bc04637694
Clears jetty CVE-2024-8184/CVE-2024-6763. Pins all Jetty modules via jetty-bom (no skew). Documents residual advisories with no upstream fix (jetty-http 11.x EOL, logback config-file CVEs, jackson WS-2026-0003) as accepted for this loopback daemon. CLAUDE.md: validate CVEs with the jetbrains analyzer (intellij-index is stale after pom edits).
53 lines
2.9 KiB
Markdown
53 lines
2.9 KiB
Markdown
# claude-bridge — project instructions
|
|
|
|
## IDE MCP tools & validation workflow (enforced)
|
|
|
|
Two IDE MCP servers are connected: **intellij-index** (semantic code intelligence) and
|
|
**jetbrains** (file problems, reformat, debugger). IntelliJ has multiple projects open; our
|
|
module is **`bridged`**. Always pass these to IDE MCP tools:
|
|
|
|
- `project_path` = `/Users/dai.ha/LTMS/claude-bridge/bridged`
|
|
- IDE paths are relative to `bridged/` (e.g. `src/main/java/dev/ltms/bridged/...`)
|
|
|
|
### After editing any file — mandatory
|
|
|
|
1. **`ide_sync_files{paths}`** — the built-in Edit/Write tools write to disk; the IDE index is
|
|
stale until synced, or IDE nav/refactor/diagnostics give wrong results.
|
|
2. **`ide_diagnostics{file}`** (or `jetbrains get_file_problems`) — clear **all** errors *and*
|
|
warnings. IDE inspections catch what a build won't (unused params/fields, redundant
|
|
modifiers, resource leaks, "always same arg", …). These diagnostics are **per-file**.
|
|
3. **`mvn clean install`** (Bash) — required for **overall project health** (clean build + full
|
|
test run). A per-file-clean file can still break the build or another module. This is the
|
|
whole-project gate before declaring work done or committing.
|
|
|
|
**Whenever dependencies change (or a `pom.xml` edit), validate CVEs with
|
|
`jetbrains get_file_problems{filePath: "bridged/pom.xml"}`** — its Mend.io check reflects the
|
|
dependencies on disk. (Note: `ide_diagnostics` / intellij-index does NOT re-resolve dependencies
|
|
after a pom edit without a full Maven reimport, so it reports stale CVE results — don't trust it
|
|
for this.) Treat a CVE warning like any other: bump to a patched version and confirm
|
|
`mvn clean install` still passes. If the latest available version is still flagged (EOL line,
|
|
"insufficient information", or config-file-only advisories), document it as accepted in the pom
|
|
rather than chasing a fix that doesn't exist.
|
|
|
|
### Use IDE MCP tools for navigation, refactoring, and diagnostics only
|
|
|
|
- **Navigate (prefer over Grep/Read for symbols):** `ide_find_definition`, `ide_find_class`,
|
|
`ide_find_file`, `ide_find_references`, `ide_find_implementations`, `ide_find_super_methods`,
|
|
`ide_call_hierarchy`, `ide_type_hierarchy`, `ide_search_text` (regex: `jetbrains
|
|
search_in_files_by_regex`).
|
|
- **Refactor (prefer over multi-file Edit / rm / mv):** `ide_refactor_rename` (position-based,
|
|
updates all refs/overrides/tests), `ide_refactor_safe_delete`, `ide_move_file`,
|
|
`jetbrains reformat_file`.
|
|
- **Diagnose:** `ide_diagnostics` / `jetbrains get_file_problems`.
|
|
|
|
### Do NOT route build/test/one-offs through the IDE
|
|
|
|
Keep `mvn` (compile/test/package/`clean install`) and **all** one-off shell commands on **Bash**.
|
|
Do not use `jetbrains build_project`, `execute_run_configuration`, or `execute_terminal_command`
|
|
to replace them.
|
|
|
|
### Java 25 notes
|
|
|
|
Prefer the unnamed lambda parameter `_` for required-but-unused params; a non-public
|
|
`static void main(String[])` is valid (JEP 512) and boots via `java -jar`.
|