On Tue, 22 Aug 2023 13:09:21 GMT, Erik Joelsson <er...@openjdk.org> wrote:
> In principle I very much prefer locking down dependency versions to keep the > build as reliable as possible. Unfortunately, as we have experienced so far, > this isn't possible with GHA because the exact package versions aren't kept > available for very long. I suppose it would be possible with very diligent > watching for new versions and manually testing and updating before the old > version disappears, but that doesn't seem feasible in practice. On the other > hand, I don't think we have actually seen any problems when bumping the > versions so far, so I'm now inclined to agree with this change. Maybe we could use [devkits](https://github.com/openjdk/jdk/blob/master/doc/building.md#cross-compiling-the-easy-way-with-openjdk-devkits) to pin the compiler version? I'm not sure how feasible that is in the GHA context. It might have a negative performance impact? ------------- PR Comment: https://git.openjdk.org/jdk/pull/15374#issuecomment-1688203379