Skip to content

chore(deps): update gradle to v9.6.1 - #267

Merged
Manabu-GT merged 2 commits into
mainfrom
renovate/gradle-9.x
Jul 31, 2026
Merged

Manabu-GT merged 2 commits into
mainfrom
renovate/gradle-9.x

Conversation

@renovate

@renovate renovate Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
gradle (source) minor 9.4.1 → 9.6.1

Release Notes

gradle/gradle (gradle)

v9.6.1

Compare Source

v9.6.0

Compare Source

v9.5.1: 9.5.1

Compare Source

The Gradle team is excited to announce Gradle 9.5.1.

Here are the highlights of this release:

  • Task provenance in reports and failure messages
  • Type-safe accessors for precompiled Kotlin Settings plugins

Read the Release Notes

We would like to thank the following community members for their contributions to this release of Gradle:
atm1020,
mataha,
Adam,
Attila Kelemen,
Benedikt Ritter,
Björn Kautler,
Caro Silva Rode,
CHANHAN,
Dmitry Nezavitin,
Eng Zer Jun,
KugelLibelle,
Madalin Valceleanu,
Markus Gaisbauer,
Oliver Kopp,
Philip Wedemann,
ploober,
Roberto Perez Alcolea,
Rohit Anand,
Suvrat Acharya,
Ujwal Suresh Vanjare,
Victor Merkulov

Upgrade instructions

Switch your build to use Gradle 9.5.1 by updating your wrapper:

./gradlew wrapper --gradle-version=9.5.1 && ./gradlew wrapper

See the Gradle 9.x upgrade guide to learn about deprecations, breaking changes and other considerations when upgrading.

For Java, Groovy, Kotlin and Android compatibility, see the full compatibility notes.

Reporting problems

If you find a problem with this release, please file a bug on GitHub Issues adhering to our issue guidelines.
If you're not sure you're encountering a bug, please use the forum.

We hope you will build happiness with Gradle, and we look forward to your feedback via Twitter or on GitHub.

v9.5.0: 9.5.0

Compare Source

The Gradle team is excited to announce Gradle 9.5.0.

Here are the highlights of this release:

  • Task provenance in reports and failure messages
  • Type-safe accessors for precompiled Kotlin Settings plugins

Read the Release Notes

We would like to thank the following community members for their contributions to this release of Gradle:
atm1020,
mataha,
Adam,
Attila Kelemen,
Benedikt Ritter,
Björn Kautler,
Caro Silva Rode,
CHANHAN,
Dmitry Nezavitin,
Eng Zer Jun,
KugelLibelle,
Madalin Valceleanu,
Markus Gaisbauer,
Oliver Kopp,
Philip Wedemann,
ploober,
Roberto Perez Alcolea,
Rohit Anand,
Suvrat Acharya,
Ujwal Suresh Vanjare,
Victor Merkulov

Upgrade instructions

Switch your build to use Gradle 9.5.0 by updating your wrapper:

./gradlew wrapper --gradle-version=9.5.0 && ./gradlew wrapper

See the Gradle 9.x upgrade guide to learn about deprecations, breaking changes and other considerations when upgrading.

For Java, Groovy, Kotlin and Android compatibility, see the full compatibility notes.

Reporting problems

If you find a problem with this release, please file a bug on GitHub Issues adhering to our issue guidelines.
If you're not sure you're encountering a bug, please use the forum.

We hope you will build happiness with Gradle, and we look forward to your feedback via Twitter or on GitHub.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 9am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@claude

claude Bot commented Jul 31, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 2m 30s —— View job


Review: Gradle wrapper 9.4.1 → 9.6.1

  • Read PR diff
  • Check wrapper integrity (checksum, wrapper JAR/scripts consistency)
  • Verify AGP / Kotlin / Java toolchain compatibility
  • Check for build-script patterns at risk from the bump
  • Validate build — could not run locally (see Validation)
  • Post review

Verdict: the change itself is correct and low-risk — a one-line distributionUrl bump within the same major. Approve once Android CI is green. Two non-blocking items below, one of which is a real supply-chain gap worth fixing while you're in this file.


Findings

1. No distributionSha256Sum — the downloaded distribution is never integrity-checked (security, medium)

gradle/wrapper/gradle-wrapper.properties:1-7 has validateDistributionUrl=true but no distributionSha256Sum. Those do different things: validateDistributionUrl only checks that the URL looks like an official gradle.org distribution URL — it does not verify the bytes that come back. So the build currently trusts whatever services.gradle.org serves, with TLS as the only control. Pinning the hash is the standard hardening step and closes the "compromised/substituted distribution" case.

Renovate maintains this field automatically once it exists — so it's a one-time fix, not recurring maintenance. Add it via:

./gradlew wrapper --gradle-version=9.6.1 --gradle-distribution-sha256-sum=<sum from https://gradle.org/release-checksums/>

Use the checksum published for gradle-9.6.1-bin.zip (the -bin, not -all, variant — that's what this file references).

Fix this →

2. Wrapper JAR and scripts were not regenerated (low / informational)

Renovate rewrites only distributionUrl; gradle-wrapper.jar, gradlew, and gradlew.bat are untouched by this PR. That's fine in practice — the wrapper JAR is a small bootstrapper and is effectively version-agnostic, which is why these PRs build green. But over many bumps the bootstrapper and launch scripts drift from what 9.6.1 ships. Gradle's documented upgrade path regenerates them:

./gradlew wrapper --gradle-version=9.6.1 && ./gradlew wrapper

(the second invocation is intentional — it re-runs the task using the newly downloaded distribution so the JAR/scripts come from 9.6.1). Worth doing periodically rather than on every patch bump. Combining it with finding #1 gets both in one command.

3. Thin changelog for 9.6.0 / 9.6.1 (informational)

The Renovate body links to empty GitHub compares for 9.6.0 and 9.6.1 — no release notes were published for those tags at PR-creation time. The only substantive notes shown are 9.5.0's (task provenance in reports, type-safe accessors for precompiled Kotlin Settings plugins), neither of which this build uses. Net: CI is the real gate here, since there's no changelog to reason from. Worth a glance at the 9.x upgrade guide for deprecation warnings that may newly surface.


Compatibility check

Verified against the declared toolchain — nothing in the matrix requires a Gradle floor above 9.6.1, and no component caps below it:

Component Version Notes
AGP 9.1.0 (gradle/libs.versions.toml:3) AGP 9.x requires Gradle 9.x — satisfied
Kotlin 2.2.21 (libs.versions.toml:20) Built-in Kotlin/KGP fine on 9.x
Java toolchain 21 (all 6 module build files, e.g. debugoverlay-core/build.gradle.kts:12) CI sets up JDK 21 (.github/workflows/android-ci.yml:22-26); 9.6.1 supports 21
JaCoCo 0.8.12 Java 21 class files supported
detekt 1.23.8 Highest-risk plugin (predates Gradle 9) — but already passing on 9.4.1, and 9.x minors don't change the plugin ABI
Spotless 8.4.0 Current

Highest-risk surface is ReportMergeTask at build.gradle.kts:24 plus the reportMerge.configure { } call nested inside tasks.withType<Detekt>().configureEach { } at build.gradle.kts:88-91. That's cross-task configuration from within another task's configuration action — legal today, but the pattern Gradle keeps tightening, so it's where a minor bump would most likely surface a new deprecation warning. Same for the cross-project it.layout.buildDirectory reads in mergedJacocoReport (build.gradle.kts:163-206). Both are pre-existing and out of scope for this PR — flagging only as the thing to check in the CI log if warnings appear. Neither blocks the merge.

Validation

I could not run ./gradlew help or check — Gradle invocation is blocked in this review sandbox (no approval for the command). So my compatibility assessment above is static analysis of the version matrix, not an executed build. The Android CI run is the authoritative check.

At the time of writing, all three runs were still in progress:

Workflow Status
Android CI 🟡 in progress
Qodana 🟡 in progress

Android CI runs ./gradlew check mergedJacocoReport reportMerge --continue --stacktrace then :sample:assembleDebug (.github/workflows/android-ci.yml:36,55), which exercises Spotless, Detekt, Lint, unit tests, JaCoCo merge, and a full assemble — good coverage for a wrapper bump. Please confirm it's green before merging; I did not verify the outcome.

Follow-ups (optional, not blocking)

  • Add distributionSha256Sum (finding Develop #1) — one-time, then Renovate maintains it.
  • renovate.json:14-89 gates Kotlin, AGP-adjacent, Compose, Square, and the maven-publish plugin behind dashboard approval, but Gradle itself isn't in any packageRules entry, so it flows through on the default path. Given the wrapper gates every build, consider whether Gradle minors deserve the same dependencyDashboardApproval treatment as the other build-critical tooling — or at least folding it into the existing "Build tooling" group.
    • branch renovate/gradle-9.x

@github-actions

github-actions Bot commented Jul 31, 2026 •

Copy link
Copy Markdown

Qodana for JVM

It seems all right 👌

No new problems were found according to the checks applied

💡 Qodana analysis was run in the pull request mode: only the changed files were checked
☁️ View the detailed Qodana report

Contact Qodana team

Contact us at qodana-support@jetbrains.com

@renovate

renovate Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@Manabu-GT
Manabu-GT merged commit f53901b into main Jul 31, 2026
4 of 5 checks passed
Manabu-GT added a commit that referenced this pull request Aug 7, 2026
* docs: update README for v2.6.3

- Bump dependency coordinate examples in README from 2.6.2 to 2.6.3.
- Add CHANGELOG entry for v2.6.3 covering the network request "Copy all"
  export (#268, item 2 of #256) and the Gradle 9.6.1 update (#267).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant