Skip to content
Back to skills

Java Conventions

ASecurity

Java code conventions covering Java 17+ records and sealed classes, formatting/static analysis, Maven/Gradle, JUnit 5, exception handling, constructor injection, streams, and security. Load when writing or reviewing Java code.

  • 146 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
ai-agentsgojavaexpresstestingsecurity

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add Goldziher/ai-rulez --skill java-conventions --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Java Conventions?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Java Conventions
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/goldziher-java-conventions/badge)](https://www.skillsdirectory.com/skills/goldziher-java-conventions)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: java-conventions
description: Java code conventions covering Java 17+ records and sealed classes, formatting/static analysis, Maven/Gradle, JUnit 5, exception handling, constructor injection, streams, and security. Load when writing or reviewing Java code.
---

- Java 17+ LTS, records for immutable data, sealed classes for restricted hierarchies, pattern matching.
- A consistent style guide and auto-formatter (e.g., Google Java Style + google-java-format). Static analysis (e.g., Error Prone + SpotBugs).
- Build: Maven or Gradle with wrapper scripts (`mvnw`/`gradlew`). Commit wrapper files.
- Testing: JUnit 5 with `@ParameterizedTest`, an assertion library (e.g., AssertJ), a coverage tool (e.g., JaCoCo) at 80%+.
- Benchmarking: JMH for microbenchmarks — never use `System.nanoTime()` loops.
- Error handling: specific exceptions only, never `catch (Exception)`, use try-with-resources for `AutoCloseable`.
- `var` for obvious types, `Optional<T>` for returns (never params/fields), `final` fields by default.
- Prefer constructor injection over field injection for DI. Immutable collections: `List.of()`, `Map.of()`.
- Streams for collection transforms, `instanceof` pattern matching, switch expressions.
- Security: OWASP `dependency-check` Maven/Gradle plugin for CVE scanning.
- Dependencies: commit lock files, use BOM for version alignment, avoid `SNAPSHOT` in releases.
- Anti-patterns: public fields, mutable static state, raw types, checked exceptions in lambdas.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…