pjfanning opened a new pull request, #129: URL: https://github.com/apache/poi-xmlbeans/pull/129
Fixes code-scanning alerts #6 and #7 (`java/implicit-cast-in-compound-assignment`) in `SchemaTypeSystemImpl.nextBytes`. The byte wraparound is intended, so the two `byte` compound assignments are now one assignment with an explicit `(byte)` cast. While there, two fixes in the same method. Both affect only how random the generated type-system names are: - The mixing loop added the index `i` and never read `bytes[i]`, so the mask depended only on how many bytes of system info there were, not on their content. - The mask was indexed with `i & _mask.length` (`i & 16`), which is always 0 for i in 0..15, so only `_mask[0]` was ever applied. It is now `i % _mask.length`, like the earlier loop. Alerts #1–#5 (`GDurationBuilder`, `GDateBuilder`, `PushedInputStream`) were raised against an older commit and are already fixed on trunk, so they should close on the next scan. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
