Repository navigation
maint: Prune verification metadata and update third-party versions - #477
Conversation
gibson9583
left a comment
There was a problem hiding this comment.
Dependency-check still requests the five Jackson POMs and Rhino POM removed here. A focused resolution test passes on the base, fails on this PR, and passes with those six checksums restored. Please retain those entries.
@gibson9583 I think I'm going to leave it for now. The dependencyCheck task looks like it was an attempt to carry over something from ant that never worked. We don't have an API key for it, and it doesn't run in CI. I tried running it manually, but it warns that it will be very slow without the API key, and I killed it after 13 minutes with no clue how far it got into the process. The renovate updates don't include the pom files that it needs, and the command in the CONTRIBUTING guide to update verification-metadata doesn't add them either. Whether we clean things up so we can use it or we get rid of it, I think I'd prefer to save that for a future PR. |
I'm good with that |
|
README, three more stale versions and one we don't ship:
|
3f382ac
4b5faad to
3f382ac
Compare
tonygermano
left a comment
There was a problem hiding this comment.
The changes @pacmano1 requested have been added to the second commit
|
nb: One small inconsistency: the TXW Runtime source link still points to |
Regenerate the file from a cold Gradle cache with the command in CONTRIBUTING.md. This only removes entries for versions the build no longer resolves, left behind by earlier bumps (Netty 4.1.119/4.1.136, Log4j 2.25.3/2.25.4, Derby 10.11.1.1, mssql-jdbc 8.4.1, JUnit 4.8.1, and others), plus the POMs of six components whose Gradle module metadata is used instead. No checksum is added or changed. Signed-off-by: Tony Germano <tony@germano.name>
Several libraries were bumped without updating the versions listed here. Match them to what the distribution ships: - Apache Log4j 2.26.1 - Netty 4.1.137 - Jakarta Mail API 1.6.8, with its source link moved to the 1.6.8 tag - PostgreSQL JDBC Driver 42.7.12 - Java Common Annotations API 1.3.2, with its source link moved to the 1.3.2 tag - SAAJ Impl 1.4.0, which ships under the legacy file name saaj-impl-1.0.jar - JAXB TXW Runtime 2.4.0-b180725.0644, which follows jaxb-ri Drop the JUnit 4.8.1 license section: nothing in the distribution bundles JUnit or Hamcrest any more, as the tests resolve them at build time. Signed-off-by: Tony Germano <tony@germano.name>
3f382ac to
a13e6af
Compare
Release cleanup with no changes to dependency versions.
Prune unused entries from verification-metadata.xml
Regenerated
gradle/verification-metadata.xmlfrom a cold Gradle cache using the command inCONTRIBUTING.md:The diff only removes lines (293). No checksum is added or changed, so this extends no new trust. What it removes:
javax.annotation-api1.3..pomof six components that also publish Gradle module metadata:jackson-{annotations,databind,dataformat-cbor,dataformat-yaml,datatype-jsr310}:2.14.3andrhino:1.7.13. Their.jarand.moduleentries remain. Gradle didn't read these POMs during the cold-cache build, andverify-metadatais on, so any metadata file the build reads but the file doesn't list fails the build.Update stale versions in THIRD-PARTY-README.txt
Several libraries were bumped without updating
server/docs/thirdparty/THIRD-PARTY-README.txt:1.6.8tag)Every other version listed in the README matches
gradle/libs.versions.toml.🤖 Generated with Claude Code