Repository navigation
Conversation
Dependabot proposed jdbi 3.55.0 and both CI checks passed on it. That is Java 17 bytecode against a Java 11 runtime floor with 1.8.8 still supported, so merging it would have shipped a library a Java 11 or older server cannot load. #781 pinned jdbi back for the same reason; nothing told Dependabot, so it reopened the same PR daily. Ignore jdbi above 3.49.6, the last Java 11 release, and authlib, which is not on Maven Central under this coordinate and cannot be removed either because XSeries signatures mention com.mojang.authlib.GameProfile.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Dependabot proposed jdbi 3.55.0 and both CI checks passed on it. That is
Java 17 bytecode against a Java 11 runtime floor with 1.8.8 still supported.
Merging it would have shipped a library a Java 11 or older server cannot load,
and it would have done so green.
#781 pinned jdbi back to 3.49.6 for exactly this. Nothing told Dependabot, so
it reopened the same proposal daily. This adds the
ignoredirective.>=3.50.0rather than>=3.55.0so the pin holds as newer releases land, and3.49.6 stays the highest version Dependabot will offer.
Why CI did not catch it
Worth recording, because it is the more interesting half.
testJava11does run, on a real Java 11 JVM. But the libraries Quarkdownloads at runtime sit on the
quarkconfiguration, and that is on no testclasspath:
So no test ever loads jdbi, and the task is checking the plugin's own bytecode
against Java 11 while the dependency that actually breaks goes untouched.
Compiling with
--release 11does not help either: that constrains Guilds'output, not its dependencies' input.
authlib
Ignored as well, for a different reason. It is not on Maven Central under this
coordinate, and it cannot be removed either: nothing imports it, but
GuildSkull.createSkull()passes an XSeriesProfileabletoXSkull, andthose signatures carry
com.mojang.authlib.GameProfile, so javac needs theclass to resolve. Leaving Dependabot to propose versions of a coordinate it
cannot verify serves no purpose.
Still to do
This stops the bleeding; it does not prevent the next instance. A build task
that reads the bytecode major version of every jar on the
quarkconfigurationand fails above 55 would catch the whole class of problem rather than two named
dependencies. I started one and it works, but it is a separate change and this
PR is deliberately just the config.
Merge Danger
Door: two-way. One file, no source or build change.
Blast Radius: Dependabot's suggestions only. Nothing about the plugin or
its CI behaviour changes.