Agent skill

Upgrade Java Deps

by nvuillam in nvuillam/npm-groovy-lint

Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…

MITAuto-check: notesSecurity

Install Upgrade Java Deps

skills CLI
$ npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nvuillam/npm-groovy-lint upgrade-java-deps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nvuillam/npm-groovy-lint.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/upgrade-java-deps .claude/skills/upgrade-java-deps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
upgrade-java-deps
GitHub stars
248
Token cost
~1.9k tokens
SKILL.md length
746 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…

  • Works in 4 steps: Find the fixed version that actually… → Keep version sets consistent. → Download new, delete old → …
  • Bumping CodeNarc
  • SKILL.md covers Background: why this is not…, Prerequisites, Option A — bump everything to… and Option B — surgical upgrade…, plus 3 more sections
  • Calls npm, node and git; reaches repo1.maven.org and api.github.com

What it does

Upgrade Java Deps is an agent skill from nvuillam/npm-groovy-lint. Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify nothing regressed. Use when bumping CodeNarc, fixing a grype/trivy CVE in a bundled jar, or refreshing the Java toolchain.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning and Linting and formatting. It works with Java and Trivy. The repository describes itself as: Lint, format and auto-fix your Groovy / Jenkinsfile / Gradle files using command line. The licence is MIT.

When your agent uses it

  • Bumping CodeNarc
  • Fixing a grype/trivy CVE in a bundled jar
  • Refreshing the Java toolchain

Example prompts

  • “/upgrade-java-deps”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Glob, Edit, Write

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Find the fixed version that actually exists. grype reports a "fixed in" version, but it may be unpublished or ahead of Maven Central…
  2. Keep version sets consistent.
  3. Download new, delete old
  4. Rebuild: npm run server:build (regenerates groovy/src/main/MANIFEST.MF Class-Path + lib/java/CodeNarcServer.jar).

What it can do on your machine

Read from SKILL.md and the folder at commit 2080dff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Glob
    • Edit
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • node
    • git
    • java
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • repo1.maven.org
    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Upgrade Java Deps loads about 1.9k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 746 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Glob, Edit, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nvuillam/npm-groovy-lint at commit 2080dff, republished under its MIT licence (© nvuillam). 746 words, ~1,908 tokens.

Download SKILL.mdSave it as .claude/skills/upgrade-java-deps/SKILL.md (or your agent's skills folder).
name
upgrade-java-deps
description
Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify nothing regressed. Use when bumping CodeNarc, fixing a grype/trivy CVE in a bundled jar, or refreshing the Java toolchain.
allowed-tools
Bash, Read, Grep, Glob, Edit, Write
user-invocable
true
model
sonnet

Upgrade the Java jars bundled under lib/java/ and rebuild the CodeNarc server.

Background: why this is not just npm update

npm-groovy-lint ships a set of committed Java jars in lib/java/ (and Groovy's own libs in lib/java/groovy/lib/). The Node CLI starts lib/java/CodeNarcServer.jar (a thin Groovy server compiled from groovy/src/main/) whose MANIFEST.MF Class-Path lists every sibling jar by exact filename. So a dependency upgrade means: swap the jar file, regenerate the manifest, recompile + repackage the server jar, and verify both run paths still work.

Security scanners in MegaLinter (grype, trivy) scan these jars, so jar CVEs surface as Mega-Linter failures even though npm audit is clean.

The jars:

  • Root (lib/java/): CodeNarc-*-groovy-4.0.jar, GMetrics-Groovy4-*.jar, jackson-{core,databind,annotations}-*.jar, logback-{classic,core}-*.jar, slf4j-api-*.jar, janino-*.jar, commons-compiler-*.jar — plus logback.xml and the built CodeNarcServer.jar.
  • Groovy (lib/java/groovy/lib/): groovy-*, groovy-ant, commons-cli, ant*.

The download targets and group/artifact IDs are codified in scripts/update-java-jars.js (TARGETS). Read it first — it is the source of truth for what is bundled and where.

Prerequisites

  • JDK 17–24 and Groovy (groovyc) on PATH. Check: java -version, groovy --version. CodeNarc 3.x targets Groovy 4 (-groovy-4.0 jars), so keep the Groovy libs on the 4.x line.
  • Run from a feature branch, never main.

Option A — bump everything to latest (broad)

bash
npm run dev:upgrade-jars      # = node scripts/update-java-jars.js  (fetches LATEST stable of every TARGET)
npm run dev:pre-commit        # lint:fix + build + server:build (regenerates manifest + CodeNarcServer.jar)

update-java-jars.js removes old jars and downloads the newest stable from Maven Central. Use this for a routine refresh. Caveat: it also bumps CodeNarc / GMetrics / Groovy, which can change lint output or break the server — always run the full verification below and review the result diff.

When only specific jars are flagged (e.g. by grype), replace just those so you don't accidentally bump CodeNarc/Groovy.

  1. Find the fixed version that actually exists. grype reports a "fixed in" version, but it may be unpublished or ahead of Maven Central. Probe before committing to a version:

    bash
    # HEAD-probe a specific jar (Windows curl needs --ssl-no-revoke)
    probe() { curl -sS --ssl-no-revoke -m 25 -o /dev/null -w "%{http_code}  $2-$3\n" \
      "https://repo1.maven.org/maven2/${1//.//}/$2/$3/$2-$3.jar"; }
    probe com.fasterxml.jackson.core jackson-databind 2.22.0
    probe ch.qos.logback logback-core 1.5.25

    If the exact "fixed in" patch is unpublished, jump to the next published version whose number is above the advisory's vulnerable range (check https://api.github.com/advisories/<GHSA-ID> for the real range). Example seen in practice: GHSA fixed-in 2.21.5 (unpublished) → use 2.22.0, which is above the < 2.21.5 range.

  2. Keep version sets consistent.

    • jackson: upgrade jackson-core, jackson-databind, jackson-annotations together to the same release train. Note jackson-annotations uses a minor-only version (e.g. jackson-annotations-2.22.jar, not 2.22.0) — confirm the exact artifact name with a probe.
    • logback: upgrade logback-classic and logback-core to the same version.
  3. Download new, delete old:

    bash
    cd lib/java
    curl -sS --ssl-no-revoke -O "https://repo1.maven.org/maven2/com/fasterxml/jackson/core/jackson-databind/2.22.0/jackson-databind-2.22.0.jar"
    # ...repeat for each jar...
    rm jackson-databind-2.19.0.jar   # remove the superseded versions
    unzip -l jackson-databind-2.22.0.jar >/dev/null && echo OK   # sanity-check it's a valid zip
    cd ../..
  4. Rebuild: npm run server:build (regenerates groovy/src/main/MANIFEST.MF Class-Path + lib/java/CodeNarcServer.jar).

Show full SKILL.md (347 more words)Show less

CRITICAL: logback.xml and the one-shot (--noserver) path

There are two run paths and they fail differently:

  • Server mode (default): Node starts the jar once and talks HTTP. Startup noise is harmless.
  • One-shot mode (--noserver, and several tests): Node runs java ... com.nvuillam.CodeNarcServer <args> and JSON.parses the entire stdout. Anything else on stdout breaks it ("Unable to use CodeNarc JSON result").

logback prints its internal status log to stdout whenever a config WARN/ERROR occurs. Newer logback versions deprecate the condition attribute on <if> (emitting a WARN) — which dumps status onto stdout and breaks one-shot mode. Mitigations, both already applied in lib/java/logback.xml, that you must preserve when bumping logback:

  • A <statusListener class="ch.qos.logback.core.status.NopStatusListener"/> as the first child of <configuration> to silence status output.
  • Keep the <if condition='isDefined("...")'> attribute form. (The <condition> element form does NOT enable the appender in 1.5.x — it silently evaluates false and the FILE appender is never created, breaking the "log file creation" test.)
  • XML comments must not contain a literal -- (double hyphen) — it's a fatal XML parse error that itself triggers a status dump. Write "no server", not "--server".

If a future logback bump changes this behavior, the canonical check is step "verify A" below (stdout must start with {).

Verify (do all three)

bash
node lib/index.js --killserver
# A) one-shot stdout must be pure JSON (no logback status, no banner)
printf 'def x=1\nprintln x\n' > /tmp/smoke.groovy
node lib/index.js --noserver /tmp/smoke.groovy            # must print a clean results table, exit 0/1 (not 2)

# B) server path
node lib/index.js --killserver && node lib/index.js /tmp/smoke.groovy

# C) full suite (needs Java + Groovy; ~10-15 min)
npm run test

A clean one-shot run is the key signal the jackson/logback swap is healthy. If npm test shows failures, confirm they are caused by your change before fixing: git stash push -- lib/java groovy/src/main/MANIFEST.MF, re-run the failing test on the original jars, then git stash pop. Some tests (e.g. an exec with escaped-quote rulesets like NoDef{"enabled":false}) fail only on Windows-local shell quoting and are green in CI — don't chase those.

Commit

The lint.yml "Update check" CI job runs npm run dev:pre-commit and fails if the tree isn't clean, so run it and stage all regenerated artifacts (the new jars, the deleted old jars, MANIFEST.MF, CodeNarcServer.jar, and logback.xml if touched).

bash
npm run dev:pre-commit
git add lib/java groovy/src/main/MANIFEST.MF
git commit   # use a "Fix CI:" / "chore(deps):" style message

Gotcha: CodeNarcServer.jar is built deterministically, but its zlib compression is sensitive to the Node version. If "Update check" reports the jar as changed after you ran dev:pre-commit, rebuild with the same Node version CI uses (see CONTRIBUTING.md).

© nvuillam, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/upgrade-java-deps of nvuillam/npm-groovy-lint.

Open the folder on GitHubat commit 2080dff

Compare with similar skills

Upgrade Java Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Upgrade Java Deps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Upgrade Java Deps this skillnvuillam/npm-groovy-lint248—~1.9kAutomated safety check: NotesMIT
Sca TrivyAgentSecOps/SecOpsAgentKit2192 repos~3.7kAutomated safety check: PassCustom licence
Fix Security Issuehardisgroupcom/sfdx-hardis400—~1.3kAutomated safety check: NotesAGPL-3.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Dep Scanepam/ai-dial-chat504—~1.2kAutomated safety check: PassApache-2.0

Similar skills

  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    219 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Fix Security Issue

    hardisgroupcom/sfdx-hardis

    Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.).

    400 GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Dep Scan

    epam/ai-dial-chat

    Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.

    504 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed
  • A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

    445 GitHub stars~3.2k tokensUpdated today
    SecurityAuto-check passed

More from nvuillam/npm-groovy-lint

  • Megalinter Check

    nvuillam/npm-groovy-lint

    Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Megalinter Setup

    nvuillam/npm-groovy-lint

    Install or upgrade MegaLinter on a repository. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check: notes
  • Megalinter

    nvuillam/npm-groovy-lint

    Entry point for everything MegaLinter. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~915 tokens
    Auto-check: notes
  • Megalinter Fix

    nvuillam/npm-groovy-lint

    Fix the errors reported by MegaLinter. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check: notes
  • PR Watch Fix

    nvuillam/npm-groovy-lint

    Watch the GitHub PR for the current branch, wait for CI to finish, and autonomously fix failing jobs by reading logs, editing sources, and pushing.

    248 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check: notes

Works with

Categories

Questions about Upgrade Java Deps

What does Upgrade Java Deps do?

Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…. Upgrade Java Deps is an agent skill from nvuillam/npm-groovy-lint.jar, and verify nothing regressed.

When should I use Upgrade Java Deps?

Upgrade Java Deps fits situations like: bumping CodeNarc; fixing a grype/trivy CVE in a bundled jar; refreshing the Java toolchain.

How do I install Upgrade Java Deps in Claude Code?

Run `npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a claude-code`. Or copy the skill folder (.claude/skills/upgrade-java-deps in nvuillam/npm-groovy-lint) into .claude/skills/upgrade-java-deps in your project. Claude Code loads it when a task matches its description.

How do I install Upgrade Java Deps in Codex?

Run `npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a codex`. Or copy the skill folder (.claude/skills/upgrade-java-deps in nvuillam/npm-groovy-lint) into .agents/skills/upgrade-java-deps in your project. Codex loads it when a task matches its description.

Can I use Upgrade Java Deps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upgrade-java-deps, .gemini/skills/upgrade-java-deps, .github/skills/upgrade-java-deps and .opencode/skills/upgrade-java-deps in your project.

What does Upgrade Java Deps need to run?

Going by SKILL.md and its folder, Upgrade Java Deps needs the command-line tools its instructions call (npm, node, git, java and curl). Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob, Edit, Write.

Does Upgrade Java Deps access the network?

SKILL.md names 2 domains. In commands or code: repo1.maven.org and api.github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Upgrade Java Deps safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Upgrade Java Deps use?

Upgrade Java Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Upgrade Java Deps use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Upgrade Java Deps?

Skills that share tags, products or a category with Upgrade Java Deps: Sca Trivy (AgentSecOps/SecOpsAgentKit, 219 stars), Fix Security Issue (hardisgroupcom/sfdx-hardis, 400 stars), Code Audit (3stoneBrother/code-audit, 893 stars) and CodeQL Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Upgrade Java Deps?

nvuillam (a GitHub user) maintains it in nvuillam/npm-groovy-lint, which has 248 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 4, 2026.

Source: nvuillam/npm-groovy-lint on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.