diff --git a/gradle/libs.versions.toml b/gradle/libs.versions.toml index 91230c2..1c8e11d 100644 --- a/gradle/libs.versions.toml +++ b/gradle/libs.versions.toml @@ -13,20 +13,20 @@ java = "21" # Build / quality -spotless = "8.8.0" -errorprone-plugin = "5.1.0" +spotless = "8.10.3" +errorprone-plugin = "5.1.1" errorprone-core = "2.50.0" google-java-format = "1.25.2" -jspecify = "1.0.0" +jspecify = "1.0.1" # Runtime — core / serialization / observability (pinned to pk-auth) # Jackson 3 ("tools.jackson") — java.time and JDK 8 datatype support is built into databind 3, # so we do not pull jackson-datatype-jdk8 / jackson-datatype-jsr310 separately. jackson = "3.2.3" jackson-annotations = "2.22" -caffeine = "3.2.4" -micrometer = "1.17.0" -slf4j = "2.0.18" +caffeine = "3.3.0" +micrometer = "1.17.1" +slf4j = "2.0.20" # Dagger 2 — compile-time DI for the Dropwizard tier (NFR-2, no Spring). Pinned to pk-auth. dagger = "2.60.1" @@ -43,20 +43,20 @@ hikaricp = "7.1.0" # Persistence — Redis backend (phase 2, sliding/hot-path reference). Lettuce is the async Redis # client; velocity-only, so it tracks the current latest 6.x. -lettuce = "7.6.0.RELEASE" +lettuce = "7.8.0.RELEASE" # Testing — Testcontainers for the backend integration tests (Postgres now; Redis/LocalStack later). testcontainers = "1.21.4" # OpenAPI parsing — validates the committed velocity-api spec is well-formed OpenAPI 3.1 in a test # (velocity-api OpenApiSpecTest). velocity-only; tracks the current latest 2.1.x. -swagger-parser = "2.1.22" +swagger-parser = "2.1.48" # Test bundle (wired in the test convention plugin). Pinned to pk-auth. -junit-jupiter = "6.1.2" +junit-jupiter = "6.1.3" assertj = "3.27.7" -mockito = "5.23.0" -logback = "1.5.38" +mockito = "5.24.0" +logback = "1.6.4" # Security floors for transitive dependencies (see the "Transitive security floors" block in # velocity.java-conventions). None of these are direct dependencies of ours — they arrive @@ -64,11 +64,11 @@ logback = "1.5.38" # Testcontainers, rhino via swagger-parser). Each value is the first patched release for the # corresponding Dependabot advisory; it is applied as a *floor*, not a pin, so a higher version # on any resolution path still wins. Dependabot keeps these current on its weekly gradle run. -netty = "4.2.15.Final" # netty-handler / netty-resolver-dns advisories (GHSA, high) -jackson2 = "2.21.5" # jackson-databind 2.x case-insensitive @JsonIgnoreProperties bypass -commons-compress = "1.26.0" # Pack200 OOM + corrupted-DUMP infinite-loop DoS -commons-lang3 = "3.18.0" # uncontrolled recursion on long inputs -rhino = "1.7.14.1" # toFixed() high-CPU DoS +netty = "4.2.18.Final" # netty-handler / netty-resolver-dns advisories (GHSA, high) +jackson2 = "2.22.3" # jackson-databind 2.x case-insensitive @JsonIgnoreProperties bypass +commons-compress = "1.28.0" # Pack200 OOM + corrupted-DUMP infinite-loop DoS +commons-lang3 = "3.20.0" # uncontrolled recursion on long inputs +rhino = "1.9.1" # toFixed() high-CPU DoS [libraries] jspecify = { module = "org.jspecify:jspecify", version.ref = "jspecify" } diff --git a/gradle/wrapper/gradle-wrapper.jar b/gradle/wrapper/gradle-wrapper.jar index b1b8ef5..5097068 100644 Binary files a/gradle/wrapper/gradle-wrapper.jar and b/gradle/wrapper/gradle-wrapper.jar differ diff --git a/gradle/wrapper/gradle-wrapper.properties b/gradle/wrapper/gradle-wrapper.properties index dbe66e1..1eca32e 100644 --- a/gradle/wrapper/gradle-wrapper.properties +++ b/gradle/wrapper/gradle-wrapper.properties @@ -1,7 +1,7 @@ distributionBase=GRADLE_USER_HOME distributionPath=wrapper/dists -distributionSha256Sum=9c0f7faeeb306cb14e4279a3e084ca6b596894089a0638e68a07c945a32c9e14 -distributionUrl=https\://services.gradle.org/distributions/gradle-9.6.1-bin.zip +distributionSha256Sum=bafd5ce9cfaea0fbccfdc8439a1ac42fbd4cd9c89dc9a988228d8a2639a58e6c +distributionUrl=https\://services.gradle.org/distributions/gradle-9.8.0-bin.zip networkTimeout=10000 retries=0 retryBackOffMs=500 diff --git a/gradlew.bat b/gradlew.bat index 8508ef6..03754c4 100644 --- a/gradlew.bat +++ b/gradlew.bat @@ -26,6 +26,33 @@ @rem Set local scope for the variables, and ensure extensions are enabled setlocal EnableExtensions +@rem Catch executions from older scripts and ensure they exit cleanly. +@rem This can be removed once we can be reasonably confident that few people +@rem will be migrating directly to this new wrapper. +goto afterSafetyNet +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: +goto exitWithErrorLevel +:afterSafetyNet + set DIRNAME=%~dp0 if "%DIRNAME%"=="" set DIRNAME=. @rem This is normally unused @@ -45,13 +72,14 @@ set JAVA_EXE=java.exe %JAVA_EXE% -version >NUL 2>&1 if %ERRORLEVEL% equ 0 goto execute -echo. 1>&2 -echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. 1>&2 -echo. 1>&2 -echo Please set the JAVA_HOME variable in your environment to match the 1>&2 -echo location of your Java installation. 1>&2 +1>&2 echo. +1>&2 echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. +1>&2 echo. +1>&2 echo Please set the JAVA_HOME variable in your environment to match the +1>&2 echo location of your Java installation. "%COMSPEC%" /c exit 1 +goto exitWithErrorLevel :findJavaFromJavaHome set JAVA_HOME=%JAVA_HOME:"=% @@ -59,13 +87,14 @@ set JAVA_EXE=%JAVA_HOME%/bin/java.exe if exist "%JAVA_EXE%" goto execute -echo. 1>&2 -echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% 1>&2 -echo. 1>&2 -echo Please set the JAVA_HOME variable in your environment to match the 1>&2 -echo location of your Java installation. 1>&2 +1>&2 echo. +1>&2 echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% +1>&2 echo. +1>&2 echo Please set the JAVA_HOME variable in your environment to match the +1>&2 echo location of your Java installation. "%COMSPEC%" /c exit 1 +goto exitWithErrorLevel :execute @rem Setup the command line @@ -75,8 +104,9 @@ echo location of your Java installation. 1>&2 @rem Execute gradlew @rem endlocal doesn't take effect until after the line is parsed and variables are expanded @rem which allows us to clear the local environment before executing the java command -endlocal & "%JAVA_EXE%" %DEFAULT_JVM_OPTS% %JAVA_OPTS% %GRADLE_OPTS% "-Dorg.gradle.appname=%APP_BASE_NAME%" -jar "%APP_HOME%\gradle\wrapper\gradle-wrapper.jar" %* & call :exitWithErrorLevel +endlocal & "%JAVA_EXE%" %DEFAULT_JVM_OPTS% %JAVA_OPTS% %GRADLE_OPTS% "-Dorg.gradle.appname=%APP_BASE_NAME%" -jar "%APP_HOME%\gradle\wrapper\gradle-wrapper.jar" %* & call :exitWithErrorLevel & goto exitWithErrorLevel +@rem This label must not be changed. We rely on old scripts being able to jump to this point. :exitWithErrorLevel @rem Use "%COMSPEC%" /c exit to allow operators to work properly in scripts "%COMSPEC%" /c exit %ERRORLEVEL% diff --git a/settings.gradle.kts b/settings.gradle.kts index 49c97b7..c8b19b3 100644 --- a/settings.gradle.kts +++ b/settings.gradle.kts @@ -10,7 +10,7 @@ plugins { // Maven Central publishing via Sonatype Central Portal. The aggregation plugin is auto-applied // to subprojects with `maven-publish` — `./gradlew publishAggregationToCentralPortal` uploads // every signed publication to the Central Portal in a single bundle (NFR-16). - id("com.gradleup.nmcp.settings") version "1.6.1" + id("com.gradleup.nmcp.settings") version "1.6.2" } rootProject.name = "velocity-engine"