lgtm,codescanning
* The query "Cross-site scripting" (`java/xss`) has been improved to recognize
`PrintWriter.format` as an XSS sink.