Our client likes SonarQube, so I decided to set up SonarQube.

SonarQube is currently *furious* at me for using the default prng for generating random strings for test data.

Look SonarQube, I agree that this code is *stupid* (and not my idea!) - but it is hardly a security flaw.