Bump Gradle Wrapper to 9.6.1, wrapper checksums, and Develocity plugin to 4.5.0 - #1034
Merged
Merged
Conversation
Bumps the npm-dependencies group with 10 updates in the /sources directory: | Package | From | To | | --- | --- | --- | | [@actions/cache](https://github.com/actions/toolkit/tree/HEAD/packages/cache) | `6.0.1` | `6.2.0` | | [semver](https://github.com/npm/node-semver) | `7.8.3` | `7.8.5` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `25.9.2` | `26.1.1` | | [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.61.0` | `8.65.0` | | [esbuild](https://github.com/evanw/esbuild) | `0.28.0` | `0.28.1` | | [eslint](https://github.com/eslint/eslint) | `10.4.1` | `10.7.0` | | [globals](https://github.com/sindresorhus/globals) | `17.6.0` | `17.7.0` | | [prettier](https://github.com/prettier/prettier) | `3.8.4` | `3.9.6` | | [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.4.11` | `29.4.12` | | [typescript](https://github.com/microsoft/TypeScript) | `5.9.3` | `7.0.2` | Updates `@actions/cache` from 6.0.1 to 6.2.0 - [Changelog](https://github.com/actions/toolkit/blob/main/packages/cache/RELEASES.md) - [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/cache) Updates `semver` from 7.8.3 to 7.8.5 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md) - [Commits](npm/node-semver@v7.8.3...v7.8.5) Updates `@types/node` from 25.9.2 to 26.1.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@typescript-eslint/eslint-plugin` from 8.61.0 to 8.65.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/eslint-plugin) Updates `esbuild` from 0.28.0 to 0.28.1 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md) - [Commits](evanw/esbuild@v0.28.0...v0.28.1) Updates `eslint` from 10.4.1 to 10.7.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.4.1...v10.7.0) Updates `globals` from 17.6.0 to 17.7.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.6.0...v17.7.0) Updates `prettier` from 3.8.4 to 3.9.6 - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.8.4...3.9.6) Updates `ts-jest` from 29.4.11 to 29.4.12 - [Release notes](https://github.com/kulshekhar/ts-jest/releases) - [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md) - [Commits](kulshekhar/ts-jest@v29.4.11...v29.4.12) Updates `typescript` from 5.9.3 to 7.0.2 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: "@actions/cache" dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: semver dependency-version: 7.8.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: "@types/node" dependency-version: 26.1.1 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: "@typescript-eslint/eslint-plugin" dependency-version: 8.65.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: esbuild dependency-version: 0.28.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: eslint dependency-version: 10.7.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: globals dependency-version: 17.7.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: prettier dependency-version: 3.9.6 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: ts-jest dependency-version: 29.4.12 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Dependabot proposed TypeScript 7.0.2 and @types/node 26.1.1 in the npm-dependencies group bump. Pin to TypeScript 6.0.3 and the latest 24.x @types/node instead, matching the Node 24 runtime targeted by the actions. Also apply the reformatting required by the prettier 3.9.6 bump. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Refreshes transitive resolutions in package-lock.json to clear 4 high and 1 low severity advisory. All fixes are semver-compatible within the existing dependency ranges, so no package.json change is required. Production (bundled into dist): - undici 6.24.1 -> 6.28.0 (@actions/github, @actions/http-client) - undici 7.24.5 -> 7.29.0 (cheerio) - brace-expansion 5.0.6 -> 5.0.9 (@actions/glob) - brace-expansion 2.0.3 -> 2.1.4 (@actions/artifact) Dev only: - shell-quote 1.8.4 -> 1.10.0 (npm-run-all) - js-yaml 3.14.2 -> 3.15.1 (ts-jest) - @babel/core 7.28.0 -> 7.29.x (ts-jest) These were outstanding because the lockfile pins transitive resolutions and dependabot is configured to bump direct deps only. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
nock 15.0.0 was published by mistake. The package is deprecated on the registry with: v15.0.0 was released accidentally and is unstable. Please use v14.x until v15 is officially ready. nock's 'latest' dist-tag still points at 14.0.17 for this reason, and 15.x remains a beta line (beta = 15.0.0-beta.14). Move to 14.0.17. Also pulls @mswjs/interceptors 0.39.8 -> 0.41.9 and adds propagate 2.0.1 as nock 14 transitives. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The file pinned Node v16, contradicting every other Node declaration in the repo: package.json engines (>=24.0.0), the esbuild node24 target, and .tool-versions (nodejs 24.3.0). Nothing reads it. No workflow uses node-version-file, and there are no other references to .nvmrc in the repository. It has been stale since 5e52225 ("Combine all sources into a sub-directory"). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three workflows pinned node-version: 20 in their setup-node steps, but sources/package.json declares engines >=24.0.0 and esbuild targets node24, so npm clean-install was emitting EBADENGINE warnings for the root package on those runners. Aligns them with .github/actions/build-dist/action.yml, which already used Node 24, and with .tool-versions (nodejs 24.3.0) used locally. Notably ci-update-dist.yml built dist/ on Node 20 in its inline steps while build-dist/action.yml built it on Node 24, so the committed distribution could be produced under either version. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Combines the wrapper bumps from #1008, #1009, #1010, #1011 and #1012 into a single commit, covering all five wrapper locations: - sources/test/init-scripts - .github/workflow-samples/gradle-plugin - .github/workflow-samples/groovy-dsl - .github/workflow-samples/java-toolchain - .github/workflow-samples/kotlin-dsl Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Consolidates seven open bot PRs into three commits.
1. Bump Gradle Wrapper from 9.5.1 to 9.6.1
Combines #1008, #1009, #1010, #1011, #1012 into a single commit. Each of those PRs bumped the wrapper in one directory; this covers all five (15 files):
sources/test/init-scripts.github/workflow-samples/gradle-plugin.github/workflow-samples/groovy-dsl.github/workflow-samples/java-toolchain.github/workflow-samples/kotlin-dslEach location gets the same
distributionUrl→gradle-9.6.1-bin.zipanddistributionSha256Sumupdate, plus the regeneratedgradlew/gradlew.batscripts.2. Update known wrapper checksums
#990, unchanged, as its own commit. Adds 36 checksum entries to
sources/src/wrapper-validation/wrapper-checksums.json, including the 9.6.1 checksums — which is what lets the wrapper bump above passCI-validate-wrappers. These two are worth landing together.3. Bump Develocity Gradle plugin from 4.4.2 to 4.5.0
#1015, unchanged, as its own commit. Updates the plugin reference across workflow samples, init-script tests, docs, and the injected default in
sources/src/develocity/build-scan.ts:Since this touches
sources/src, the bundleddist/will change when the update-dist bot runs.Verification
All three cherry-picks applied without conflicts. On the combined branch:
./build— cleannpm run check(prettier + eslint) — cleannpm test— 373 tests, 15 suites, all passingOriginal bot authorship is preserved on all three commits.
Superseded PRs
Once this merges, these can be closed: #1008, #1009, #1010, #1011, #1012, #990, #1015.
🤖 Generated with Claude Code