Skip to content

maint: Prune verification metadata and update third-party versions - #477

Merged
tonygermano merged 2 commits into
OpenIntegrationEngine:mainfrom
tonygermano:maint/cleanup-metadata
Oct 9, 2026
Merged

tonygermano merged 2 commits into
OpenIntegrationEngine:mainfrom
tonygermano:maint/cleanup-metadata

Conversation

@tonygermano

Copy link
Copy Markdown
Member

Release cleanup with no changes to dependency versions.

Prune unused entries from verification-metadata.xml

Regenerated gradle/verification-metadata.xml from a cold Gradle cache using the command in CONTRIBUTING.md:

  GRADLE_USER_HOME=$(mktemp -d) ./gradlew --write-verification-metadata sha256 build dist -PdisableSigning=true -Pcoverage=true                                                                                

The diff only removes lines (293). No checksum is added or changed, so this extends no new trust. What it removes:

  • 37 components for versions the build no longer resolves, left behind by earlier bumps: Netty 4.1.119/4.1.136, Log4j 2.25.3/2.25.4, Derby 10.11.1.1 (rolled back in b457938), mssql-jdbc 8.4.1, JUnit 4.8.1, Jakarta Mail 1.6.7, PostgreSQL 42.7.8, commons-configuration2 2.13.0, older Jackson/JUnit BOMs and parent POMs, and javax.annotation-api 1.3.
  • The .pom of six components that also publish Gradle module metadata: jackson-{annotations,databind,dataformat-cbor,dataformat-yaml,datatype-jsr310}:2.14.3 and rhino:1.7.13. Their .jar and .module entries remain. Gradle didn't read these POMs during the cold-cache build, and verify-metadata is on, so any metadata file the build reads but the file doesn't list fails the build.

Update stale versions in THIRD-PARTY-README.txt

Several libraries were bumped without updating server/docs/thirdparty/THIRD-PARTY-README.txt:

Library Was Now
Apache Log4j 2.25.3 2.26.1
Netty 4.1.119 4.1.137
Jakarta Mail API 1.6.7 1.6.8 (source link moved to the 1.6.8 tag)
PostgreSQL JDBC Driver 42.7.8 42.7.12

Every other version listed in the README matches gradle/libs.versions.toml.

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Test Results

127 files  ±0  127 suites  ±0   3m 41s ⏱️ + 1m 14s
727 tests ±0  727 ✅ ±0  0 💤 ±0  0 ❌ ±0 
817 runs  ±0  811 ✅ ±0  6 💤 ±0  0 ❌ ±0 

Results for commit 3f382ac. ± Comparison against base commit d9520f9.

♻️ This comment has been updated with latest results.

@gibson9583 gibson9583 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency-check still requests the five Jackson POMs and Rhino POM removed here. A focused resolution test passes on the base, fails on this PR, and passes with those six checksums restored. Please retain those entries.

jonbartels
jonbartels previously approved these changes Oct 8, 2026
@tonygermano

Copy link
Copy Markdown
Member Author

Dependency-check still requests the five Jackson POMs and Rhino POM removed here. A focused resolution test passes on the base, fails on this PR, and passes with those six checksums restored. Please retain those entries.

@gibson9583 I think I'm going to leave it for now. The dependencyCheck task looks like it was an attempt to carry over something from ant that never worked. We don't have an API key for it, and it doesn't run in CI. I tried running it manually, but it warns that it will be very slow without the API key, and I killed it after 13 minutes with no clue how far it got into the process. The renovate updates don't include the pom files that it needs, and the command in the CONTRIBUTING guide to update verification-metadata doesn't add them either.

Whether we clean things up so we can use it or we get rid of it, I think I'd prefer to save that for a future PR.

@gibson9583

Copy link
Copy Markdown
Contributor

Dependency-check still requests the five Jackson POMs and Rhino POM removed here. A focused resolution test passes on the base, fails on this PR, and passes with those six checksums restored. Please retain those entries.

@gibson9583 I think I'm going to leave it for now. The dependencyCheck task looks like it was an attempt to carry over something from ant that never worked. We don't have an API key for it, and it doesn't run in CI. I tried running it manually, but it warns that it will be very slow without the API key, and I killed it after 13 minutes with no clue how far it got into the process. The renovate updates don't include the pom files that it needs, and the command in the CONTRIBUTING guide to update verification-metadata doesn't add them either.

Whether we clean things up so we can use it or we get rid of it, I think I'd prefer to save that for a future PR.

I'm good with that

@gibson9583
gibson9583 self-requested a review October 8, 2026 22:00
gibson9583
gibson9583 previously approved these changes Oct 8, 2026
@pacmano1

pacmano1 commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

README, three more stale versions and one we don't ship:

  • Java Common Annotations API 1.3: ships 1.3.2 (why this PR can prune 1.3)
  • SOAP with Attachment API for Java Impl 1.0: saaj-impl is 1.4.0
  • JAXB TXW Runtime 2.4.0-b180725.0427: txw2 follows jaxb-ri, 2.4.0-b180725.0644
  • the JUnit 4.8.1 license section: nothing ships JUnit any more (the tests fetch 4.13.1 at build time), so the section can go

@tonygermano
tonygermano dismissed stale reviews from gibson9583 and jonbartels via 3f382ac October 9, 2026 00:45
@tonygermano
tonygermano force-pushed the maint/cleanup-metadata branch from 4b5faad to 3f382ac Compare October 9, 2026 00:45

@tonygermano tonygermano left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes @pacmano1 requested have been added to the second commit

@NicoPiel

NicoPiel commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

nb: One small inconsistency: the TXW Runtime source link still points to tree/master/jaxb-ri/txw, while the jaxb-ri entry above it points to the version tag.

@NicoPiel NicoPiel left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@tonygermano tonygermano added this to the Next Release milestone Oct 9, 2026
@tonygermano tonygermano added dependencies Dependency updates licensing Eclipse Intellectual Property (IP) due diligence: licensing, provenance, Dash results, IP reviews and removed dependencies Dependency updates labels Oct 9, 2026
Regenerate the file from a cold Gradle cache with the command in
CONTRIBUTING.md. This only removes entries for versions the build no
longer resolves, left behind by earlier bumps (Netty 4.1.119/4.1.136,
Log4j 2.25.3/2.25.4, Derby 10.11.1.1, mssql-jdbc 8.4.1, JUnit 4.8.1,
and others), plus the POMs of six components whose Gradle module
metadata is used instead. No checksum is added or changed.

Signed-off-by: Tony Germano <tony@germano.name>
Several libraries were bumped without updating the versions listed
here. Match them to what the distribution ships:

- Apache Log4j 2.26.1
- Netty 4.1.137
- Jakarta Mail API 1.6.8, with its source link moved to the 1.6.8 tag
- PostgreSQL JDBC Driver 42.7.12
- Java Common Annotations API 1.3.2, with its source link moved to the
  1.3.2 tag
- SAAJ Impl 1.4.0, which ships under the legacy file name
  saaj-impl-1.0.jar
- JAXB TXW Runtime 2.4.0-b180725.0644, which follows jaxb-ri

Drop the JUnit 4.8.1 license section: nothing in the distribution
bundles JUnit or Hamcrest any more, as the tests resolve them at build
time.

Signed-off-by: Tony Germano <tony@germano.name>
@tonygermano
tonygermano force-pushed the maint/cleanup-metadata branch from 3f382ac to a13e6af Compare October 9, 2026 20:02
@tonygermano
tonygermano merged commit a13e6af into OpenIntegrationEngine:main Oct 9, 2026
2 checks passed
@tonygermano
tonygermano deleted the maint/cleanup-metadata branch October 9, 2026 20:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

licensing Eclipse Intellectual Property (IP) due diligence: licensing, provenance, Dash results, IP reviews

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants