Code Analyzer results
What Salesforce Code Analyzer reports on the Sojourn package, and every finding accepted with its reason.
The Code Analyzer workflow scans the package directories sojourn/ and sojourn-omni/ on every pull request, every push to main, and every week. It runs the AppExchange and Recommended rule selectors, which include every rule in the command the AppExchange security review prescribes, and Salesforce Graph Engine, which follows data from each entry point through the Apex classes to find missing access checks. This page is generated from those scans, and the workflow fails when the page and the scans disagree.
Engines: code-analyzer 0.53.0, cpd 0.46.0, pmd 0.46.0, regex 0.40.0, sfge 0.25.0.
Rule-based findings#
| Severity | Findings |
|---|---|
| Critical | 0 |
| High | 0 |
| Moderate | 0 |
| Low | 0 |
| Info | 0 |
Total: 0.
No findings at any severity.
Graph Engine findings#
| Severity | Findings |
|---|---|
| Critical | 0 |
| High | 0 |
| Moderate | 0 |
| Low | 0 |
| Info | 0 |
Total: 0.
No findings at any severity.
Accepted with a reason#
Rules turned off#
| Rule | Engine | Reason |
|---|---|---|
| ApexDoc | pmd | Accepted (D-308): the documentation standard is a one-line purpose comment on every class and on every non-obvious member; full ApexDoc blocks with @param and @return on every member only restate signatures. |
Suppressed in code#
| Rule | Classes | Reason |
|---|---|---|
| PMD.ApexUnitTestClassShouldHaveRunAs | ApplicationFactoriesTest, BusinessHoursCalcTest, CaptureEngineBulkTest, CaptureEngineSecurityTest, ChangeCaptureTest, ChangeDetectorTest, ConfigCacheTest, ErrorLoggerTest, GoalStamperTest, IntervalsTest, LimitGuardTest, LookupResolverTest, PermissionModelTest, RecordNamesSelectorTest, SObjectSelectorTest, SchemaTest, SelectorsTest, SnapshotCopierTest, SojournSettingsTest, SupportUtilitiesTest, TestDataFactoryTest, TrackedFieldsTest, TrackedRecordsTest, TriggerHandlerTest, UnitOfWorkTest |
Methods without System.runAs test behaviour as the test user; access denial is proven with System.runAs in the security tests. |
| PMD.ApexUnitTestClassShouldHaveRunAs | ChangeCaptureServiceTest |
Total complexity is the sum of independent one-scenario tests; no method exceeds 2. Methods without System.runAs test behaviour as the test user; access denial is proven with System.runAs in the security tests. Queries the second save in changeEveryReference spent. |
| PMD.AvoidDebugStatements | ErrorLogger |
The debug log is the only channel left when an error row itself cannot be written. |
| PMD.AvoidGlobalModifier | ChangeCapture |
The invocable must be global so subscriber Flows can call it; CLAUDE.md rule 10 names it as one of two global types. |
| PMD.CognitiveComplexity | UnitOfWork |
three small DML strategy classes and per-type accessors live here on purpose so callers write UnitOfWork.UserModeDml |
| PMD.CyclomaticComplexity | ChangeCaptureServiceTest |
Total complexity is the sum of independent one-scenario tests; no method exceeds 2. Methods without System.runAs test behaviour as the test user; access denial is proven with System.runAs in the security tests. Queries the second save in changeEveryReference spent. |
| PMD.CyclomaticComplexity | UnitOfWork |
three small DML strategy classes and per-type accessors live here on purpose so callers write UnitOfWork.UserModeDml |
| PMD.EmptyStatementBlock | SObjectDomain |
The trigger-event hooks are empty virtual methods on purpose; each domain overrides only the events it handles. |
| PMD.ExcessiveParameterList | Intervals |
Each argument is a distinct fact of the new interval; a holder type would only rename them. |
| PMD.ExcessiveParameterList | BusinessHoursCalc |
The four inputs are the four independent sources in the documented resolution order. |
| PMD.ExcessiveParameterList | TriggerHandler |
mirrors the five Trigger context values on purpose |
| PMD.FieldNamingConventions | Application |
The registry fields are nouns by design (Application.Service, Application.Selector); see the architecture standard. |
| PMD.OperationWithLimitsInLoop | RecordNamesSelector |
One query per referenced object type (in practice User and Group), never per record. |
| PMD.OperationWithLimitsInLoop | TestDataFactory |
The loop exists to spend DML statements; tests use it to prove the limit guards. |
| PMD.OperationWithLimitsInLoop | TestDataFactory |
The loop exists to spend queries; tests use it to prove the limit guards. |