From 24eb1f92388975266ea7a0466260eca3ccbb025e Mon Sep 17 00:00:00 2001 From: Yeikel Santana Date: Sat, 15 Nov 2025 20:51:28 -0500 Subject: [PATCH 1/2] Document that Gradle runs when updating the Gradle Wrapper --- data/reusables/dependabot/supported-package-managers.md | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/data/reusables/dependabot/supported-package-managers.md b/data/reusables/dependabot/supported-package-managers.md index e25729f1e7be..40a29338137d 100644 --- a/data/reusables/dependabot/supported-package-managers.md +++ b/data/reusables/dependabot/supported-package-managers.md @@ -102,10 +102,16 @@ For more information about using {% data variables.product.prodname_dependabot_v {% data variables.product.prodname_dependabot %} doesn't run Gradle but supports updates to the following files: * `build.gradle`, `build.gradle.kts` (for Kotlin projects) -* `gradle/wrapper/gradle-wrapper.properties` (for Gradle wrapper) * `gradle/libs.versions.toml` (for projects using a standard Gradle version catalog) * Files included via the `apply` declaration that have `dependencies` in the filename. Note that `apply` does not support `apply to`, recursion, or advanced syntaxes (for example, Kotlin's `apply` with `mapOf`, filenames defined by property). +{% data variables.product.prodname_dependabot %} runs Gradle to update the Gradle Wrapper: + +* `gradle/wrapper/gradle-wrapper.properties` +* `gradlew` +* `gradlew.bat` +* `gradle/wrapper/gradle-wrapper.jar` + {% data variables.product.prodname_dependabot %} uses information from the `pom.xml` file of dependencies to add links to release information in update pull requests. If the information is omitted from the `pom.xml` file, then it cannot be included in {% data variables.product.prodname_dependabot %} pull requests, see [AUTOTITLE](/code-security/dependabot/ecosystems-supported-by-dependabot/optimizing-java-packages-dependabot). For {% data variables.product.prodname_dependabot_security_updates %}, Gradle support is limited to manual uploads of the dependency graph data using the {% data variables.dependency-submission-api.name %}. For more information about the {% data variables.dependency-submission-api.name %}, see [AUTOTITLE](/code-security/supply-chain-security/understanding-your-software-supply-chain/using-the-dependency-submission-api). From 333a3ed94a271e75aac369a4ca604aafe40b9e19 Mon Sep 17 00:00:00 2001 From: Yeikel Santana Date: Sat, 15 Nov 2025 20:55:00 -0500 Subject: [PATCH 2/2] Remove empty line --- data/reusables/dependabot/supported-package-managers.md | 1 - 1 file changed, 1 deletion(-) diff --git a/data/reusables/dependabot/supported-package-managers.md b/data/reusables/dependabot/supported-package-managers.md index 40a29338137d..65979a70f2fe 100644 --- a/data/reusables/dependabot/supported-package-managers.md +++ b/data/reusables/dependabot/supported-package-managers.md @@ -106,7 +106,6 @@ For more information about using {% data variables.product.prodname_dependabot_v * Files included via the `apply` declaration that have `dependencies` in the filename. Note that `apply` does not support `apply to`, recursion, or advanced syntaxes (for example, Kotlin's `apply` with `mapOf`, filenames defined by property). {% data variables.product.prodname_dependabot %} runs Gradle to update the Gradle Wrapper: - * `gradle/wrapper/gradle-wrapper.properties` * `gradlew` * `gradlew.bat`