Springboot Verification

affaan-m/ECC/docs/ja-JP/skills/springboot-verification

by affaan-mef648e01899ba3e8dc6371642deaaf64b4477775No license275K starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 4 days ago

Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.

AI-generated overview

Runs a Spring Boot verification loop: build, static analysis, tests with coverage, security scans, and diff review.

What it does
Guides an agent through a six-phase verification sequence for Spring Boot projects: build, static analysis, tests with coverage, security scanning, optional lint/format, and diff review. It supplies Maven and Gradle commands for each phase plus a checklist for reviewing changes. It produces a structured verification report template summarizing pass/fail status, test counts, coverage, CVEs, and changed files.
When to use it
Use before opening a pull request, after large changes, or before deploying a Spring Boot application. It also fits periodic re-runs during long sessions or when quick feedback is needed.
Requirements
A Spring Boot project with Maven or Gradle, plus the relevant plugins (SpotBugs, PMD, Checkstyle, JaCoCo, OWASP dependency-check, Spotless) and git for diff review. No scripts ship with the skill; it is instructions only.

Spring Boot 検証ループ

PR前、大きな変更後、デプロイ前に実行します。

フェーズ1: ビルド

bash
mvn -T 4 clean verify -DskipTests# または./gradlew clean assemble -x test

ビルドが失敗した場合は、停止して修正します。

フェーズ2: 静的解析

Maven(一般的なプラグイン):

bash
mvn -T 4 spotbugs:check pmd:check checkstyle:check

Gradle(設定されている場合):

bash
./gradlew checkstyleMain pmdMain spotbugsMain

フェーズ3: テスト + カバレッジ

bash
mvn -T 4 testmvn jacoco:report   # 80%以上のカバレッジを確認# または./gradlew test jacocoTestReport

レポート:

  • 総テスト数、合格/失敗
  • カバレッジ%(行/分岐)

フェーズ4: セキュリティスキャン

bash
# 依存関係のCVEmvn org.owasp:dependency-check-maven:check# または./gradlew dependencyCheckAnalyze
# シークレット(git)git secrets --scan  # 設定されている場合

フェーズ5: Lint/Format(オプションゲート)

bash
mvn spotless:apply   # Spotlessプラグインを使用している場合./gradlew spotlessApply

フェーズ6: 差分レビュー

bash
git diff --statgit diff

チェックリスト:

  • デバッグログが残っていない(System.out、ガードなしの log.debug)
  • 意味のあるエラーとHTTPステータス
  • 必要な場所にトランザクションと検証がある
  • 設定変更が文書化されている

出力テンプレート

検証レポート===================ビルド:     [合格/不合格]静的解析:   [合格/不合格] (spotbugs/pmd/checkstyle)テスト:     [合格/不合格] (X/Y 合格, Z% カバレッジ)セキュリティ: [合格/不合格] (CVE発見: N)差分:       [X ファイル変更]
全体:       [準備完了 / 未完了]
修正が必要な問題:1. ...2. ...

継続モード

  • 大きな変更があった場合、または長いセッションで30〜60分ごとにフェーズを再実行
  • 短いループを維持: mvn -T 4 test + spotbugs で迅速なフィードバック

注意: 迅速なフィードバックは遅い驚きに勝ります。ゲートを厳格に保ち、本番システムでは警告を欠陥として扱います。

Source and attribution

Source:affaan-m/ECCindocs/ja-JP/skills/springboot-verificationat commitef648e0

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal