Skip to content

chore: take vaadin-quarkus version from Flow - #9522

Merged
ZheSun88 merged 1 commit into
mainfrom
chore/quarkus-from-flow-version
Sep 25, 2026
Merged

ZheSun88 merged 1 commit into
mainfrom
chore/quarkus-from-flow-version

Conversation

@totally-not-ai

Copy link
Copy Markdown
Contributor

Summary

From 25.4, the Vaadin Quarkus extension is built and released as part of Flow. The platform now takes the vaadin-quarkus version from Flow and no longer pins its own version. This is the same change we made for vaadin-cdi.

What changed

Behavior change: vaadin-quarkus and vaadin-quarkus-deployment now resolve to Flow's version, not the old separate 3.2.2 release. The Quarkus version goes from 3.32.0 to 3.33.0 to match Flow. This affects Quarkus users of the platform BOMs.

  • versions.json: removed the vaadin-quarkus entry (it was pinned at 3.2.2).
  • Spring BOM and Quarkus extension POM templates: use ${flow.version} in place of ${vaadin.quarkus.version}. The generator now writes the flow.version property into the extension parent.
  • vaadin-quarkus-extension/pom.xml: the extension metadata rewrite now matches Flow's version. quarkus.version is now 3.33.0.
  • Javadoc POM template: the Quarkus BOM is now 3.33.0.
  • Release-note templates: the Quarkus plugin line now shows core.flow.javaVersion and links to Flow's releases.
  • Changelog generator: stopped reading releases from vaadin/quarkus.

The Vaadin Quarkus extension is built and released as part of Flow from
25.4 onwards, and flow-bom manages vaadin-quarkus and
vaadin-quarkus-deployment at Flow's version. This gives it the same
treatment vaadin-cdi got:

- versions.json loses the vaadin-quarkus entry, which was pinned at 3.2.2
- the spring BOM and the vaadin-quarkus-extension parent use
  ${flow.version} for vaadin-quarkus and vaadin-quarkus-deployment, and
  the generator writes the flow.version property into the extension parent
- the extension metadata rewrite matches the Flow version
- quarkus.version in the extension and the Quarkus BOM in the javadoc
  POM follow Flow's 3.33.0
- both release-note templates take the Quarkus plugin version from
  core.flow and link to Flow's releases
- the changelog module list no longer looks for vaadin/quarkus releases

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Artur-
Artur- marked this pull request as ready for review September 25, 2026 13:40
@Artur-
Artur- requested a review from ZheSun88 September 25, 2026 13:40
@ZheSun88
ZheSun88 enabled auto-merge (squash) September 25, 2026 13:41
@github-actions

Copy link
Copy Markdown
Contributor

Dependencies Report

  • 🟠 Known Vulnerabilities:

    • Vulnerabilities in: pkg:maven/me.friwi/jcef-api@jcef-ca49ada%2Bcef-135.0.20%2Bge7de5c3%2Bchromium-135.0.7049.85 [CVE-2024-21639, CVE-2024-21640, CVE-2024-9410] (owasp)
      👌 Wait for the update from the jcefmaven community. Meanwhile the swing-kit is supposed to be used with fixed websites and not to browse the internet, we have a check for that, so the only possible attacker would be the same person that created the swing application, aka our customer devs. so this vulnerability is not classified by us as critical issue
      · cpe:2.3:a:chromiumembedded:chromium_embedded_framework::::::::
      · cpe:2.3:a:ada:ada::::::::
    • Vulnerabilities in: pkg:maven/io.opentelemetry/opentelemetry-api@1.65.0 [CVE-2026-54285] (owasp)
      👌 False positive: the advisory is for opentelemetry-js (@opentelemetry/core W3CBaggagePropagator.extract(), fixed in JS 2.8.0) and its only CPE targets node.js. io.opentelemetry is opentelemetry-java, an unrelated codebase on its own 1.x line, so the version range matches only by CPE collision; osv-scanner and ossindex report nothing for this coordinate. It reaches the sbom transitively through selenium-remote-driver under vaadin-testbench, a test only dependency.
      · cpe:2.3:a:opentelemetry:opentelemetry::::::node.js::*
    • Vulnerabilities in: pkg:maven/com.vaadin/vaadin-swing-kit-flow@3.0.1 [CVE-2021-33604] (owasp)
      👌 false report: this CVE is targeting Vaadin version prior 20, swing-kit-flow is using vaadin 24+ version, the related issue has been fixed.
      · cpe:2.3:a:vaadin:flow-server::::::::
      · cpe:2.3:a:vaadin:vaadin::::::::
  • 📔 No Core License Issues

  • 📔 No License Issues

  • 🟠 Changes in 25.4-SNAPSHOT since V25.3.0-rc1

    • 1 packages added (1 external, 0 vaadin)
    • 243 packages modified (17 external, 226 vaadin)
    • 405 packages same (389 external, 16 vaadin)

[Click for more Details]

@ZheSun88
ZheSun88 merged commit 5fd7ebc into main Sep 25, 2026
4 checks passed
@ZheSun88
ZheSun88 deleted the chore/quarkus-from-flow-version branch September 25, 2026 14:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant