for CVE-2026-28338 - Andreas Dangel (@adangel)
- #6489: [doc] CPD: document --report-file parameter - Andreas Dangel (@adangel)
- #6504: [core] Fix #6503: Don't escape externalInfoUrl in reports - Andreas Dangel (@adangel)
- #6505: [java] Fix #6502: CloseResource should consider unqualified method calls - Andreas Dangel (@adangel)
- #6545: [java] Fix #6531: False negative in InsecureCryptoIv with array initializers - Zbynek Konecny (@zbynek)
📦️ Dependency updates
- #6476: Bump PMD from 7.21.0 to 7.22.0
- #6479: chore(deps): bump actions/download-artifact from 7.0.0 to 8.0.0
- #6480: chore(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0
- #6481: chore(deps): bump com.puppycrawl.tools:checkstyle from 13.2.0 to 13.3.0
- #6482: chore(deps): bump org.mockito:mockito-core from 5.21.0 to 5.22.0
- #6483: chore(deps-dev): bump net.bytebuddy:byte-buddy from 1.18.5 to 1.18.7
- #6484: chore(deps): bump org.yaml:snakeyaml from 2.5 to 2.6
- #6485: chore(deps): bump org.checkerframework:checker-qual from 3.53.1 to 3.54.0
- #6486: chore(deps-dev): bump net.bytebuddy:byte-buddy-agent from 1.18.5 to 1.18.7
- #6487: chore(deps): bump com.google.protobuf:protobuf-java from 4.33.5 to 4.34.0
- #6490: chore: Update gems, remove github-pages
- #6498: chore(deps): bump ruby/setup-ruby from 1.288.0 to 1.290.0
- #6499: chore(deps-dev): bump commons-logging:commons-logging from 1.3.5 to 1.3.6
- #6500: chore(deps-dev): bump org.apache.maven.plugins:maven-shade-plugin from 3.6.1 to 3.6.2
- #6501: chore(deps): bump org.apache.maven.plugins:maven-resources-plugin from 3.4.0 to 3.5.0
- #6506: chore(deps): bump actions/create-github-app-token from 2.2.1 to 3.0.0
- #6507: chore(deps): bump actions/download-artifact from 8.0.0 to 8.0.1
- #6508: chore(deps): bump marocchino/sticky-pull-request-comment from 2.9.4 to 3.0.2
- #6509: chore(deps): bump ruby/setup-ruby from 1.290.0 to 1.295.0
- #6511: chore(deps): bump org.mockito:mockito-core from 5.22.0 to 5.23.0
- #6514: chore: bump maven from 3.9.12 to 3.9.14
- #6516: chore: bump json from 2.19.0 to 2.19.2
- #6548: chore(deps): bump actions/cache from 5.0.3 to 5.0.4
- #6549: chore(deps): bump com.google.protobuf:protobuf-java from 4.34.0 to 4.34.1
- #6551: chore: use ruby4
📈️ Stats
- 38 commits
- 9 closed tickets & PRs
- Days since last release: 27
PMD 7.22.0 (27-February-2026)
27-February-2026 - 7.22.0
The PMD team is pleased to announce PMD 7.22.0.
This is a minor release.
Table Of Contents
- 🚀️ New and noteworthy
- 🌟️ New and Changed Rules
- 🐛️ Fixed Issues
- 🚨️ API Changes
- ✨️ Merged pull requests
- 📦️ Dependency updates
- 📈️ Stats
🚀️ New and noteworthy
Security fixes
- This release fixes a stored XSS vulnerability in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages.
Affects CI/CD pipelines that run PMD with--format vbhtmlor--format yahtmlon untrusted source code
(e.g. pull requests from external contributors) and expose the HTML report as a build artifact.
JavaScript executes in the browser context of anyone who opens the report.
Note: The defaulthtmlformat is not affected by unescaped violation messages, but a similar problem
existed with suppressed violation markers.
If you use these reports, it is recommended to upgrade PMD.
Reported by Smaran Chand (@smaranchand).
🌟️ New and Changed Rules
New Rules
- The new Java rule
UnnecessaryInterfaceDeclarationdetects classes that
implement interfaces that are already implemented by its superclass, and interfaces
that extend other interfaces already declared by their superinterfaces.
These declarations are redundant and can be removed to simplify the code.
Changed Rules
- The rule
CloseResourceintroduces a new property,allowedResourceMethodPatterns,
which lets you specify method invocation patterns whose return values are resources managed externally.
This is useful for ignoring managed resources - for example,Reader/Writerinstances obtained from
HttpServletRequest/HttpServletResponse- because the servlet container, not application code,
is responsible for closing them. By default, the rule ignoresInputStream/OutputStream/Reader/Writer
resources returned by methods on(Http)ServletRequestand(Http)ServletResponse
(bothjavax.servletandjakarta.servlet).
🐛️ Fixed Issues
- core
- doc
- #6396: [doc] Mention test-pmd-tool as alternative for testing
- java-bestpractices
- #6431: [java] UnitTestShouldIncludeAssert: False positive with SoftAssertionsExtension on parent/grandparent classes
- java-codestyle
- #6458: [java] New Rule: UnnecessaryInterfaceDeclaration
- java-errorprone
🚨️ API Changes
Deprecations
- core
CodeClimateIssue: This class is an implementation detail of
CodeClimateRenderer. It will be internalized in a future release.
- visualforce
DataType. The enum constants have been renamed to follow Java naming
conventions. The old enum constants are deprecated and should no longer be used.
The methodDataType#fromStringwill return the new
enum constants.
UseDataType#fieldTypeNameOfto get the original field type name.
✨️ Merged pull requests
- #6396: [doc] Mention test-pmd-tool as alternative for testing - Beech Horn (@metalshark)
- #6397: [java] Add support for Lombok-generated getters in symbol resolution - Anurag Agarwal (@altaiezior)
- #6420: [ci] build: Add typos as spell checker - Andreas Dangel (@adangel)
- #6432: [java] UnitTestShouldIncludeAssert: False positive with SoftAssertionsExtension on parent/grandparent classes - Artur Kalimullin (@kaliy)
- #6434: [java] chore(style): Fix lambda argument indentation for checkstyle compliance - Kai (@aclfe)
- #6437: [java] CloseResource: Allow to ignore managed resources - Gildas Cuisinier (@gcuisinier)
- #6445: chore: Fix FieldNamingConventions - Andreas Dangel (@adangel)
- #6446: [doc] Add new IntelliJ Plugin "PMD X" - Andreas Dangel (@adangel)
- #6447: chore: Small release process fixes - Andreas Dangel (@adangel)
- #6458: [java] New Rule: UnnecessaryInterfaceDeclaration - Zbynek Konecny (@zbynek)
- #6472: [core] Fix BaseAntlrTerminalNode getTokenKind to return type instead of index - Peter Paul Bakker (@stokpop)
- #6475: [core] Fix stored XSS in VBHTMLRenderer and YAHTMLRenderer - Andreas Dangel (@adangel)
📦️ Dependency updates
- #6433: Bump PMD from 7.20.0 to 7.21.0
- #6438: chore(deps): bump actions/cache from 5.0.2 to 5.0.3
- #6439: chore(deps): bump ruby/setup-ruby from 1.286.0 to 1.288.0
- #6440: chore(deps): bump scalameta.version from 4.14.6 to 4.14.7
- #6441: chore(deps): bump org.apache.maven.plugins:maven-compiler-plugin from 3.14.1 to 3.15.0
- #6442: chore(deps): bump org.checkerframework:checker-qual from 3.53.0 to 3.53.1
- #6443: chore(deps): bump com.puppycrawl.tools:checkstyle from 13.0.0 to 13.1.0
- #6444: chore(deps): bump com.google.protobuf:protobuf-java from 4.33.4 to 4.33.5
- #6452: chore(deps): bump actions/checkout from 6.0.1 to 6.0.2
- #6455: chore(deps): bump org.apache.maven.plugins:maven-dependency-plugin from 3.9.0 to 3.10.0
- #6456: chore(deps): bump com.puppycrawl.tools:checkstyle from 13.1.0 to 13.2.0
- #6462: chore(deps): bump junit.version from 6.0.2 to 6.0.3
- #6463: chore(deps): bump scalameta.version from 4.14.7 to 4.15.2
- #6465: chore(deps-dev): bump net.bytebuddy:byte-buddy-agent from 1.18.4 to 1.18.5
- #6468: chore(deps-dev): bump net.bytebuddy:byte-buddy from 1.18.4 to 1.18.5
- #6469: chore(deps): bump surefire.version from 3.5.4 to 3.5.5
- #6470: chore(deps): bump org.jetbrains:annotations from 26.0.2-1 to 26.1.0
- #6473: chore(deps): bump nokogiri to 1.19.1
- #6474: chore(deps): bump faraday from 2.13.3 to 2.14.1
📈️ Stats
- 66 commits
- 16 closed tickets & PRs
- Days since last release: 28
PMD 7.21.0 (30-January-2026)
30-January-2026 - 7.21.0
The PMD team is pleased to announce PMD 7.21.0.
This is a minor release.
Table Of Contents
- 🚀️ New and noteworthy
- 🌟️ New and Changed Rules
- 🐛️ Fixed Issues
- 🚨️ API Changes
- ✨️ Merged pull requests
- 📦️ Dependency updates
- 📈️ Stats
🚀️ New and noteworthy
🚀️ New: Java 26 Support
This release of PMD brings support for Java 26.
There are no new standard language features.
There is one preview language feature:
In order to analyze a project with PMD that uses these preview language features,
you'll need to select the new language version 26-preview:
pmd check --use-version java-26-preview ...
Note: Support for Java 24 preview language features have been removed. The version "24-preview"
is no longer available.
Build Requirement is Java 21
From now on, Java 21 or newer is required to build PMD. PMD itself still remains compatible with Java 8,
so that it still can be used in a pure Java 8 environment. This allows us to use the latest
checkstyle version during the build.
CPD
- The Apex module now supports suppression through
CPD-ON/CPD-OFFcomment pairs. See #6417
🌟️ New and Changed Rules
New Rules
- The new Java rule
PublicMemberInNonPublicTypedetects public members (such as methods
or fields) within non-public types. Non-public types should not declare public members, as their effective
visibility is limited, and using thepublicmodifier can create confusion. - The new Java rule
UnsupportedJdkApiUsageflags the use of unsupported and non-portable
JDK APIs, includingsun.*packages,sun.misc.Unsafe, andjdk.internal.misc.Unsafe. These APIs are unstable,
intended for internal use, and may change or be removed. The rule complements Java compiler warnings by
highlighting such usage during code reviews and encouraging migration to official APIs like VarHandle and
the Foreign Function & Memory API.
Changed Rules
The following rules have been changed to use a consistent implementation of enum based
rule properties:
- The property
checkAddressTypesof ruleAvoidUsingHardCodedIPhas changed:- Instead of
IPv4useipv4 - Instead of
IPv6useipv6 - Instead of
IPv4 mapped IPv6useipv4MappedIpv6 - The old values still work, but you'll see a deprecation warning.
- Instead of
- The property
nullCheckBranchof ruleConfusingTernaryhas changed:- Instead of
Anyuseany - Instead of
Thenusethen - Instead of
Elseuseelse - The old values still work, but you'll see a deprecation warning.
- Instead of
- The property
typeAnnotationsof ruleModifierOrderhas changed:- Instead of
ontypeuseonType - Instead of
ondecluseonDecl - The old values still work, but you'll see a deprecation warning.
- Instead of
- The values of the properties of rule
CommentRequiredhave changed:- Instead of
Requireduserequired - Instead of
Ignoreduseignored - Instead of
Unwanteduseunwanted - The old values still work, but you'll see a deprecation warning.
- Instead of
Deprecated Rules
- The Java rule
DontImportSunhas been deprecated. It is replaced by
UnsupportedJdkApiUsage.
🐛️ Fixed Issues
- core
- #6184: [core] Consistent implementation of enum properties
- apex
- #6417: [apex] Support CPD suppression with "CPD-OFF" & "CPD-ON"
- apex-codestyle
- #6349: [apex] FieldDeclarationsShouldBeAtStart: False positive with properties
- cli
- #6290: [cli] Improve Designer start script
- java
- java-design
- #6231: [java] New Rule: PublicMemberInNonPublicType
- java-errorprone
- java-performance
- #3857: [java] InsufficientStringBufferDeclaration: False negatives with String constants
🚨️ API Changes
Deprecations
- core
MetricOption#valueName: When metrics are used for (rule) properties,
then the conventional enum mapping (from SCREAMING_SNAKE_CASE to camelCase) will be used for the enum values.
SeeconventionalEnumListProperty.- In
PropertyFactory:enumProperty(String, Map). Use
conventionalEnumPropertyinstead.enumProperty(String, Class). Use
conventionalEnumPropertyinstead.enumProperty(String, Class, Function). Use
conventionalEnumPropertyinstead.enumListProperty(String, Map). Use
conventionalEnumListPropertyinstead.enumListProperty(String, Class, Function). Use
conventionalEnumListPropertyinstead.
- java
AvoidBranchingStatementAsLastInLoopRule#CHECK_FOR. This constant should
have never been public.AvoidBranchingStatementAsLastInLoopRule#CHECK_DO. This constant should
have never been public.AvoidBranchingStatementAsLastInLoopRule#CHECK_WHILE. This constant should
have never been public.- <a href="https://docs.pmd-code.org/apidocs/pmd-java/7.21.0/net/sourceforge/pmd/lang/java/rule...
PMD 7.20.0 (30-December-2025)
30-December-2025 - 7.20.0
The PMD team is pleased to announce PMD 7.20.0.
This is a minor release.
Table Of Contents
- 🌟️ Changed Rules
- 🐛️ Fixed Issues
- 🚨️ API Changes
- ✨️ Merged pull requests
- 📦️ Dependency updates
- 📈️ Stats
🌟️ Changed Rules
- The Java rule
OnlyOneReturnhas a new propertyignoredMethodNames. This property by
default is set tocompareToandequals, thus this rule now by default allows multiple return statements
for these methods. To restore the old behavior, simply set this property to an empty value.
🐛️ Fixed Issues
- core
- #6330: [core] "Unable to create ValueRepresentation" when using @LiteralText (XPath)
- java
- java-bestpractices
- #4282: [java] GuardLogStatement: False positive when guard is not a direct parent
- #6028: [java] UnusedPrivateMethod: False positive with raw type for generic method
- #6257: [java] UnusedLocalVariable: False positive with instanceof pattern guard
- #6291: [java] EnumComparison: False positive for any object when object.equals(null)
- #6328: [java] UnusedLocalVariable: False positive for pattern variable in for-each without braces
- java-codestyle
- #4257: [java] OnlyOneReturn: False positive with equals method
- #5043: [java] LambdaCanBeMethodReference: False positive on overloaded methods
- #6237: [java] UnnecessaryCast: ContextedRuntimeException when parsing switch expression with lambdas
- #6279: [java] EmptyMethodInAbstractClassShouldBeAbstract: False positive for final empty methods
- #6284: [java] UnnecessaryConstructor: False positive for JavaDoc-bearing constructor
- java-errorprone
- java-performance
- maintenance
- #6230: [core] Single module snapshot build fails
🚨️ API Changes
Experimental API
✨️ Merged pull requests
- #6262: [java] UnusedLocalVariable: fix false positive with guard in switch - Zbynek Konecny (@zbynek)
- #6285: [java] Fix #5043: FP in LambdaCanBeMethodReference when method ref would be ambiguous - Clément Fournier (@oowekyala)
- #6287: [doc] Explain how to build or pull snapshot dependencies for single module builds - Marcel (@mrclmh)
- #6288: [java] Fix #6279: EmptyMethodInAbstractClassShouldBeAbstract should ignore final methods - Marcel (@mrclmh)
- #6292: [java] Fix #6291: EnumComparison FP when comparing with null - Clément Fournier (@oowekyala)
- #6293: [java] Fix #6276: NullAssignment should not report assigning null to a final field in a constructor - Lukas Gräf (@lukasgraef)
- #6294: [java] Fix #6028: UnusedPrivateMethod FP - Clément Fournier (@oowekyala)
- #6295: [java] Fix #6237: UnnecessaryCast error with switch expr returning lambdas - Clément Fournier (@oowekyala)
- #6296: [java] Fix #4282: GuardLogStatement only detects guard methods immediately around it - Marcel (@mrclmh)
- #6299: [java] Fix grammar of switch label - Clément Fournier (@oowekyala)
- #6309: [java] Fix #4257: Allow ignoring methods in OnlyOneReturn - Marcel (@mrclmh)
- #6311: [java] Fix #6284: UnnecessaryConstructor reporting false-positive on JavaDoc-bearing constructor - Marcel (@mrclmh)
- #6313: [java] Fix #4910: if-statement triggers ConsecutiveAppendsShouldReuse - Marcel (@mrclmh)
- #6316: [java] Fix #5877: AvoidArrayLoops false-negative when break inside switch statement - Marcel (@mrclmh)
- #6342: [core] Fix #6330: Cannot access Chars attribute from XPath - Clément Fournier (@oowekyala)
- #6344: [java] Fix #6328: UnusedLocalVariable should consider pattern variable in for-each without curly braces - Mohamed Hamed (@mdhamed238)
- #6348: [jsp] Fix malformed Javadoc HTML in JspDocStyleTest - Gianmarco (@gianmarcoschifone)
- #6359: [java] Fix #6234: Parser fails to parse switch expressions in super() constructor calls - Mohamed Hamed (@mdhamed238)
- #6360: [java] Fix #4158: BigIntegerInstantiation false-negative with compile-time constant - Lukas Gräf (@lukasgraef)
- #6361: [vf] Fix invalid Javadoc syntax in VfDocStyleTest - Gianmarco (@gianmarcoschifone)
- #6363: [apex] Add sca-extra ruleset for Salesforce Apex testing - Beech Horn (@metalshark)
📦️ Dependency updates
- #6286: Bump PMD from 7.18.0 to 7.19.0
- #6300: chore(deps): bump actions/checkout from 6.0.0 to 6.0.1
- #6301: chore(deps): bump org.checkerframework:checker-qual from 3.52.0 to 3.52.1
- #6302: chore(deps): bump org.apache.maven.plugins:maven-resources-plugin from 3.3.1 to 3.4.0
- #6303: chore(deps-dev): bump net.bytebuddy:byte-buddy from 1.18.1 to 1.18.2
- #6304: chore(deps): bump com.puppycrawl.tools:checkstyle from 12.1.2 to 12.2.0
- #6305: chore(deps): bump org.sonarsource.scanner.maven:sonar-maven-plugin from 5.3.0.6276 to 5.4.0.6343
- #6306: chore(deps): bump webrick from 1.9.1 to 1.9.2 in /docs
- #6318: chore(deps): bump actions/create-github-app-token from 2.2.0 to 2.2.1
- #6319: chore(deps): bump actions/setup-java from 5.0.0 to 5.1.0
- #6320: chore(deps): bump ruby/setup-ruby from 1.268.0 to 1.269.0
- #6321: chore(deps-dev): bump net.bytebuddy:byte-buddy-agent from 1.18.1 to 1.18.2
- #6323: chore(deps): bump com.google.protobuf:protobuf-java from 4.33.1 to 4.33.2
- #6324: chore(deps): bump io.github.apex-dev-tools:apex-ls_2.13 from 6.0.1 to 6.0.2
- #6325: chore(deps): bump org.apache.maven.plugins:maven-assembly-plugin from 3.7.1 to 3.8.0
- #6329: chore(deps): bump org.mozilla:rhino from 1.7.15 to 1.7.15.1
- #6331: chore(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0
- #6332: chore(deps): bump org.mockito:mockito-core from 5.20.0 to 5.21.0
- #6333: chore(deps): bump actions/download-artifact from 6.0.0 to 7.0.0
- #6334: chore(deps): bump ruby/setup-ruby ...