Skip to main content

Find new exceptions thrown without the caught exception

org.openrewrite.staticanalysis.FindNewExceptionWithoutCause

Finds catch blocks that throw a newly created exception without referencing the caught exception, which discards the original exception's stack trace and message. Data flow (taint) tracking is used to establish whether the caught exception—or any value derived from it—reaches the thrown exception, so indirect references through local variables and string concatenation are not falsely reported. This mirrors PMD's PreserveStackTrace rule.

Recipe source

GitHub: FindNewExceptionWithoutCause.java, Issue Tracker, Code Genome Project

This recipe is available under the Moderne Source Available License. Moderne customers can download precompiled artifacts from The Code Genome Project. For non-commercial use you can build the artifact from source locally.

Example

Before
import java.io.IOException;
class A {
void risky() throws IOException {}
void foo() {
try {
risky();
} catch (IOException e) {
throw new RuntimeException("Failed");
}
}
}
After
import java.io.IOException;
class A {
void risky() throws IOException {}
void foo() {
try {
risky();
} catch (IOException e) {
throw /*~~>*/new RuntimeException("Failed");
}
}
}

Usage

This recipe has no required configuration options. It can be activated by adding a dependency on `org.openrewrite.recipe:rewrite-static-analysis` in your build file or by running a shell command (in which case no build changes are needed):

OpenRewrite artifacts, including the Maven and Gradle plugins themselves, are distributed through the Code Genome Project repository (https://artifacts.codegenomeproject.org/maven), which requires authentication. Sign in to the Code Genome Project to create a download token; your build authenticates with the email or username you signed in with, plus that token as the password. See the quickstart guide for details.

  1. Put your Code Genome Project credentials in ~/.gradle/gradle.properties, so that they are not committed alongside your build:
    ~/.gradle/gradle.properties
    codeGenomeUsername=you@example.com
    codeGenomeToken=your-download-token
  2. Add the Code Genome Project repository to your settings.gradle file, so that the plugin itself can be resolved:
    settings.gradle
    pluginManagement {
    repositories {
    maven {
    url = "https://artifacts.codegenomeproject.org/maven"
    credentials {
    username = providers.gradleProperty("codeGenomeUsername").get()
    password = providers.gradleProperty("codeGenomeToken").get()
    }
    }
    // Keep the portal for any other plugins your build applies
    gradlePluginPortal()
    }
    }
  3. Add the following to your build.gradle file:
    build.gradle
    plugins {
    id("org.openrewrite.rewrite") version("latest.release")
    }

    rewrite {
    activeRecipe("org.openrewrite.staticanalysis.FindNewExceptionWithoutCause")
    setExportDatatables(true)
    }

    repositories {
    mavenCentral()
    maven {
    url = "https://artifacts.codegenomeproject.org/maven"
    credentials {
    username = providers.gradleProperty("codeGenomeUsername").get()
    password = providers.gradleProperty("codeGenomeToken").get()
    }
    }
    }

    dependencies {
    rewrite("org.openrewrite.recipe:rewrite-static-analysis:2.43.0")
    }
  4. Run gradle rewriteRun to run the recipe.

See how this recipe works across multiple open-source repositories

Run this recipe on OSS repos at scale with the Moderne SaaS.

The community edition of the Moderne platform enables you to easily run recipes across thousands of open-source repositories.

Please contact Moderne for more information about safely running the recipes on your own codebase in a private SaaS.

Data Tables

Exceptions thrown without the caught cause

org.openrewrite.staticanalysis.table.ExceptionsWithoutCause

New exceptions thrown from a catch block that do not reference the caught exception.

Column NameDescription
Source pathThe path to the source file containing the offending throw.
Caught exception typeThe declared type of the exception caught by the enclosing catch clause.
Thrown exception typeThe type of the new exception thrown without referencing the caught exception.