Skip to content

build(deps): AGP 9.4.1 + Gradle 9.6 (spike — blocked on Dokka) - #80

Draft
pandeymangg wants to merge 1 commit into
mainfrom
anshuman/agp-9-gradle-9.6
Draft

pandeymangg wants to merge 1 commit into
mainfrom
anshuman/agp-9-gradle-9.6

Conversation

@pandeymangg

@pandeymangg pandeymangg commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Ref ENG-3341

Draft / spike. Do not merge. This maps the AGP 9 migration and gets two of its three blockers out of the way; the third is unsolved and breaks releases. Opened so the work is visible and reviewable, not because it is ready.

What & why

Was: #77 bumps agp 8.9.2 → 9.4.1 and nothing else, so it cannot configure at all — AGP 9 needs Gradle ≥ 9.6.0 and the wrapper is on 8.11.1. That is why its CI is red.

Now: wrapper bumped alongside it, plus the two build-script changes AGP 9 forces. :android:assembleRelease passes. Publishing does not.

AGP 9 matters for security: it drops gRPC outright, which takes the entire Netty chain — 41 of the 52 open Dependabot alerts — off the plugin classpath. It does not cover everything, so it does not replace #79 (see below).

The three blockers

# Blocker State
1 android.defaults.buildfeatures.buildconfig removed in AGP 9 Fixed — dropped from gradle.properties; BuildConfig is referenced nowhere in android/src
2 AGP 9's built-in Kotlin is incompatible with kapt (used for data binding) Bypassed — android.builtInKotlin=false + android.newDsl=false, Google's documented opt-out. Real fix is kapt → KSP
3 Dokka fails on AGP 9's variant model Open — blocks release

Blocker 3 in full:

Execution failed for task ':android:dokkaGeneratePublicationJavadoc'
> Pre-generation validity check failed: Source sets 'androidJvm' and 'release'
  have the common source roots: android/src/main/kotlin, android/src/main/java

dokkaJavadocJar is part of publishAndReleaseToMavenCentral, so the SDK cannot be released while this stands. Dokka 2.2.0 is the latest stable — only 2.3.0-Beta is newer, and a beta doc toolchain is not something to ship on a security bump.

Verified

Check Outcome
:android:assembleRelease passes on AGP 9.4.1 / Gradle 9.6
buildEnvironment no io.netty and no io.grpc on the classpath at all; protobuf 3.25.5, commons-compress 1.27.1
:android:dokkaJavadocJar fails — blocker 3
Gradle 9.6 deprecations build reports "incompatible with Gradle 10" — not triaged

This does not replace #79

Resolved on this branch, against what the alerts require:

Package AGP 9.4.1 gives Alert needs
bcprov / bcpkix / bcutil 1.80.2 1.84, 1.85 still vulnerable
jose4j 0.9.5 0.9.6 still vulnerable
jdom2 2.0.6 2.0.6.1 still vulnerable

Six alerts survive AGP 9, three of them high severity. #79's floors are what clear those, and they stay useful here — the Netty and protobuf halves simply go inert, which is what a floor is supposed to do.

Left to do

  • kapt → KSP, then drop the two opt-out properties
  • A Dokka fix, or a different javadoc path
  • Triage the Gradle 10 deprecation warnings
  • Re-check the unit test tasks: AGP 9 exposes testDebugUnitTest only; testReleaseUnitTest is gone, and jacocoAndroidTestReport (what SonarCloud runs) is untested here

@sonarqubecloud

Copy link
Copy Markdown

pandeymangg added a commit that referenced this pull request Sep 28, 2026
…ttp to AGP 8.9-compatible versions

Every CI run on main has been red since the 2026-09-23 dependabot merges.
Two independent breakages:

- Kotlin 2.4.20 (#69) turns `kotlinOptions { jvmTarget = "11" }` into a
  script compilation error, so the build never configures.
- With that fixed, the test APK's AAR-metadata check rejects
  androidx.core 1.19.0 (#67, needs AGP >= 9.1) and okhttp 5.5.0 (#71,
  needs compileSdk 37) on AGP 8.9.2.

Migrate the script to `kotlin { compilerOptions { ... } }`, pin core-ktx
back to 1.16.0 and okhttp to 4.12.0, and have dependabot ignore newer
versions of those two until the AGP 9 migration (#80) lands. appcompat,
fragment and the Kotlin bump itself stay.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant