Clears jetty CVE-2024-8184/CVE-2024-6763. Pins all Jetty modules via jetty-bom (no skew). Documents residual advisories with no upstream fix (jetty-http 11.x EOL, logback config-file CVEs, jackson WS-2026-0003) as accepted for this loopback daemon. CLAUDE.md: validate CVEs with the jetbrains analyzer (intellij-index is stale after pom edits).
2.9 KiB
claude-bridge — project instructions
IDE MCP tools & validation workflow (enforced)
Two IDE MCP servers are connected: intellij-index (semantic code intelligence) and
jetbrains (file problems, reformat, debugger). IntelliJ has multiple projects open; our
module is bridged. Always pass these to IDE MCP tools:
project_path=/Users/dai.ha/LTMS/claude-bridge/bridged- IDE paths are relative to
bridged/(e.g.src/main/java/dev/ltms/bridged/...)
After editing any file — mandatory
ide_sync_files{paths}— the built-in Edit/Write tools write to disk; the IDE index is stale until synced, or IDE nav/refactor/diagnostics give wrong results.ide_diagnostics{file}(orjetbrains get_file_problems) — clear all errors and warnings. IDE inspections catch what a build won't (unused params/fields, redundant modifiers, resource leaks, "always same arg", …). These diagnostics are per-file.mvn clean install(Bash) — required for overall project health (clean build + full test run). A per-file-clean file can still break the build or another module. This is the whole-project gate before declaring work done or committing.
Whenever dependencies change (or a pom.xml edit), validate CVEs with
jetbrains get_file_problems{filePath: "bridged/pom.xml"} — its Mend.io check reflects the
dependencies on disk. (Note: ide_diagnostics / intellij-index does NOT re-resolve dependencies
after a pom edit without a full Maven reimport, so it reports stale CVE results — don't trust it
for this.) Treat a CVE warning like any other: bump to a patched version and confirm
mvn clean install still passes. If the latest available version is still flagged (EOL line,
"insufficient information", or config-file-only advisories), document it as accepted in the pom
rather than chasing a fix that doesn't exist.
Use IDE MCP tools for navigation, refactoring, and diagnostics only
- Navigate (prefer over Grep/Read for symbols):
ide_find_definition,ide_find_class,ide_find_file,ide_find_references,ide_find_implementations,ide_find_super_methods,ide_call_hierarchy,ide_type_hierarchy,ide_search_text(regex:jetbrains search_in_files_by_regex). - Refactor (prefer over multi-file Edit / rm / mv):
ide_refactor_rename(position-based, updates all refs/overrides/tests),ide_refactor_safe_delete,ide_move_file,jetbrains reformat_file. - Diagnose:
ide_diagnostics/jetbrains get_file_problems.
Do NOT route build/test/one-offs through the IDE
Keep mvn (compile/test/package/clean install) and all one-off shell commands on Bash.
Do not use jetbrains build_project, execute_run_configuration, or execute_terminal_command
to replace them.
Java 25 notes
Prefer the unnamed lambda parameter _ for required-but-unused params; a non-public
static void main(String[]) is valid (JEP 512) and boots via java -jar.