Skip to content

ci: tell Dependabot to stop proposing libraries past Java 11 - #828

Closed
darbyjack wants to merge 1 commit into
masterfrom
ci/dependabot-ignore-java17
Closed

darbyjack wants to merge 1 commit into
masterfrom
ci/dependabot-ignore-java17

Conversation

@darbyjack

Copy link
Copy Markdown
Member

Summary

Dependabot proposed jdbi 3.55.0 and both CI checks passed on it. That is
Java 17 bytecode against a Java 11 runtime floor with 1.8.8 still supported.
Merging it would have shipped a library a Java 11 or older server cannot load,
and it would have done so green.

#781 pinned jdbi back to 3.49.6 for exactly this. Nothing told Dependabot, so
it reopened the same proposal daily. This adds the ignore directive.

  ignore:
    - dependency-name: "org.jdbi:jdbi3-core"
      versions: [">=3.50.0"]
    - dependency-name: "org.jdbi:jdbi3-sqlobject"
      versions: [">=3.50.0"]
    - dependency-name: "com.mojang:authlib"

>=3.50.0 rather than >=3.55.0 so the pin holds as newer releases land, and
3.49.6 stays the highest version Dependabot will offer.

Why CI did not catch it

Worth recording, because it is the more interesting half.

testJava11 does run, on a real Java 11 JVM. But the libraries Quark
downloads at runtime sit on the quark configuration, and that is on no test
classpath:

$ ./gradlew dependencies --configuration testJava11RuntimeClasspath | grep -E "jdbi|hikari"
(no output)

So no test ever loads jdbi, and the task is checking the plugin's own bytecode
against Java 11 while the dependency that actually breaks goes untouched.
Compiling with --release 11 does not help either: that constrains Guilds'
output, not its dependencies' input.

authlib

Ignored as well, for a different reason. It is not on Maven Central under this
coordinate, and it cannot be removed either: nothing imports it, but
GuildSkull.createSkull() passes an XSeries Profileable to XSkull, and
those signatures carry com.mojang.authlib.GameProfile, so javac needs the
class to resolve. Leaving Dependabot to propose versions of a coordinate it
cannot verify serves no purpose.

Still to do

This stops the bleeding; it does not prevent the next instance. A build task
that reads the bytecode major version of every jar on the quark configuration
and fails above 55 would catch the whole class of problem rather than two named
dependencies. I started one and it works, but it is a separate change and this
PR is deliberately just the config.

Merge Danger

Door: two-way. One file, no source or build change.

Blast Radius: Dependabot's suggestions only. Nothing about the plugin or
its CI behaviour changes.

Dependabot proposed jdbi 3.55.0 and both CI checks passed on it. That is
Java 17 bytecode against a Java 11 runtime floor with 1.8.8 still supported,
so merging it would have shipped a library a Java 11 or older server cannot
load. #781 pinned jdbi back for the same reason; nothing told Dependabot, so
it reopened the same PR daily.

Ignore jdbi above 3.49.6, the last Java 11 release, and authlib, which is not
on Maven Central under this coordinate and cannot be removed either because
XSeries signatures mention com.mojang.authlib.GameProfile.
@darbyjack darbyjack closed this Oct 5, 2026
@darbyjack
darbyjack deleted the ci/dependabot-ignore-java17 branch October 5, 2026 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant