Skip to content

refactor: skip already indexed artifacts in aggregate Jandex indexes - #9518

Merged
Artur- merged 1 commit into
mainfrom
refactor/jandex-index-creation
Sep 25, 2026
Merged

Artur- merged 1 commit into
mainfrom
refactor/jandex-index-creation

Conversation

@mcollovati

Copy link
Copy Markdown
Contributor

vaadin-jandex and vaadin-core-jandex now only index classes from dependencies that do not ship their own META-INF/jandex.idx, avoiding duplicate entries once artifacts (e.g. Flow modules) provide per-artifact indexes.

Dependency unpacking is done by scripts/jandex/UnpackNonIndexedJars.java, which copies the classes into a dedicated directory (emptied on each run, so classes from artifacts that gained an index are not kept) and logs which artifacts are still covered by the aggregate index. It warns when the classpath contains no Vaadin jars. A --verify mode fails if any Vaadin jar lacks an index, to be kept as a check once the aggregate modules are removed.

The smoke tests now verify that the aggregate index does not overlap with per-artifact indexes, and that expected classes are indexed by either of them. Jandex plugin and library are bumped to 3.6.0.

Related to vaadin/flow#25899

vaadin-jandex and vaadin-core-jandex now only index classes from
dependencies that do not ship their own META-INF/jandex.idx, avoiding
duplicate entries once artifacts (e.g. Flow modules) provide per-artifact
indexes.

Dependency unpacking is done by scripts/jandex/UnpackNonIndexedJars.java,
which copies the classes into a dedicated directory (emptied on each run,
so classes from artifacts that gained an index are not kept) and logs
which artifacts are still covered by the aggregate index. It warns when
the classpath contains no Vaadin jars. A --verify mode fails if any
Vaadin jar lacks an index, to be kept as a check once the aggregate
modules are removed.

The smoke tests now verify that the aggregate index does not overlap
with per-artifact indexes, and that expected classes are indexed by
either of them. Jandex plugin and library are bumped to 3.6.0.
@mcollovati

Copy link
Copy Markdown
Contributor Author

After all Vaadin artifacts gets updated to have their own Jandex index, we can remove the platform aggregated Jandex modules (better first deprecate and provide empty ones).
When we completely drop the aggregated indexes, the UnpackNonIndexedJars.java script with the --verify option can still be used in the platform validation to ensure there are no dependencies without an index.

@mcollovati

Copy link
Copy Markdown
Contributor Author

Here's what will be reported after the Flow PR gets merged

[INFO] --- exec:3.5.1:exec (unpack-non-indexed-dependencies) @ vaadin-core-jandex ---
[jandex] Adding to aggregate index: [collaboration-engine-7.1-SNAPSHOT.jar, vaadin-accordion-flow-25.4-SNAPSHOT.jar, vaadin-ai-core-flow-25.4-SNAPSHOT.jar, vaadin-app-layout-flow-25.4-SNAPSHOT.jar, vaadin-aura-theme-25.4-SNAPSHOT.jar, vaadin-avatar-flow-25.4-SNAPSHOT.jar, vaadin-badge-flow-25.4-SNAPSHOT.jar, vaadin-breadcrumbs-flow-25.4-SNAPSHOT.jar, vaadin-button-flow-25.4-SNAPSHOT.jar, vaadin-card-flow-25.4-SNAPSHOT.jar, vaadin-checkbox-flow-25.4-SNAPSHOT.jar, vaadin-combo-box-flow-25.4-SNAPSHOT.jar, vaadin-confirm-dialog-flow-25.4-SNAPSHOT.jar, vaadin-context-menu-flow-25.4-SNAPSHOT.jar, vaadin-custom-field-flow-25.4-SNAPSHOT.jar, vaadin-date-picker-flow-25.4-SNAPSHOT.jar, vaadin-date-time-picker-flow-25.4-SNAPSHOT.jar, vaadin-details-flow-25.4-SNAPSHOT.jar, vaadin-dialog-flow-25.4-SNAPSHOT.jar, vaadin-field-highlighter-flow-25.4-SNAPSHOT.jar, vaadin-flow-components-base-25.4-SNAPSHOT.jar, vaadin-form-layout-flow-25.4-SNAPSHOT.jar, vaadin-grid-flow-25.4-SNAPSHOT.jar, vaadin-icons-flow-25.4-SNAPSHOT.jar, vaadin-list-box-flow-25.4-SNAPSHOT.jar, vaadin-login-flow-25.4-SNAPSHOT.jar, vaadin-lumo-theme-25.4-SNAPSHOT.jar, vaadin-markdown-flow-25.4-SNAPSHOT.jar, vaadin-master-detail-layout-flow-25.4-SNAPSHOT.jar, vaadin-menu-bar-flow-25.4-SNAPSHOT.jar, vaadin-messages-flow-25.4-SNAPSHOT.jar, vaadin-notification-flow-25.4-SNAPSHOT.jar, vaadin-ordered-layout-flow-25.4-SNAPSHOT.jar, vaadin-popover-flow-25.4-SNAPSHOT.jar, vaadin-progress-bar-flow-25.4-SNAPSHOT.jar, vaadin-radio-button-flow-25.4-SNAPSHOT.jar, vaadin-renderer-flow-25.4-SNAPSHOT.jar, vaadin-select-flow-25.4-SNAPSHOT.jar, vaadin-side-nav-flow-25.4-SNAPSHOT.jar, vaadin-slider-flow-25.4-SNAPSHOT.jar, vaadin-split-layout-flow-25.4-SNAPSHOT.jar, vaadin-tabs-flow-25.4-SNAPSHOT.jar, vaadin-text-field-flow-25.4-SNAPSHOT.jar, vaadin-time-picker-flow-25.4-SNAPSHOT.jar, vaadin-upload-flow-25.4-SNAPSHOT.jar, vaadin-virtual-list-flow-25.4-SNAPSHOT.jar]
[jandex] Skipping, already indexed: [flow-data-25.4-SNAPSHOT.jar, flow-dnd-25.4-SNAPSHOT.jar, flow-html-components-25.4-SNAPSHOT.jar, flow-lit-template-25.4-SNAPSHOT.jar, flow-server-25.4-SNAPSHOT.jar]

@github-actions

Copy link
Copy Markdown
Contributor

Dependencies Report

  • 🟠 Known Vulnerabilities:

    • Vulnerabilities in: pkg:maven/me.friwi/jcef-api@jcef-ca49ada%2Bcef-135.0.20%2Bge7de5c3%2Bchromium-135.0.7049.85 [CVE-2024-21639, CVE-2024-21640, CVE-2024-9410] (owasp)
      👌 Wait for the update from the jcefmaven community. Meanwhile the swing-kit is supposed to be used with fixed websites and not to browse the internet, we have a check for that, so the only possible attacker would be the same person that created the swing application, aka our customer devs. so this vulnerability is not classified by us as critical issue
      · cpe:2.3:a:chromiumembedded:chromium_embedded_framework::::::::
      · cpe:2.3:a:ada:ada::::::::
    • Vulnerabilities in: pkg:maven/io.opentelemetry/opentelemetry-api@1.65.0 [CVE-2026-54285] (owasp)
      👌 False positive: the advisory is for opentelemetry-js (@opentelemetry/core W3CBaggagePropagator.extract(), fixed in JS 2.8.0) and its only CPE targets node.js. io.opentelemetry is opentelemetry-java, an unrelated codebase on its own 1.x line, so the version range matches only by CPE collision; osv-scanner and ossindex report nothing for this coordinate. It reaches the sbom transitively through selenium-remote-driver under vaadin-testbench, a test only dependency.
      · cpe:2.3:a:opentelemetry:opentelemetry::::::node.js::*
    • Vulnerabilities in: pkg:maven/com.vaadin/vaadin-swing-kit-flow@3.0.1 [CVE-2021-33604] (owasp)
      👌 false report: this CVE is targeting Vaadin version prior 20, swing-kit-flow is using vaadin 24+ version, the related issue has been fixed.
      · cpe:2.3:a:vaadin:flow-server::::::::
      · cpe:2.3:a:vaadin:vaadin::::::::
  • 📔 No Core License Issues

  • 📔 No License Issues

  • 🟠 Changes in 25.4-SNAPSHOT since V25.3.0-rc1

    • 1 packages added (1 external, 0 vaadin)
    • 243 packages modified (17 external, 226 vaadin)
    • 405 packages same (389 external, 16 vaadin)

[Click for more Details]

@mcollovati

Copy link
Copy Markdown
Contributor Author

This change can be merged before the Flow PR gets in, as it will not break the existing functionality.

@Artur-
Artur- enabled auto-merge (squash) September 25, 2026 09:02
@Artur-
Artur- merged commit 5213978 into main Sep 25, 2026
4 checks passed
@Artur-
Artur- deleted the refactor/jandex-index-creation branch September 25, 2026 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants