renovate-bot opened a new pull request, #6822:
URL: https://github.com/apache/jmeter/pull/6822

   This PR contains the following updates:
   
   | Package | Type | Update | Change |
   |---|---|---|---|
   | [gradle/actions](https://redirect.github.com/gradle/actions) | action | 
minor | `v6.3.0` → `v6.4.0` |
   
   ---
   
   ### Release Notes
   
   <details>
   <summary>gradle/actions (gradle/actions)</summary>
   
   ### 
[`v6.4.0`](https://redirect.github.com/gradle/actions/releases/tag/v6.4.0)
   
   [Compare 
Source](https://redirect.github.com/gradle/actions/compare/v6.3.0...v6.4.0)
   
   #### Highlights
   
   ##### Gradle version support status in the Job Summary
   
   The actions now report the support status of every Gradle version used in a 
workflow, as job
   annotations and in the Job Summary 
([#&#8203;1057](https://redirect.github.com/gradle/actions/issues/1057)). 
Thanks to [@&#8203;ov7a](https://redirect.github.com/ov7a) for the contribution.
   
   | version kind                                                               
             | job annotation | version table         | below the table         
                                                                                
                                        |
   | 
---------------------------------------------------------------------------------------
 | -------------- | --------------------- | 
-----------------------------------------------------------------------------------------------------------------------------------------------
 |
   | **End-of-life** — two or more major versions behind the latest release     
             | warning        | :warning:             | expandable section 
naming the affected release lines, pointing at the [Gradle Security 
Subscription](https://gradle.org/security-subscription/) |
   | **Out of date** — one major behind, or more than two minors behind on the 
current major | notice         | :information\_source: | one-line legend 
pointing at the [Gradle release 
lifecycle](https://docs.gradle.org/current/userguide/feature_lifecycle.html#eol_support)
 docs   |
   | **Current**                                                                
             | none           | —                     | —                       
                                                                                
                                        |
   
   Deliberately *not* reported: patch releases (being on `9.7.0` when `9.7.1` 
exists is not flagged) and
   pre-releases (release candidates, milestones and snapshots never produce 
annotations). The latest
   Gradle release is determined from the wrapper checksum data already bundled 
with the action, so no
   network access is required.
   
   Note that these annotations are emitted independently of the 
`add-job-summary` setting: setting
   `add-job-summary: 'never'` suppresses the Job Summary itself, but the 
warning and notice annotations
   remain.
   
   ##### Gradle itself is now reported in the dependency graph
   
   The `dependency-submission` action now applies **v1.5.0** of the
   [GitHub Dependency Graph Gradle 
Plugin](https://redirect.github.com/gradle/github-dependency-graph-gradle-plugin)
   (up from v1.4.2) 
([#&#8203;1069](https://redirect.github.com/gradle/actions/issues/1069)).
   
   The headline change is that the Gradle Build Tool running the build is now 
reported as an
   `org.gradle:gradle-core` dependency, so that **GitHub can surface known 
vulnerabilities in the version
   of Gradle used to run your build**. These are the coordinates that GitHub 
advisories for the Gradle
   Build Tool are published against.
   
   Details worth knowing:
   
   - The entry is always reported as a **direct** dependency with 
**development** scope.
   - It is **not** affected by the project, configuration or scope filters, so 
it appears even in graphs
     that filter aggressively.
   - Expect dependency graphs to gain this one new entry the first time a build 
runs after upgrading.
   
   ##### A new Gradle signing key, if you use dependency verification
   
   > \[!IMPORTANT]
   > If your build has [dependency 
verification](https://docs.gradle.org/current/userguide/dependency_verification.html#sec:signature-verification)
   > enabled, you must add a **second** trusted key before upgrading, or 
Dependency Graph generation will
   > fail signature verification.
   
   `github-dependency-graph-gradle-plugin` `1.5.0` is signed with a new Gradle 
signing subkey, and the
   key previously documented in our setup guide has been revoked upstream:
   
   | Artifact                                                             | 
Signing key                                               |
   | -------------------------------------------------------------------- | 
--------------------------------------------------------- |
   | `org.gradle:github-dependency-graph-gradle-plugin` `1.5.0` and later | 
`E2879931BCA1A42E55F2D64DD9B2DFBD9F3298BA` (new)          |
   | `org.gradle` plugin versions before the rotation                     | 
`7B79ADD11F8A779FE90FD3D0893A028475557671` (old, revoked) |
   | `com.gradle` Develocity Gradle plugin, including `4.5.0`             | 
`7B79ADD11F8A779FE90FD3D0893A028475557671` (old, revoked) |
   
   Because the Develocity Gradle plugin is still signed with the old key, you 
should trust **both** keys
   rather than swapping one for the other — replacing the old key outright will 
break Develocity
   injection. The documented snippet in
   
[docs/setup-gradle.md](https://redirect.github.com/gradle/actions/blob/3f5f9adaf7d9fecd50b5935e54106014257a94e6/docs/setup-gradle.md#dependency-verification)
   has been updated accordingly 
([#&#8203;1071](https://redirect.github.com/gradle/actions/issues/1071)):
   
   ```xml
   <trusted-keys>
      <trusted-key id="7B79ADD11F8A779FE90FD3D0893A028475557671">
         <trusting group="com.gradle"/>
         <trusting group="org.gradle"/>
      </trusted-key>
      <trusted-key id="E2879931BCA1A42E55F2D64DD9B2DFBD9F3298BA">
         <trusting group="org.gradle"/>
      </trusted-key>
   </trusted-keys>
   ```
   
   ##### `cache-provider: external` for externally managed Gradle User Home
   
   Builds that save and restore Gradle User Home by some other mechanism 
(Develocity Artifact Cache, for
   example) previously had to set `cache-disabled: true`, which was misleading: 
caching wasn't disabled,
   it just wasn't managed by this action, and the Job Summary reported it as 
"Disabled".
   
   `cache-provider: external` skips Gradle User Home restore/save exactly as 
`cache-disabled` does, but
   reports a distinct **External** status in the Job Summary explaining that 
caching is handled by
   another provider 
([#&#8203;1059](https://redirect.github.com/gradle/actions/issues/1059)).
   
   ```yaml
   - uses: gradle/actions/setup-gradle@v6
     with:
       cache-provider: 'external'
   ```
   
   ##### Develocity access keys containing OIDC tokens now work
   
   Short-lived-token handling validated the `server=key[;server=key]*` access 
key format with a regex
   whose `key` portion was too strict, so an access key holding an OIDC token 
value was rejected
   outright. Worse, had it passed the regex, parsing split each entry on `=` 
and kept only the second
   field — silently **truncating** any key containing `=` (as JWT padding does) 
and sending the mangled
   key to the server. Both problems are fixed 
([#&#8203;1061](https://redirect.github.com/gradle/actions/issues/1061)).
   
   ##### Job Summary attribution
   
   Job summaries produced by `setup-gradle` and `dependency-submission` now 
carry a top-level heading
   naming the action, so the block stays attributable when another action's 
summary content lands in the
   same job 
([#&#8203;1058](https://redirect.github.com/gradle/actions/issues/1058)).
   
   ##### Updated defaults
   
   - GitHub Dependency Graph Gradle Plugin: **1.4.2 → 1.5.0**
   - 5 new known-good wrapper checksums for `wrapper-validation` (368 → 373 
entries)
   
   #### What's Changed
   
   - Bump the github-actions group across 3 directories with 6 updates by 
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in 
[#&#8203;1039](https://redirect.github.com/gradle/actions/pull/1039)
   - Bump the npm-dependencies group in /sources with 3 updates by 
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in 
[#&#8203;1038](https://redirect.github.com/gradle/actions/pull/1038)
   - Add action heading to Gradle job summary by 
[@&#8203;bigdaz](https://redirect.github.com/bigdaz) in 
[#&#8203;1058](https://redirect.github.com/gradle/actions/pull/1058)
   - Add cache-provider: external to skip Gradle User Home caching by 
[@&#8203;bigdaz](https://redirect.github.com/bigdaz) in 
[#&#8203;1059](https://redirect.github.com/gradle/actions/pull/1059)
   - Relax Develocity access key format validation by 
[@&#8203;bigdaz](https://redirect.github.com/bigdaz) in 
[#&#8203;1061](https://redirect.github.com/gradle/actions/pull/1061)
   - Use the root-qualified `:wrapper` task by 
[@&#8203;cobexer](https://redirect.github.com/cobexer) in 
[#&#8203;1064](https://redirect.github.com/gradle/actions/pull/1064)
   - Report EOL and maintenance status for Gradle versions by 
[@&#8203;ov7a](https://redirect.github.com/ov7a) in 
[#&#8203;1057](https://redirect.github.com/gradle/actions/pull/1057)
   - Update dependencies by 
[@&#8203;bigdaz](https://redirect.github.com/bigdaz) in 
[#&#8203;1065](https://redirect.github.com/gradle/actions/pull/1065)
   - Update .tool-versions: node 24.18.0, gradle 9.7.1, java 17 by 
[@&#8203;bigdaz](https://redirect.github.com/bigdaz) in 
[#&#8203;1068](https://redirect.github.com/gradle/actions/pull/1068)
   - Combined automated updates: wrapper checksums, npm dependencies, 
setup-java by [@&#8203;bigdaz](https://redirect.github.com/bigdaz) in 
[#&#8203;1070](https://redirect.github.com/gradle/actions/pull/1070)
   - Bump dependency-graph-gradle-plugin to 1.5.0 by 
[@&#8203;bigdaz](https://redirect.github.com/bigdaz) in 
[#&#8203;1069](https://redirect.github.com/gradle/actions/pull/1069)
   - Document the new Gradle signing key for dependency verification by 
[@&#8203;bigdaz](https://redirect.github.com/bigdaz) in 
[#&#8203;1071](https://redirect.github.com/gradle/actions/pull/1071)
   
   #### New Contributors
   
   - [@&#8203;cobexer](https://redirect.github.com/cobexer) made their first 
contribution in 
[#&#8203;1064](https://redirect.github.com/gradle/actions/pull/1064)
   - [@&#8203;ov7a](https://redirect.github.com/ov7a) made their first 
contribution in 
[#&#8203;1057](https://redirect.github.com/gradle/actions/pull/1057)
   
   **Full Changelog**: 
<https://github.com/gradle/actions/compare/v6.3.0...v6.4.0>
   
   </details>
   
   ---
   
   ### Configuration
   
   📅 **Schedule**: (UTC)
   
   - Branch creation
     - "every 3 weeks on Monday"
   - Automerge
     - At any time (no schedule defined)
   
   🚦 **Automerge**: Disabled by config. Please merge this manually once you are 
satisfied.
   
   ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry 
checkbox.
   
   🔕 **Ignore**: Close this PR and you won't be reminded about this update 
again.
   
   ---
   
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this 
box
   
   ---
   
   This PR was generated by [Mend Renovate](https://mend.io/renovate/). View 
the [repository job log](https://developer.mend.io/github/apache/jmeter).
   
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to