affaan-m/ECC

springboot-verification

Use it for engineering tasks; the detail page covers purpose, installation, and practical steps.

71CollectingRuns scripts
See how to use itView GitHub source
npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/springboot-verification"
Automated source guide

Source checked Jul 28, 2026·Refresh due Oct 26, 2026

Reorganized from the pinned upstream SKILL.md

Turn springboot-verification's source instructions into a guide you can follow

According to the pinned SKILL.md from affaan-m/ECC: Spring Boot项目验证循环:构建、静态分析、测试覆盖、安全扫描,以及发布或PR前的差异审查。

npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/springboot-verification"
Check the pinned source

Best fit

  • Use it for engineering tasks; the detail page covers purpose, installation, and practical steps.

Bring this context

  • A concrete task that matches the documented purpose of springboot-verification.
  • The files, examples, or context the task depends on.
  • Your constraints, target environment, and definition of done.

Expected outputs

  • A result that follows the pinned springboot-verification instructions.
  • A concise record of assumptions, inputs used, and unresolved questions.
  • A final check against the source workflow and relevant permission signals.

Key source sections

Read springboot-verification through these 5 source sections

Sections are extracted automatically from the pinned SKILL.md and link back to the source.

01

何时激活

为 Spring Boot 服务开启拉取请求之前 在重大重构或依赖项升级之后 用于暂存或生产环境的部署前验证 运行完整的构建 → 代码检查 → 测试 → 安全扫描流水线 验证测试覆盖率是否满足阈值

SKILL.md · 何时激活
为 Spring Boot 服务开启拉取请求之前在重大重构或依赖项升级之后用于暂存或生产环境的部署前验证
03

or

./gradlew clean assemble -x test bash mvn -T 4 spotbugs:check pmd:check checkstyle:check bash ./gradlew checkstyleMain pmdMain spotbugsMain bash mvn -T 4 test mvn jacoco:report verify 80%+ coverage

SKILL.md · or
./gradlew clean assemble -x test bash mvn -T 4 spotbugs:check pmd:check checkstyle:check bash ./gradlew checkstyleMain pmdMain spotbugsMain bash mvn -T 4 test mvn jacoco:report verify 80%+ coverage
04

阶段 2:静态分析

Review the “阶段 2:静态分析” section in the pinned source before continuing.

SKILL.md · 阶段 2:静态分析
Review and apply the “阶段 2:静态分析” source section.

SkillSignal prompt templates

Provide the task, context, and acceptance criteria

These prompts were written by SkillSignal from the source structure; they are not upstream text.

Task-start prompt

Confirm source fit, inputs, and outputs before acting.

Use springboot-verification to help me with: [specific task]. Context: [files, data, or background]. Constraints: [environment, scope, and prohibited actions]. Before acting, check the pinned SKILL.md and explain which sections apply, what inputs are still missing, and what you will deliver.

Source-guided execution

Make the Agent explicitly follow the key extracted sections.

Apply the pinned springboot-verification source to [task]. Pay particular attention to these source sections: “何时激活”, “阶段 1:构建”, “or”, “阶段 2:静态分析”, “阶段 3:测试 + 覆盖率”. Preserve the important decision at each step. Mark facts not covered by the source as “needs confirmation” instead of inventing them. Then verify the result against my acceptance criteria: [criteria].

Result-review prompt

Check omissions, permissions, and source drift before delivery.

Review the current springboot-verification result: (1) does it satisfy the original task; (2) were any applicable steps or limits in the pinned SKILL.md missed; (3) did it perform any unauthorized file, command, network, or data action; and (4) which conclusions remain unverified? List issues first, then fix only what the source or user authorization supports.

Output checklist

Verify each item before delivery

The task matches the purpose documented in the SKILL.md.

The source section “何时激活” has been checked.

The source section “阶段 1:构建” has been checked.

The source section “or” has been checked.

The source section “阶段 2:静态分析” has been checked.

Inputs, constraints, and acceptance criteria are explicit.

Unverified facts, compatibility, and outcome claims are clearly marked.

Any file, command, network, or data action has been reviewed.

Choose a different workflow

When another Skill is the better fit

FAQ

What does springboot-verification do?

Spring Boot项目验证循环:构建、静态分析、测试覆盖、安全扫描,以及发布或PR前的差异审查。

How do I start using springboot-verification?

The catalog detected this source-specific install command: npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/springboot-verification". Inspect the command and pinned source before running it.

Which Agent platforms does it declare?

No dedicated Agent platform is declared in the pinned source record.

Repository stars
234,327
Repository forks
35,711
Quality
71/100
Source repository last pushed

Quality breakdown

Based on traceable docs and repository signals; stars are not treated as quality.

71/100
Documentation26/30
Specificity15/25
Maintenance20/20
Trust signals10/25

Compare before choosing

Related Agent Skills and source variants

These links are selected from shared tasks, functions, stacks, platforms, and same-name variants. Compare the source owner, documentation, permissions, and maintenance signals.

View original Skill.mdThis page is parsed directly from the repository SKILL.md without editorial rewriting. Collected: Jul 28, 2026 · about 1 min

Spring Boot 验证循环

在提交 PR 前、重大变更后以及部署前运行。

何时激活

  • 为 Spring Boot 服务开启拉取请求之前
  • 在重大重构或依赖项升级之后
  • 用于暂存或生产环境的部署前验证
  • 运行完整的构建 → 代码检查 → 测试 → 安全扫描流水线
  • 验证测试覆盖率是否满足阈值

阶段 1:构建

mvn -T 4 clean verify -DskipTests
# or
./gradlew clean assemble -x test

如果构建失败,停止并修复。

阶段 2:静态分析

Maven(常用插件):

mvn -T 4 spotbugs:check pmd:check checkstyle:check

Gradle(如果已配置):

./gradlew checkstyleMain pmdMain spotbugsMain

阶段 3:测试 + 覆盖率

mvn -T 4 test
mvn jacoco:report   # verify 80%+ coverage
# or
./gradlew test jacocoTestReport

报告:

  • 总测试数,通过/失败
  • 覆盖率百分比(行/分支)

单元测试

使用模拟的依赖项来隔离测试服务逻辑:

@ExtendWith(MockitoExtension.class)
class UserServiceTest {

  @Mock private UserRepository userRepository;
  @InjectMocks private UserService userService;

  @Test
  void createUser_validInput_returnsUser() {
    var dto = new CreateUserDto("Alice", "alice@example.com");
    var expected = new User(1L, "Alice", "alice@example.com");
    when(userRepository.save(any(User.class))).thenReturn(expected);

    var result = userService.create(dto);

    assertThat(result.name()).isEqualTo("Alice");
    verify(userRepository).save(any(User.class));
  }

  @Test
  void createUser_duplicateEmail_throwsException() {
    var dto = new CreateUserDto("Alice", "existing@example.com");
    when(userRepository.existsByEmail(dto.email())).thenReturn(true);

    assertThatThrownBy(() -> userService.create(dto))
        .isInstanceOf(DuplicateEmailException.class);
  }
}

使用 Testcontainers 进行集成测试

针对真实数据库(而非 H2)进行测试:

@SpringBootTest
@Testcontainers
class UserRepositoryIntegrationTest {

  @Container
  static PostgreSQLContainer<?> postgres = new PostgreSQLContainer<>("postgres:16-alpine")
      .withDatabaseName("testdb");

  @DynamicPropertySource
  static void configureProperties(DynamicPropertyRegistry registry) {
    registry.add("spring.datasource.url", postgres::getJdbcUrl);
    registry.add("spring.datasource.username", postgres::getUsername);
    registry.add("spring.datasource.password", postgres::getPassword);
  }

  @Autowired private UserRepository userRepository;

  @Test
  void findByEmail_existingUser_returnsUser() {
    userRepository.save(new User("Alice", "alice@example.com"));

    var found = userRepository.findByEmail("alice@example.com");

    assertThat(found).isPresent();
    assertThat(found.get().getName()).isEqualTo("Alice");
  }
}

使用 MockMvc 进行 API 测试

在完整的 Spring 上下文中测试控制器层:

@WebMvcTest(UserController.class)
class UserControllerTest {

  @Autowired private MockMvc mockMvc;
  @MockBean private UserService userService;

  @Test
  void createUser_validInput_returns201() throws Exception {
    var user = new UserDto(1L, "Alice", "alice@example.com");
    when(userService.create(any())).thenReturn(user);

    mockMvc.perform(post("/api/users")
            .contentType(MediaType.APPLICATION_JSON)
            .content("""
                {"name": "Alice", "email": "alice@example.com"}
                """))
        .andExpect(status().isCreated())
        .andExpect(jsonPath("$.name").value("Alice"));
  }

  @Test
  void createUser_invalidEmail_returns400() throws Exception {
    mockMvc.perform(post("/api/users")
            .contentType(MediaType.APPLICATION_JSON)
            .content("""
                {"name": "Alice", "email": "not-an-email"}
                """))
        .andExpect(status().isBadRequest());
  }
}

阶段 4:安全扫描

# Dependency CVEs
mvn org.owasp:dependency-check-maven:check
# or
./gradlew dependencyCheckAnalyze

# Secrets in source
grep -rn "password\s*=\s*\"" src/ --include="*.java" --include="*.yml" --include="*.properties"
grep -rn "sk-\|api_key\|secret" src/ --include="*.java" --include="*.yml"

# Secrets (git history)
git secrets --scan  # if configured

常见安全发现

# 检查 System.out.println(应使用日志记录器)
grep -rn "System\.out\.print" src/main/ --include="*.java"

# 检查响应中的原始异常消息
grep -rn "e\.getMessage()" src/main/ --include="*.java"

# 检查通配符 CORS 配置
grep -rn "allowedOrigins.*\*" src/main/ --include="*.java"

阶段 5:代码检查/格式化(可选关卡)

mvn spotless:apply   # if using Spotless plugin
./gradlew spotlessApply

阶段 6:差异审查

git diff --stat
git diff

检查清单:

  • 没有遗留调试日志(System.outlog.debug 没有防护)
  • 有意义的错误信息和 HTTP 状态码
  • 在需要的地方有事务和验证
  • 配置变更已记录

输出模板

验证报告
===================
构建:     [通过/失败]
静态分析:    [通过/失败] (spotbugs/pmd/checkstyle)
测试:     [通过/失败] (X/Y 通过, Z% 覆盖率)
安全性:  [通过/失败] (CVE 发现数: N)
差异:      [X 个文件变更]

总体:   [就绪 / 未就绪]

待修复问题:
1. ...
2. ...

持续模式

  • 在重大变更时或长时间会话中每 30–60 分钟重新运行各阶段
  • 保持短循环:mvn -T 4 test + spotbugs 以获取快速反馈

记住:快速反馈胜过意外惊喜。保持关卡严格——将警告视为生产系统中的缺陷。

Source repo
affaan-m/ECC
Skill path
docs/zh-CN/skills/springboot-verification/SKILL.md
Commit SHA
4e973d3eaf92
Repository license
MIT
Data collected