lgtm,codescanning * The query "Cross-site scripting" (`java/xss`) has been improved to recognize `PrintWriter.format` as an XSS sink.